HomeDomainsPayment Card Security
Discipline 05

Payment Card Security

PCI DSS v4.0.1 compliance with the SAQ, ROC and AOC workflows built in — scope confirmed, requirements evidenced, and the acquirer's paperwork produced from the same record.

At a glance
  • StandardPCI DSS v4.0.1 — 12 requirements
  • ValidationSAQ A–D by merchant level · ROC by QSA
  • AttestationAOC to the acquirer or brand, annually
  • Future-datedRequirements effective 31 March 2025 tracked
Discipline 05
Why it matters

Payment Card Security

PCI DSS binds anyone who stores, processes or transmits cardholder data, and it is unusual among frameworks in prescribing exactly how compliance is validated: a Self-Assessment Questionnaire whose type depends on how you take payments, or a Report on Compliance by a Qualified Security Assessor, and in either case an Attestation of Compliance delivered to the acquirer.

Version 4.0.1 made two things harder. Scope must be documented and confirmed every twelve months, and a set of future-dated requirements — targeted risk analyses, authenticated vulnerability scanning, anti-phishing controls — moved from best practice to mandatory in March 2025. A programme run from last year's spreadsheet does not know which of its controls changed category.

GRCLens carries the full v4.0.1 requirement set with the SAQ, ROC and AOC workflows as first-class objects: the scope exercise, the requirement-by-requirement assessment, the evidence, and the attestation are one record, and the future-dated requirements are flagged as such until the date passes.

Discipline 05

What the platform does for PCI DSS

01

Scope on record

Cardholder data environment, connected systems and segmentation recorded per client, with the twelve-month confirmation kept as evidence.

02

SAQ, signed off and dispatched

The questionnaire that matches how payments are taken — A, A-EP, B, B-IP, C, C-VT or D — completed in the platform with a sign-off step, then dispatched to the acquirer.

03

ROC and AOC as documents

Held per client, versioned and dated, with comments — so the assessor's report and the attestation the acquirer receives are the same record.

04

Evidence with an AI review step

Every uploaded document is reviewed by Baseerah against the requirement it evidences, and a human approves or rejects the review.

05

Future-dated requirements

Requirements that became mandatory in March 2025 flagged in the catalogue and on the dashboard, so nothing is assessed against the old edition.

06

Network and phishing evidence

NSPM's rulebase findings and PhishLens's awareness-campaign results are held as evidence for Requirement 1 and Requirement 12.6.

In the platform

How it shows up in a tenant

PCI DSS is enabled per tenant; these are the screens it adds.

01

PCI dashboard

Twelve requirements with posture, evidence coverage and the future-dated markers.

02

SAQ / ROC / AOC

The validation workflow, step by step, with every artefact kept.

03

Scope register

CDE inventory, segmentation and the annual confirmation record.

04

Evidence

Scans, penetration tests, configuration standards and reviews, reused wherever ISO/IEC 27001 asks for the same.

Questions

Payment Card Security

Which SAQ applies to us?

It depends on how cardholder data is handled: fully outsourced e-commerce uses SAQ A, standalone terminals SAQ B, and anything that stores cardholder data electronically SAQ D. GRCLens holds each SAQ type, so the one your acquirer expects can be completed and signed off in place.

Does GRCLens perform the ROC?

No. A Report on Compliance is performed by a Qualified Security Assessor. GRCLens holds the ROC and the AOC as documents against the client, with the evidence and comments the QSA worked from.

How are the March 2025 future-dated requirements handled?

They are part of the v4.0.1 catalogue and marked as future-dated until their effective date; assessments completed before that date show them as best practice, and after it as mandatory.

Produce the AOC from the record, not from memory

A walkthrough of the PCI dashboard, the SAQ workflow and the scope register, on your payment channels.