Menu

PCI DSS V 4.0.1 - Payment Card Industry Data Security Standard

PCI DSS V 4.0.1 - Payment Card Industry Data Security Standard

It is essential to keep payment card data secure and free from breaches. Every business that handles card transactions must protect customer information from breaches and fraud. That’s where PCI DSS comes in. It’s the global security standard built to protect cardholder data. Your organization can achieve PCI DSS compliance by storing, processing and transmitting payment card data securely and safely. At INTERCERT we provide PCI DSS compliance assessment service to ensure your organization improve the system and achieve compliance standards.

What is PCI DSS?

Any organization handling cardholder data must adhere to a set of security requirements set forth by the Payment Card Industry Data Security Standard (PCI DSS). It has features for monitoring systems, limiting access, encrypting private information and safeguarding networks.

The PCI DSS v 4.0.1 have following compliance levels:

Level 1

Merchants or Service Providers processing over 6 million card transactions annually.

Level 2

Merchants or Service Providers processing 1 to 6 million transactions annually.

Level 3

Merchants or Service Providers processing 20,000 to 1 million transactions annually.

Level 4

Merchants or Service Providers processing fewer than 20,000 transactions annually.

How to Achieve PCI DSS Compliance?

Here is a general overview of the key steps your organization should follow to achieve PCI DSS compliance service:

Pre Assessment
checkmark

Conduct an initial assessment to determine whether the current process meets the requirements of standards or frameworks.


Scope Identification
checkmark

Identify the scope to understand inclusions and exclusions, which establishes boundaries, supports, goal achievement, and a clear path to achieving success.


Policy and Procedure Development
checkmark

Ensures a streamlined workflow, aligning processes to achieve goals while maintaining efficiency and quality.


Technical Solutions Improvement and Implementation
checkmark

Identify, develop, and implement solutions to meet requirements, improving and optimizing them to remain effective and aligned.


Training and Awareness
checkmark

Provide training to boost skills, awareness, and understanding of handling tasks, managing risks, and applying the best methods to improve the process and requirements of the standard or framework requirements.


Audit And Assessment
checkmark

Conduct an audit to examine compliance with standards or framework requirements and provide an assessment report that includes compliance evaluation and improvement areas.


Continuous Improvement
checkmark

Ensure constant process improvement to enhance outcomes and drive efficiency and overall performance.


General Audit and Assessment Process for PCI DSS Compliance

Phase 1: Audit Planning
checkmark

Understanding of Business Context

checkmark

Confirmation of Audit Scope

checkmark

Assignment of QSA Auditor

checkmark

Preparation of Audit Plan

checkmark

ASV Scan accordance with the defined Scope

Phase 2: Audit & Assessment
checkmark

Opening Meeting

checkmark

Confirmation of Scope

checkmark

Collection of Evidence

checkmark

Testing of control implementation & Effectiveness

checkmark

Closing Meeting

Phase 3: Audit Reporting & Attestation
checkmark

Preparation of Draft Report

checkmark

Client approval on Draft Report

checkmark

Delivery of Attestation of Compliance (AOC) and Certificate of Compliance (COC)

An Overview of Core PCI DSS Requirements

PCI DSS v4.0.1 has not introduced new requirements but has refined existing ones through clarifications, updated guidance, and minor formatting changes. The core principles of the standard remain unchanged and continue to provide a foundation for cardholder data protection, covering both technical and operational safeguards from network security to physical protections.

Requirement 1: Install and maintain network security controls

Configure and manage firewalls and segmentation rules to block unauthorized access into the cardholder data environment (CDE).

Requirement 2: Apply secure configurations to system components

Remove default settings, disable unnecessary features and close misconfigurations to reduce any gaps.

Requirement 3: Protect stored cardholder data

PCI DSS v4.0.1 reinforces the ban on storing sensitive authentication data (SAD) post-authorization, except for issuer exemptions, and refines guidance on applicability.

Requirement 4: Encrypt transmission of cardholder data over public networks

Use secure protocols (e.g., TLS 1.2+) to prevent interception when data travels across untrusted networks.

Requirement 5: Secure systems against malware

Deploy and update anti-malware tools to shield CDE from malicious software.

Requirement 6: Develop and maintain secure systems and software

Follow secure development practices and patch vulnerabilities quickly. PCI DSS v4.0.1 requires critical vulnerabilities to be remediated within 30 days, with non-critical fixes based on risk-based timelines.

Requirement 7: Restrict access based on business need-to-know

Grant access only to individuals with a clear, legitimate business need.

Requirement 8: Identify and authenticate access

Assign unique IDs, enforce strong authentication, and expand MFA usage to verify user access.

Requirement 9: Restrict physical access to cardholder data

Use physical barriers such as locks, keycards, and access logs to secure devices containing CHD.

Requirement 10: Log and monitor access to system components

Maintain audit trails to capture user activities and review them regularly for anomalies.

Requirement 11: Test security of systems and networks regularly

Conduct vulnerability scans, penetration testing, and wireless assessments to uncover weaknesses before attackers do.

Requirement 12: Maintain security policies and programs

Implement governance, training and risk management to ensure continuous compliance. PCI DSS v4.0.1 clarifies that service providers must also assist customers by providing documentation and evidence upon request.

Benefits of PCI DSS


checkmark

Protects sensitive cardholder data from breaches.

checkmark

Builds customer trust and confidence in your brand.

checkmark

Ensures compliance with industry and legal standards.

checkmark

Reduces financial and reputational risks from data breaches.

checkmark

Streamlines card holder data security processes for better efficiency.

checkmark

Enhances your reputation and gives a competitive edge in the market.

Benefits of PCI DSS

Frequently Asked Questions

How Can We Help You?

We are here to answer all your questions.


©2026 Intercert. All Rights Reserved