Skip to content
PCI DSS v4.0 · March 2024

PCI DSS v4.0 Checklist

Interactive checklist for PCI Data Security Standard v4.0 across all 12 requirements. Applies to any entity storing, processing, or transmitting cardholder data.

12

Requirements

Mar 2024

v4.0 Effective

Req 11.4

Annual pentest

All CDE

MFA required

0%0/44 controls implemented
Build and Maintain a Secure Network: 0/7
Protect Account Data: 0/6
Maintain a Vulnerability Management Programme: 0/7
Implement Strong Access Control Measures: 0/7
Restrict Physical Access to Cardholder Data: 0/3
Monitor, Test, and Maintain: 0/14

Frequently Asked Questions

What is PCI DSS v4.0?

The Payment Card Industry Data Security Standard, version 4.0 (finalised in 2022, mandatory from 31 March 2025), covering security requirements for any entity that stores, processes or transmits cardholder data.

How many requirements does PCI DSS have?

12 requirement categories, grouped into six control objectives — from building a secure network to maintaining an information security policy.

What's new in v4.0 compared to v3.2.1?

v4.0 introduces customised implementation as an alternative to the defined approach, expands multi-factor authentication requirements, and adds more explicit requirements for authenticated scanning and targeted risk analyses.

What is the CDE (Cardholder Data Environment)?

The people, processes and technology that store, process or transmit cardholder data or sensitive authentication data, plus any connected or security-impacting systems — it defines PCI DSS assessment scope.