i-Prot

Frameworks · PCI DSS 4.0

PCI DSS: protect cardholder data and validate your compliance.

We prepare and support you in complying with PCI DSS 4.0 — with controls over cardholder data and the validation (ROC or SAQ) ready.

diagram · frameworks · pci dss 4.0

Who it applies to

PCI DSS applies to any organization that stores, processes or transmits payment card data: merchants, processors, fintechs and service providers.

What the framework requires

PCI DSS 4.0 defines 12 requirements over the cardholder data environment (CDE). Compliance is validated with a ROC (by a QSA) or an SAQ, depending on the merchant level.

Scope (CDE)

Delimit where the cardholder data lives.

12 requirements

Controls over network, data, access and monitoring.

Segmentation

Reduce the scope by isolating the CDE.

Validation (ROC/SAQ)

A ROC by a QSA or an SAQ self-assessment depending on the level.

Risks of not acting

  • Fines and penalties from the card brands for non-compliance.
  • A poorly defined scope (CDE) that inflates the effort.
  • Exposure of cardholder data and associated fraud.
  • Losing the ability to operate payments with customers.

The i-Prot proposal

We define and reduce the scope (CDE), implement the 12 requirements and prepare the validation (ROC or SAQ). Integrated into the CGF cycle, with a focus on sustainable, not one-off, compliance.

How we work with this framework

Scope (CDE)

Identification and reduction of the data environment.

Gap analysis

State against the 12 requirements.

Implementation

Controls, segmentation and procedures.

Evidence and validation

Preparation of the ROC or SAQ.

Upkeep

Continuous compliance and revalidation.

Deliverables

  • Gap analysis
  • Implementation plan
  • Controls matrix
  • System documentation
  • Evidence
  • Internal audit
  • Management review
  • Roadmap

How it connects with CGF

CGF uses PCI DSS as a source of requirements. This framework mainly covers the Assess, Design, Implement and Operate & measure stages of the cycle.

See the CGF methodology →

Complyze and PCI DSS

Complyze maps the 12 requirements, their evidence and compliance status, and keeps progress toward validation visible.

Frequently asked questions

Do you need to comply with PCI DSS?

Tell us how you handle cardholder data and we’ll define the scope.

By submitting you accept our privacy policy.

By submitting you accept the privacy policy and the processing of your data in order to be contacted.