Frameworks · PCI DSS 4.0
PCI DSS: protect cardholder data and validate your compliance.
We prepare and support you in complying with PCI DSS 4.0 — with controls over cardholder data and the validation (ROC or SAQ) ready.
Who it applies to
PCI DSS applies to any organization that stores, processes or transmits payment card data: merchants, processors, fintechs and service providers.
What the framework requires
PCI DSS 4.0 defines 12 requirements over the cardholder data environment (CDE). Compliance is validated with a ROC (by a QSA) or an SAQ, depending on the merchant level.
Scope (CDE)
12 requirements
Segmentation
Validation (ROC/SAQ)
Risks of not acting
- Fines and penalties from the card brands for non-compliance.
- A poorly defined scope (CDE) that inflates the effort.
- Exposure of cardholder data and associated fraud.
- Losing the ability to operate payments with customers.
The i-Prot proposal
We define and reduce the scope (CDE), implement the 12 requirements and prepare the validation (ROC or SAQ). Integrated into the CGF cycle, with a focus on sustainable, not one-off, compliance.
How we work with this framework
Scope (CDE)
Gap analysis
Implementation
Evidence and validation
Upkeep
Deliverables
- Gap analysis
- Implementation plan
- Controls matrix
- System documentation
- Evidence
- Internal audit
- Management review
- Roadmap
How it connects with CGF
CGF uses PCI DSS as a source of requirements. This framework mainly covers the Assess, Design, Implement and Operate & measure stages of the cycle.
See the CGF methodology →
Complyze and PCI DSS
Complyze maps the 12 requirements, their evidence and compliance status, and keeps progress toward validation visible.
Frequently asked questions
Do you need to comply with PCI DSS?
Tell us how you handle cardholder data and we’ll define the scope.
By submitting you accept our privacy policy.