Get Demo
↑

The 12 PCI DSS v4.0.1 Requirements Explained (with Sub-Requirements)

Overview of all 12 PCI DSS v4.0.1 requirements, six control objectives, and links to deep-dive guides for each requirement.

Published: September 2026 Compliance · PCI DSS 8-12 min read

PCI DSS v4.0.1 organizes roughly 286 testing procedures under 12 requirements and six control objectives. This hub summarizes each requirement's official title and primary focus, then links to CyberSilo deep-dive guides. For the full framework overview, start at the PCI DSS hub.

Regional note for Saudi / GCC merchants: see also PCI DSS 12 requirements explained for Saudi merchants.

Official framing: Clause titles below match PCI DSS v4.0 / v4.0.1. The v4.0.1 limited revision clarified wording and guidance; it did not add or delete requirements. Many former future-dated controls became mandatory on 31 March 2025.

Six Control Objectives

  1. Build and Maintain a Secure Network and Systems - Requirements 1 and 2
  2. Protect Account Data - Requirements 3 and 4
  3. Maintain a Vulnerability Management Program - Requirements 5 and 6
  4. Implement Strong Access Control Measures - Requirements 7, 8, and 9
  5. Regularly Monitor and Test Networks - Requirements 10 and 11
  6. Maintain an Information Security Policy - Requirement 12

All 12 Requirements

1

Install and Maintain Network Security Controls

NSCs, diagrams, six-month rule reviews.

2

Apply Secure Configurations to All System Components

Harden components, change vendor defaults.

3

Protect Stored Account Data

Minimize storage, never keep SAD post-auth, render PAN unreadable.

5

Protect All Systems and Networks from Malicious Software

Anti-malware and phishing technical controls (5.4.1).

6

Develop and Maintain Secure Systems and Software

Secure SDLC, patching, payment page scripts (6.4.3).

7

Restrict Access to System Components and Cardholder Data by Business Need to Know

Least privilege and access reviews (7.2.4 / 7.2.5).

8

Identify Users and Authenticate Access to System Components

Unique IDs, 12-character passwords (8.3.6), MFA (8.4.2).

9

Restrict Physical Access to Cardholder Data

Physical access, media, and POI device controls (9.5.1).

10

Log and Monitor All Access to System Components and Cardholder Data

Daily review (10.4.1), automation (10.4.1.1), retention (10.5.1), time sync (10.6).

11

Test Security of Systems and Networks Regularly

ASV scans, pentests, IDS/FIM, payment-page tamper detection (11.6.1).

12

Support Information Security with Organizational Policies and Programs

Policy, TRA (12.3.1), awareness, TPSPs, incident response.

Map PCI DSS v4.0.1 Controls to Continuous Evidence

CyberSilo CSA and ThreatHawk SIEM help US merchants and service providers collect QSA-ready evidence across the 12 requirements.

Frequently Asked Questions

How many requirements does PCI DSS v4.0.1 have?

PCI DSS v4.0.1 still has 12 principal requirements. The limited revision clarified wording and guidance; it did not add or delete requirements.

What changed for future-dated controls?

Many v4.0 controls that were best practices until 31 March 2025 are now mandatory. Full verified ID list: 51 future-dated requirements. Related: TRA elements, Customized Approach, and PCI DSS v4.0.1 overview.

What is the difference between an SAQ and a ROC?

Eligible merchants and service providers may validate with a Self-Assessment Questionnaire (SAQ). Level 1 entities typically require a Report on Compliance (ROC) by a Qualified Security Assessor. See the SAQ vs ROC guide and the main PCI DSS hub for assessment paths.

PCI DSS hub · Gap assessment · Future-dated requirements · Customized Approach · TRA required elements · Evidence checklist · Checklist · IR plan template · SAQ selector · PCI DSS v4.0.1: What Changed · SAQ vs ROC

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!