Compyl

The Complete Guide to PCI DSS Compliance

June 05, 2026
Framework · PCI DSS

The Complete Guide to PCI DSS Compliance

By Compyl ResearchUpdated June 20264 min read

PCI DSS is the Payment Card Industry Data Security Standard — a set of 12 requirements that any organization storing, processing, or transmitting cardholder data must meet.

Key takeaways
  • PCI DSS v4.0.1 is the standard for all 2026 assessments; its formerly optional requirements are now enforceable.
  • There are 12 core requirements grouped into six control objectives.
  • Your merchant level (1–4, by transaction volume) determines how you validate.
  • Most merchants validate with a Self-Assessment Questionnaire (SAQ); the largest use a Report on Compliance (ROC) by a QSA.

The 12 requirements (six objectives)

Objective Requirements
Build & maintain a secure network 1. Network security controls · 2. Secure configurations
Protect account data 3. Protect stored data · 4. Encrypt data in transit
Vulnerability management 5. Anti-malware · 6. Secure systems & software
Strong access control 7. Restrict by need-to-know · 8. Identify & authenticate · 9. Physical access
Monitor & test networks 10. Log & monitor · 11. Test security regularly
Information security policy 12. Maintain a security policy

Merchant levels and validation

  • Level 1 (largest volume) — annual Report on Compliance (ROC) by a Qualified Security Assessor, plus quarterly scans.
  • Levels 2–4 — typically validate with the appropriate Self-Assessment Questionnaire (SAQ) and quarterly scans where required.

The SAQ remains the primary validation instrument for most merchants under v4.0.1; the v4.0.1 SAQs were published in October 2024.

The path to PCI DSS compliance

  1. Scope your cardholder data environment (CDE) — everything that stores, processes, or transmits cardholder data, plus connected systems. Minimizing scope minimizes effort.
  2. Determine your level and SAQ type.
  3. Implement the 12 requirements across your CDE.
  4. Run required scans and testing (vulnerability scans, penetration testing).
  5. Validate via SAQ or ROC and submit attestation.
  6. Maintain continuously — v4.0.1 emphasizes ongoing security, not an annual snapshot.

What changed with v4.0.1

v4.0.1 (published June 2024) was a limited-revision clarification of v4.0 — no new or deleted requirements. The bigger shift is timing: the 51 “future-dated” requirements that were best practices under v4.0 became mandatory on March 31, 2025, and all 2026 assessments are conducted against v4.0.1. v4.0 placed greater emphasis on continuous, outcome-based security — which is where continuous controls monitoring earns its keep.

Frequently asked questions

What is PCI DSS?
The Payment Card Industry Data Security Standard — 12 requirements that any organization handling cardholder data must meet to protect that data.
What version of PCI DSS applies in 2026?
v4.0.1. Its previously optional ("future-dated") requirements became mandatory on March 31, 2025, and all 2026 assessments use v4.0.1.
How do merchants validate PCI compliance?
By merchant level: the largest (Level 1) complete a Report on Compliance with a QSA; most others use the appropriate Self-Assessment Questionnaire and required scans.
How do I reduce PCI scope?
Minimize where cardholder data is stored, processed, or transmitted, and segment the cardholder data environment from the rest of your network.

See PCI DSS compliance on your own data

Compyl unifies governance, risk, compliance and audit on one source of truth — built by CISOs, with a human approving every consequential decision.

Request a demo →

About this guide. By Compyl Research, referencing PCI SSC v4.0.1 guidance (2024–2026). Compyl is an AI-powered, agentic GRC platform built by CISOs.

Monitoring thousands of environments daily
By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies