Get Demo
↑

PCI DSS Requirement 1: Network Security Controls Explained

PCI DSS v4.0.1 Requirement 1 - install and maintain network security controls (NSCs), CDE traffic rules.

Published: September 2026 Compliance · PCI DSS 8-12 min read

PCI DSS Requirement 1 in v4.0.1 is titled Install and Maintain Network Security Controls. It defines how network security controls (NSCs) protect the cardholder data environment (CDE) - not only classic firewalls, but any control that enforces trusted boundaries, allowed services, and deny-by-default traffic.

Related: PCI DSS hub · Requirement 2.

Official framing: Clause IDs below match PCI DSS v4.0 / v4.0.1 (v4.0.1 added clarifications elsewhere; Requirement 1 IDs are unchanged). Future-dated controls elsewhere in the standard became mandatory on 31 March 2025.

Requirement 1 Structure

Clause
Focus
1.1
Processes and mechanisms for NSCs are defined and understood (policies 1.1.1; roles 1.1.2)
1.2
NSCs are configured and maintained (standards, change control, diagrams, services, six-month review)
1.3
Network access to and from the CDE is restricted
1.4
Connections between trusted and untrusted networks are controlled
1.5
Risks from devices that can reach both untrusted networks and the CDE are mitigated

Must-Implement Controls

Common Failures

Stale network or data-flow diagrams; broad outbound “permit any” from the CDE; wireless bridged into the CDE without an NSC; dual-homed laptops that can reach the Internet and the CDE without enforced endpoint controls.

How CyberSilo Helps

Map PCI DSS v4.0.1 Controls to Continuous Evidence

CyberSilo CSA and ThreatHawk SIEM help US merchants and service providers collect QSA-ready evidence across the 12 requirements.

Frequently Asked Questions

Does Requirement 1 only mean traditional firewalls?

No. PCI DSS v4.0.1 uses network security controls (NSCs) - firewalls, cloud security groups, routers, and equivalent controls that enforce the CDE boundary.

How often must NSC configurations be reviewed?

Requirement 1.2.7 requires NSC configurations to be reviewed at least once every six months to confirm they remain relevant and effective.

What diagrams does Requirement 1 expect?

An accurate network diagram (1.2.3) showing CDE connections including wireless, and a data-flow diagram (1.2.4) showing account data flows, updated when the environment changes.

PCI DSS hub · PCI DSS v4.0.1: What Changed · USA v4.0.1 services

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!