Get Demo
↑

PCI DSS v4.0.1 Compliance Checklist

PCI DSS v4.0.1 compliance checklist - scoping, 12 requirements, SAQ vs ROC path, ASV and pentest cadence.

Published: September 2026 Compliance · PCI DSS 8-12 min read

This is a practical readiness checklist - not a substitute for the official SAQ or ROC. Use it to brief owners before assessor fieldwork. (The older URL pci-dss-v4-0-compliance-checklist-what-changes-and-how-to-automate-the-gap is a v4 changes article, not this checklist.)

Related: 12 requirements hub · Gap assessment · Evidence list · Policy templates · SAQ types.

Gotcha: Checking boxes without operating evidence fails ROC sampling. "Policy exists" is not the same as "control operates."

Readiness Checklist

  1. Scope - CHD/SAD data-flow diagram; CDE inventory; connected-to and security-impacting systems; annual scope confirmation documented
  2. Path - Merchant vs service provider; brand/acquirer level; correct SAQ type or ROC; executive sign-off plan
  3. Requirements 1-2 - Network security control rules; trusted/untrusted boundaries; secure configs; no vendor defaults
  4. Requirements 3-4 - Minimize storage; no SAD after authentication; PAN protection; strong cryptography in transit on open networks
  5. Requirements 5-6 - Malware protections; secure SDLC; payment-page script inventory, authorization, and integrity (6.4.3)
  6. Requirements 7-9 - Need-to-know access; unique IDs; MFA where required; physical media and SAD controls
  7. Requirements 10-11 - Logging and review; time sync; retention expectations (including immediately available recent logs as applicable); ASV; internal/external vulnerabilities; penetration testing; change and tamper detection (11.6.1)
  8. Requirement 12 - Security policy; targeted risk analyses for flexible frequencies (12.3.1); awareness including phishing; TPSP list, agreements, and monitoring; incident response plan tested
  9. Evidence hygiene - Named owners, dates, and sampling-ready artefacts (see the audit evidence checklist)

How CyberSilo Helps

Map PCI DSS v4.0.1 Controls to Continuous Evidence

CyberSilo CSA and ThreatHawk SIEM help US merchants and service providers collect QSA-ready evidence across scoping, cloud, and SAQ/ROC validation paths.

Frequently Asked Questions

Is this an official SSC checklist?

No. Official testing procedures are in the PCI DSS and SAQ documents from PCI SSC.

Do SAQ A merchants need the full 12-requirement depth?

Only applicable SAQ questions apply - but confirm eligibility every year.

Is there an Excel download?

This page is HTML-only. Request a scoped worksheet via a gap scan if you need a working file for your environment.

12 requirements hub · Gap assessment · Evidence list · Policy templates · SAQ types · Requirement 12

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!