Requirement 1: Install and Maintain Network Security Controls
Firewalls became "network security controls" in v4 — the requirement now covers any technology that polices traffic between networks, including cloud security groups. What the assessor tests is whether every path into and out of the CDE is known, restricted and reviewed.
Reviewed by Abhay Singh, PCI SSC-qualified QSA professional · CyberSigma is a PCI SSC-listed QSA company · Part of the Requirement 1–12 series
The controls that decide your assessment
Control numbers reference PCI DSS v4.0.1 (June 2024). Verify wording against the standard itself — PCI SSC document library.
Where programmes actually fail
A VLAN is not segmentation until a penetration test proves isolation (11.4.5). Flat networks discovered at assessment time re-scope the whole engagement.
v4 explicitly includes cloud NSCs. Six-monthly ruleset reviews (1.2.7) apply to AWS/Azure security groups exactly as to firewalls — most first-year cloud programmes miss this.
1.3.2 restricts egress from the CDE too. Unrestricted outbound is both a finding and the exfiltration path in real breaches.
If the diagram was last touched the week before the assessment, the assessor will test its accuracy against reality — and use discrepancies to expand sampling.
Evidence a QSA accepts
A policy document proves intent; configuration proves control. Bring these to the assessment:
- Current network and account-data-flow diagrams with change history
- Firewall / security-group exports with business justification per rule
- Six-monthly ruleset review records with actions taken
- Segmentation penetration-test report covering isolation of the CDE
- Configuration standard for NSCs and evidence of secured config files
Requirement 1 FAQ
Is network segmentation mandatory under PCI DSS?
No — segmentation is not a requirement, but without it the entire network is in scope. Segmentation reduces scope and must then be verified by penetration testing at least annually (11.4.5).
Do cloud security groups count as firewalls?
Yes. v4 uses the term "network security controls" precisely so that security groups, NACLs and host-based firewalls are covered by Requirement 1, including the six-monthly review at 1.2.7.
How often must firewall rules be reviewed?
At least once every six months (1.2.7), confirming every rule still has a business need and removing what does not.
Requirement 1 in your environment
A PCI SSC-listed QSA firm can tell you in one session whether your controls will survive assessment — before the assessment.
