We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

PCI DSS v4.0.1 · the full series

PCI DSS Requirements 1–12, explained properly

One deep guide per requirement: the controls that decide assessments, where programmes actually fail, and the evidence a QSA accepts — from the PCI SSC-listed QSA firm that runs these assessments.

Requirement 1
Network Security Controls

Install and Maintain Network Security Controls

Requirement 2
Secure Configurations

Apply Secure Configurations to All System Components

Requirement 3
Protect Stored Data

Protect Stored Account Data

Requirement 4
Encryption in Transit

Protect Cardholder Data with Strong Cryptography During Transmission

Requirement 5
Anti-Malware

Protect All Systems and Networks from Malicious Software

Requirement 6
Secure Development & Patching

Develop and Maintain Secure Systems and Software

Requirement 7
Need-to-Know Access

Restrict Access to System Components and Cardholder Data by Business Need to Know

Requirement 8
Identity & Authentication

Identify Users and Authenticate Access

Requirement 9
Physical Security

Restrict Physical Access to Cardholder Data

Requirement 10
Logging & Monitoring

Log and Monitor All Access to System Components and Cardholder Data

Requirement 11
Security Testing

Test Security of Systems and Networks Regularly

Requirement 12
Governance & Programme

Support Information Security with Organizational Policies and Programs

Start with the PCI scope checker, or go straight to PCI DSS services.