Get Demo
↑

PCI DSS Audit Evidence Checklist: What Your QSA Will Ask For

PCI DSS audit evidence checklist - diagrams, configs, logs.

Published: September 2026 Compliance · PCI DSS 8-12 min read

Assessors sample operating evidence - not slide decks. Use this checklist to stage artefacts before SAQ sign-off or ROC fieldwork under PCI DSS v4.0.1.

Related: Gap assessment · Checklist · Requirement 10 · Requirement 11 · ROC and AOC · Policy templates.

Gotcha: Screenshots without dates or system names fail sampling. Name the asset, UTC timestamp, and control owner.

Evidence Categories

  1. Scope artefacts - network and data-flow diagrams; asset inventory; CHD storage locations; prior AOC/SAQ
  2. Policies / TRAs - information security policy; TRA docs for flexible frequencies; IR plan and last test record
  3. Network / config - NSC rule sets; change tickets; hardening baselines; wireless surveys if applicable
  4. Identity - unique IDs; MFA evidence; access reviews; joiner/mover/leaver samples
  5. Crypto / data - key custodians; encryption configs; SAD non-storage attestations; PAN masking samples
  6. Logging - log sources covering the CDE; retention proof; review evidence (manual or automated 10.4.1.1 where applicable); time sync
  7. Vuln / ASV / pentest - four quarterly ASV; internal scan cadence; pentest reports; segmentation test if used for scope reduction; 11.6.1 change-detection evidence
  8. SDLC / scripts - change control; 6.4.3 script inventory, authorization, and integrity
  9. TPSP - inventory; written agreements (12.8.2); AOC copies; responsibility matrix
  10. People - awareness completion; phishing training records; screening where required

How CyberSilo Helps

Map PCI DSS v4.0.1 Controls to Continuous Evidence

CyberSilo CSA and ThreatHawk SIEM help merchants and service providers collect QSA-ready evidence across scoping, cloud, and SAQ/ROC validation paths.

Frequently Asked Questions

Is SAQ evidence thinner than ROC?

ROC sampling is typically deeper, but SAQ answers still need truthful operating evidence for applicable questions.

How far back should logs go?

Align to PCI retention expectations and your assessment period; many programs keep at least 12 months with recent logs immediately available.

Can we submit vendor marketing certificates as TPSP evidence?

No. Use official AOC templates - see the certification myth guide.

Gap assessment · Checklist · Requirement 10 · Requirement 11 · ROC and AOC · Policy templates

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!