Payment Card Security
PCI DSS v4.0.1 compliance with the SAQ, ROC and AOC workflows built in — scope confirmed, requirements evidenced, and the acquirer's paperwork produced from the same record.
- StandardPCI DSS v4.0.1 — 12 requirements
- ValidationSAQ A–D by merchant level · ROC by QSA
- AttestationAOC to the acquirer or brand, annually
- Future-datedRequirements effective 31 March 2025 tracked
Payment Card Security
PCI DSS binds anyone who stores, processes or transmits cardholder data, and it is unusual among frameworks in prescribing exactly how compliance is validated: a Self-Assessment Questionnaire whose type depends on how you take payments, or a Report on Compliance by a Qualified Security Assessor, and in either case an Attestation of Compliance delivered to the acquirer.
Version 4.0.1 made two things harder. Scope must be documented and confirmed every twelve months, and a set of future-dated requirements — targeted risk analyses, authenticated vulnerability scanning, anti-phishing controls — moved from best practice to mandatory in March 2025. A programme run from last year's spreadsheet does not know which of its controls changed category.
GRCLens carries the full v4.0.1 requirement set with the SAQ, ROC and AOC workflows as first-class objects: the scope exercise, the requirement-by-requirement assessment, the evidence, and the attestation are one record, and the future-dated requirements are flagged as such until the date passes.
What the platform does for PCI DSS
Scope on record
Cardholder data environment, connected systems and segmentation recorded per client, with the twelve-month confirmation kept as evidence.
SAQ, signed off and dispatched
The questionnaire that matches how payments are taken — A, A-EP, B, B-IP, C, C-VT or D — completed in the platform with a sign-off step, then dispatched to the acquirer.
ROC and AOC as documents
Held per client, versioned and dated, with comments — so the assessor's report and the attestation the acquirer receives are the same record.
Evidence with an AI review step
Every uploaded document is reviewed by Baseerah against the requirement it evidences, and a human approves or rejects the review.
Future-dated requirements
Requirements that became mandatory in March 2025 flagged in the catalogue and on the dashboard, so nothing is assessed against the old edition.
Network and phishing evidence
NSPM's rulebase findings and PhishLens's awareness-campaign results are held as evidence for Requirement 1 and Requirement 12.6.
How it shows up in a tenant
PCI DSS is enabled per tenant; these are the screens it adds.
PCI dashboard
Twelve requirements with posture, evidence coverage and the future-dated markers.
SAQ / ROC / AOC
The validation workflow, step by step, with every artefact kept.
Scope register
CDE inventory, segmentation and the annual confirmation record.
Evidence
Scans, penetration tests, configuration standards and reviews, reused wherever ISO/IEC 27001 asks for the same.
Frameworks in this discipline
PCI DSS v4.0.1 Payment Card Industry Data Security Standard
Scope your cardholder data environment, work through SAQ or ROC, and evidence every PCI DSS v4.0.1 requirement.
Open the framework page →ISO/IEC 27001:2022 Information Security Management
Annex A controls, Statement of Applicability, risk treatment and evidence — managed in one place, ready for your certification body.
Open the framework page →Network Security Policy Management (NSPM)
Govern firewalls and network policy operationally — device inventory, rule-base analysis, findings and compliance checks in one workspace.
Open the framework page →PhishLens — Phishing Simulation & Awareness
Test and evidence security awareness — phishing campaigns, click analytics and executive reporting that feed your compliance frameworks.
Open the framework page →Payment Card Security
Which SAQ applies to us?
It depends on how cardholder data is handled: fully outsourced e-commerce uses SAQ A, standalone terminals SAQ B, and anything that stores cardholder data electronically SAQ D. GRCLens holds each SAQ type, so the one your acquirer expects can be completed and signed off in place.
Does GRCLens perform the ROC?
No. A Report on Compliance is performed by a Qualified Security Assessor. GRCLens holds the ROC and the AOC as documents against the client, with the evidence and comments the QSA worked from.
How are the March 2025 future-dated requirements handled?
They are part of the v4.0.1 catalogue and marked as future-dated until their effective date; assessments completed before that date show them as best practice, and after it as mandatory.
Deep expertise across the disciplines that matter

Produce the AOC from the record, not from memory
A walkthrough of the PCI dashboard, the SAQ workflow and the scope register, on your payment channels.