The standard

The 12 PCI DSS requirements, in plain English

Every PCI assessment tests the same 12 requirements (PCI DSS v4.0.1). Here's what each one means -- and what your assessor actually looks for.

Requirement 1: Install and Maintain Network Security Controls

Firewalls and network controls between your cardholder data environment and everything else. Assessors test the rulesets, not the diagrams -- every rule needs a business justification.

Requirement 2: Apply Secure Configurations

No vendor defaults: change default passwords, strip unnecessary services, and harden every in-scope system to a documented standard.

Requirement 3: Protect Stored Account Data

Minimize what you store, encrypt or tokenize what remains, and never store sensitive authentication data after authorization. Data you don't keep can't leak.

Requirement 4: Protect Cardholder Data in Transit

Strong cryptography for card data moving across public networks -- TLS everywhere it travels, no legacy protocols.

Requirement 5: Protect Against Malicious Software

Anti-malware on all systems commonly affected, kept current -- plus the v4.x expectation that you can show it's actually running and updated.

Requirement 6: Develop and Maintain Secure Systems and Software

Patch promptly, manage vulnerabilities, and -- the v4.x headline -- inventory every payment-page script with written justification and integrity controls (6.4.3).

Requirement 7: Restrict Access by Business Need to Know

Least privilege, enforced: access reviews, role-based controls, and documented approval for who can touch cardholder data.

Requirement 8: Identify Users and Authenticate Access

Unique IDs for everyone, strong passwords, and -- now fully enforced -- MFA for all access into the CDE, not just remote access (8.3.6).

Requirement 9: Restrict Physical Access

Badges, visitor logs, and physical controls over the rooms and devices where cardholder data lives -- including POS terminals and paper records.

Requirement 10: Log and Monitor All Access

Comprehensive audit logs of CDE access, reviewed regularly, protected from tampering, and retained. If it isn't logged, it didn't happen -- per your assessor.

Requirement 11: Test Security Regularly

Quarterly ASV scans, annual penetration testing, segmentation validation, change detection -- and under v4.x, automated tamper detection on payment pages (11.6.1).

Requirement 12: Support Information Security with Policies and Programs

The governance layer: security policies, risk assessments, incident response plans, service-provider management -- plus documented targeted risk analyses justifying control frequencies (12.3.2).

Know the requirements. Now find your assessor. Tell us your environment once -- matched QSA firms send scoped quotes. Free · 2 minutes.

Get matched quotes

Requirement questions

Which PCI requirement fails most often?

In the v4.x cycle, the new items fail most: payment-page script inventory (6.4.3), tamper detection (11.6.1), and MFA for all CDE access (8.3.6). Historically, logging (10), patching (6), and access reviews (7) are perennial findings.

Do all 12 requirements apply to every merchant?

No -- your SAQ type determines which requirements apply to you. SAQ A covers a subset; SAQ D covers effectively all of them. A ROC tests the full set against your scoped environment.

What is the customized approach in v4.x?

PCI DSS v4.x lets organizations meet a requirement's objective with custom controls instead of the defined implementation -- but you must document the approach and have the QSA validate it. It adds flexibility at the cost of more assessor scrutiny.

→ Which SAQ type are you?  ·  What's new in v4.0.1  ·  Readiness quiz

Ready to validate?

Get scoped quotes from QSA firms that fit your environment.

Get a free quote