The Complete Guide to PCI DSS Compliance
PCI DSS is the Payment Card Industry Data Security Standard — a set of 12 requirements that any organization storing, processing, or transmitting cardholder data must meet.
- PCI DSS v4.0.1 is the standard for all 2026 assessments; its formerly optional requirements are now enforceable.
- There are 12 core requirements grouped into six control objectives.
- Your merchant level (1–4, by transaction volume) determines how you validate.
- Most merchants validate with a Self-Assessment Questionnaire (SAQ); the largest use a Report on Compliance (ROC) by a QSA.
The 12 requirements (six objectives)
| Objective | Requirements |
|---|---|
| Build & maintain a secure network | 1. Network security controls · 2. Secure configurations |
| Protect account data | 3. Protect stored data · 4. Encrypt data in transit |
| Vulnerability management | 5. Anti-malware · 6. Secure systems & software |
| Strong access control | 7. Restrict by need-to-know · 8. Identify & authenticate · 9. Physical access |
| Monitor & test networks | 10. Log & monitor · 11. Test security regularly |
| Information security policy | 12. Maintain a security policy |
Merchant levels and validation
- Level 1 (largest volume) — annual Report on Compliance (ROC) by a Qualified Security Assessor, plus quarterly scans.
- Levels 2–4 — typically validate with the appropriate Self-Assessment Questionnaire (SAQ) and quarterly scans where required.
The SAQ remains the primary validation instrument for most merchants under v4.0.1; the v4.0.1 SAQs were published in October 2024.
The path to PCI DSS compliance
- Scope your cardholder data environment (CDE) — everything that stores, processes, or transmits cardholder data, plus connected systems. Minimizing scope minimizes effort.
- Determine your level and SAQ type.
- Implement the 12 requirements across your CDE.
- Run required scans and testing (vulnerability scans, penetration testing).
- Validate via SAQ or ROC and submit attestation.
- Maintain continuously — v4.0.1 emphasizes ongoing security, not an annual snapshot.
What changed with v4.0.1
v4.0.1 (published June 2024) was a limited-revision clarification of v4.0 — no new or deleted requirements. The bigger shift is timing: the 51 “future-dated” requirements that were best practices under v4.0 became mandatory on March 31, 2025, and all 2026 assessments are conducted against v4.0.1. v4.0 placed greater emphasis on continuous, outcome-based security — which is where continuous controls monitoring earns its keep.
Frequently asked questions
What is PCI DSS?
What version of PCI DSS applies in 2026?
How do merchants validate PCI compliance?
How do I reduce PCI scope?
See PCI DSS compliance on your own data
Compyl unifies governance, risk, compliance and audit on one source of truth — built by CISOs, with a human approving every consequential decision.
About this guide. By Compyl Research, referencing PCI SSC v4.0.1 guidance (2024–2026). Compyl is an AI-powered, agentic GRC platform built by CISOs.