PCI DSS v4.0
Practical help to understand which PCI DSS v4.0 requirements apply to you, where you fall short, and how to close the gaps before your assessment.
Request a proposalWhat it is
The Payment Card Industry Data Security Standard (PCI DSS) sets the security requirements for any organisation that stores, processes or transmits payment card data, or that can affect its security. Version 4.0, and its current revision v4.0.1, introduced new requirements and a customised approach that many organisations are still adapting to.
We help you scope your cardholder data environment correctly, compare your current controls with the standard, and build a realistic plan to meet it.
-
Scoping and data-flow review
Identify where card data flows and which systems are in scope, and look for ways to reduce that scope.
-
Gap assessment
Requirement-by-requirement comparison of your controls with PCI DSS v4.0, including the requirements that became mandatory on 31 March 2025.
-
Readiness support
Evidence preparation, policy and procedure updates, and guidance on the correct Self-Assessment Questionnaire (SAQ) or Report on Compliance (ROC) path.
-
Remediation support
Practical advice and technical validation, including penetration and segmentation testing, while you close the gaps.
Who needs it
PCI DSS consulting is valuable if you are:
- A merchant accepting card payments online, in store or by phone
- A service provider that stores, processes or transmits card data for others, or can affect its security
- Moving from PCI DSS v3.2.1 to v4.0 and unsure what has changed
- Preparing for your first assessment, or asked by your acquiring bank to show compliance
- Looking to reduce scope and cost through tokenisation, outsourcing or segmentation
Our approach
-
Discovery
Understand your payment channels, business processes and existing compliance status.
-
Scope confirmation
Map card data flows, confirm the cardholder data environment and connected systems, and identify scope-reduction opportunities.
-
Gap assessment
Review policies, configurations and evidence against each applicable requirement and record the gaps.
-
Remediation planning
Prioritise gaps by risk and effort and agree owners and timelines with your team.
-
Readiness review
Re-check remediated areas and confirm you are ready for your formal assessment or SAQ submission.
Deliverables
-
Scope document
Card data flow diagrams and a confirmed list of in-scope systems and processes.
-
Gap assessment report
Status of each applicable requirement with evidence, gaps and recommendations.
-
Remediation roadmap
A prioritised, time-phased plan with owners to reach compliance.
-
Readiness summary
A short statement of remaining gaps before your formal assessment.
Frequently asked questions
Which version of PCI DSS applies now?
PCI DSS v4.0 replaced v3.2.1, which was retired on 31 March 2024. The current revision is v4.0.1. Requirements that were future-dated became mandatory on 31 March 2025.
Can you sign our Report on Compliance (ROC)?
A ROC must be completed by a Qualified Security Assessor (QSA) or, in some cases, an Internal Security Assessor. Our gap assessment and readiness work prepares you for that assessment.
Do we need a full assessment or a Self-Assessment Questionnaire?
It depends on your merchant or service provider level and how you accept payments. Your acquiring bank or payment brand sets the requirement; we help you identify the right path.
Can we reduce our PCI DSS scope?
Often, yes. Network segmentation, tokenisation, point-to-point encryption and outsourcing to compliant providers can all reduce the number of systems in scope.
Ready to find out where you stand?
Tell us about your environment and goals. We will reply with a suggested scope and next steps.