PCI Security Standards Council · International

PCI DSS v4.0.1 Payment Card Industry Data Security Standard compliance software

Scope your cardholder data environment, work through SAQ or ROC, and evidence every PCI DSS v4.0.1 requirement.

Overview

What PCI DSS requires

PCI DSS applies to any organisation that stores, processes or transmits cardholder data, and to any system component that could affect the security of the cardholder data environment. It is enforced contractually by the payment brands and acquirers rather than by statute.

As of 31 March 2025 all previously future-dated requirements in v4.0.1 became mandatory, so the transition grace period has closed. Organisations validated against the older baseline without those controls in place will generally fail assessment until they remediate.

Scope is where PCI programmes succeed or fail. Requirements 6.4.3 and 11.6.1 extended obligations to every script executing on a payment page, and AI systems that touch payment data are treated as in-scope system components like any other.

Who it applies to

  • Merchants accepting card payments at any level
  • Service providers processing or storing cardholder data
  • Organisations completing a Self-Assessment Questionnaire
  • Entities requiring a Report on Compliance validated by a QSA

At a glance

  • Current version: v4.0.1
  • Requirements: 12 principal requirements across 6 control objectives
  • Validation: SAQ (self-assessment) or ROC (QSA-validated)
  • Key deadline: Future-dated v4.0.1 requirements mandatory since 31 March 2025
In the platform

How GRCLens supports PCI DSS

PCI DSS runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.

SAQ and ROC workflows

Work through the appropriate SAQ type or build a Report on Compliance, with requirement-level responses and evidence.

Scope definition

Record the cardholder data environment and connected system components so scope decisions are documented and defensible.

Gap analysis and remediation

Identify unmet requirements, assign owners and track remediation through to closure with a dated record.

Requirements library

The full v4.0.1 requirement set with testing procedures, available for reference during assessment.

Questions

PCI DSS frequently asked questions

Are AI systems in scope for PCI DSS?

If an AI system stores, processes or transmits cardholder data, or could affect the security of the cardholder data environment, it is a system component and falls in scope like any other. Fraud-scoring and transaction-monitoring models that see card data should be treated accordingly.

Do we need a SAQ or a ROC?

That depends on your merchant or service provider level and your acquirer's requirements. Higher transaction volumes and service provider status generally require a Report on Compliance validated by a Qualified Security Assessor.

Is the v4.0.1 transition period still open?

No. All previously future-dated requirements became mandatory on 31 March 2025, so there is no remaining grace period.

Talk to us about PCI DSS

Security Solution Consultants provides PCI DSS advisory and QSA readiness alongside the platform, so you can combine tooling with hands-on expertise.

Contact us