FixTheVuln

PCI DSS Compliance Checklist

By FixTheVuln Team Peer-reviewed security content Sources: CISA, NVD, OWASP

Test Your Knowledge

CISSP Practice Quiz Security+ Practice Quiz
← Back to Home

PCI DSS v4.0 Requirements

The Payment Card Industry Data Security Standard (PCI DSS) applies to any organization that stores, processes, or transmits cardholder data. Version 4.0 introduces a customized approach alongside the traditional defined approach.

Goal 1: Build and Maintain a Secure Network and Systems

Req 1 Install and Maintain Network Security Controls

Configure and maintain firewalls, routers, and other network security controls to protect cardholder data.

  • Document and implement firewall configuration standards
  • Restrict inbound/outbound traffic to only that which is necessary
  • Prohibit direct public access to cardholder data environment (CDE)
  • Install personal firewalls on portable devices
  • Document all allowed services, protocols, and ports
Req 2 Apply Secure Configurations to All System Components

Change vendor-supplied defaults and remove/disable unnecessary services.

  • Change all vendor-supplied default passwords
  • Remove or disable unnecessary default accounts
  • Develop configuration standards for all system types
  • Enable only necessary services, protocols, daemons
  • Implement additional security for insecure services (if required)

Goal 2: Protect Account Data

Req 3 Protect Stored Account Data

Minimize data storage, implement retention policies, and protect stored data.

  • Keep cardholder data storage to a minimum
  • Do not store sensitive authentication data after authorization
  • Mask PAN when displayed (first 6 and last 4 digits maximum)
  • Render PAN unreadable using encryption, hashing, or truncation
  • Document and implement key management procedures
Req 4 Protect Cardholder Data with Strong Cryptography During Transmission

Encrypt transmission of cardholder data across open, public networks.

  • Use strong cryptography (TLS 1.2+) for transmission
  • Never send unprotected PANs via email, chat, SMS
  • Document all transmission security policies
  • Use trusted certificates from recognized CAs

Goal 3: Maintain a Vulnerability Management Program

Req 5 Protect All Systems Against Malware

Deploy and maintain anti-malware software and processes.

  • Deploy anti-malware on all systems commonly affected
  • Ensure anti-malware is kept current and active
  • Perform periodic scans and real-time protection
  • Maintain audit logs for anti-malware
  • Evaluate systems not commonly affected by malware
Req 6 Develop and Maintain Secure Systems and Software

Identify vulnerabilities and develop software securely.

  • Establish process to identify security vulnerabilities
  • Install critical security patches within one month
  • Develop applications based on secure coding guidelines
  • Address common coding vulnerabilities (OWASP)
  • Protect public-facing web applications from attacks

Goal 4: Implement Strong Access Control Measures

Req 7 Restrict Access to System Components and Cardholder Data

Limit access to cardholder data on a need-to-know basis.

  • Define access needs for each role
  • Restrict access based on job responsibilities
  • Default deny-all setting for access control systems
  • Review access rights at least every 6 months
Req 8 Identify Users and Authenticate Access

Assign unique identification and implement strong authentication.

  • Assign unique ID to each person with access
  • Implement MFA for all access to CDE
  • Require minimum 12-character passwords (or 8 with MFA)
  • Lock out accounts after 10 failed attempts
  • Session timeout after 15 minutes of inactivity
Req 9 Restrict Physical Access to Cardholder Data

Limit physical access to systems and media containing cardholder data.

  • Use facility entry controls for sensitive areas
  • Distinguish between onsite personnel and visitors
  • Control physical access to network jacks and devices
  • Physically secure all media containing cardholder data
  • Destroy media when no longer needed

Goal 5: Regularly Monitor and Test Networks

Req 10 Log and Monitor All Access to System Components and Cardholder Data

Track and monitor all access to network resources and cardholder data.

  • Implement audit trails for all access to cardholder data
  • Record user identification, event type, date/time, success/failure
  • Review logs daily for critical systems
  • Retain audit history for at least one year
  • Protect audit trails from unauthorized modification
Req 11 Test Security of Systems and Networks Regularly

Regularly test security systems, processes, and software.

  • Test for unauthorized wireless access points quarterly
  • Run internal and external vulnerability scans quarterly
  • Conduct penetration testing annually (or after significant changes)
  • Use intrusion-detection/prevention systems
  • Deploy change-detection mechanism on critical files

Goal 6: Maintain an Information Security Policy

Req 12 Support Information Security with Organizational Policies and Programs

Establish, publish, maintain, and disseminate a security policy.

  • Establish and publish information security policy
  • Implement risk assessment process (annually minimum)
  • Develop acceptable use policies for critical technologies
  • Ensure personnel are aware of responsibilities
  • Implement incident response plan
  • Conduct security awareness training upon hire and annually

Merchant Compliance Levels

Level Annual Transactions Validation Requirements
Level 1 > 6 million Annual on-site assessment by QSA, quarterly network scans
Level 2 1-6 million Annual SAQ, quarterly network scans
Level 3 20,000-1 million (e-commerce) Annual SAQ, quarterly network scans
Level 4 < 20,000 (e-commerce) or < 1 million (other) Annual SAQ, quarterly scans if applicable

Need Detailed PCI DSS Implementation Guides?

For comprehensive tutorials and compliance guides:

Visit FixTheVuln.com →

FixTheVuln Store

Studying for CISSP or CISA?

Structured study planners covering compliance, governance, and risk.

CISSP 2026 CISA CISM 2026 CRISC
CompTIA (ISC)2 AWS Cisco All โ†’

Related Resources

๐Ÿ‡ช๐Ÿ‡บ GDPR Guide EU data protection compliance ๐Ÿ—„๏ธ Database Security Protect your data stores ๐Ÿ”‘ Encryption Cheatsheet Algorithms & best practices

FixTheVuln Store

Studying for CompTIA Security+? Get the Study Planner

Fillable PDF study planners with domain trackers, weekly schedules, and progress tracking. Available in Standard, ADHD-Friendly, Dark Mode, and 4-Format Bundle.

CompTIA Security+ Planner

60+ certifications available — from $5.99