PCI DSS v4, without the spreadsheets.
Secure cardholder data and pass your assessment.
What is PCI DSS v4?
PCI DSS applies to every organisation that stores, processes or transmits payment card data, or that can affect the security of that environment. Version 4.0 introduced a customised approach and a set of future-dated requirements that became mandatory on 31 March 2025.
Who needs it
- Merchants accepting card payments
- Payment service providers and processors
- SaaS platforms that touch the cardholder data environment
What PCI DSS v4 looks at
Network and system security
Network security controls and secure configurations for every system in scope.
Protect account data
Minimise storage, encrypt stored data and protect it in transit.
Vulnerability management
Anti-malware, secure development and timely patching.
Access, logging and testing
Strong authentication, logging of all access and regular security testing.
How Beviso gets you there
- Requirements pre-loaded with evidence from cloud, endpoint and vulnerability scanning tools
- MFA and access evidence from your identity provider
- Policy templates for the documented procedures PCI DSS expects
11 PCI DSS v4 controls, ready on day one
These controls are loaded when you enable PCI DSS v4, each with the tools that can supply its evidence automatically. You can add your own controls alongside them.
Req.1
Install and Maintain Network Security Controls
Network security controls (NSCs) are in place and configured to restrict inbound and outbound traffic.
Evidence from
- Cloudflare
- AWS
- DigitalOcean
- Hetzner
- Microsoft Azure
Req.2
Apply Secure Configurations to All System Components
System components are protected from known weaknesses by securing configurations.
Evidence from
- Terraform Cloud
- AWS
- Microsoft Azure
- Doppler
- GitHub
Req.3
Protect Stored Account Data
Stored account data is protected through encryption and restricted retention.
Evidence from
- HashiCorp Vault
- Doppler
- Bitwarden
- 1Password
- AWS
Req.4
Protect Cardholder Data with Cryptography in Transit
Strong cryptography is used to protect PAN during transmission over open, public networks.
Evidence from
- Cloudflare
- HashiCorp Vault
- AWS
Req.5
Protect All Systems Against Malware
All system components are protected from malware, and anti-malware software or programs are maintained.
Evidence from
- CrowdStrike
- SentinelOne
- Jamf
- Kandji
Req.6
Develop and Maintain Secure Systems and Software
Vulnerabilities are identified and addressed through security vulnerability management processes.
Evidence from
- Snyk
- SonarCloud
- Veracode
- GitHub
- GitLab
Req.7
Restrict Access to System Components by Business Need
Access to system components and cardholder data is limited to only those individuals whose job requires such access.
Evidence from
- Okta
- AWS
- HashiCorp Vault
- GitHub
- Microsoft Azure
Req.8
Identify Users and Authenticate Access to System Components
All users are assigned a unique ID before allowing access, and strong authentication is used.
Evidence from
- Okta
- Duo
- Google Workspace
- Microsoft Azure
- AWS
- 1Password
Req.10
Log and Monitor All Access to Network Resources and Cardholder Data
Logging mechanisms are in place and the ability to track and monitor all access to network resources and cardholder data.
Evidence from
- Datadog
- AWS
- Splunk
- Okta
- HashiCorp Vault
- Salesforce
Req.11
Test Security of Systems and Networks Regularly
Security controls, processes, and procedures are tested regularly to ensure they remain effective.
Evidence from
- Snyk
- Qualys
- Rapid7
- Detectify
- Wiz
- Lacework
- HackerOne
Req.12
Support Information Security with Organizational Policies and Programs
Information security policies and procedures support the protection of the entity's cardholder data environment.
Evidence from
- KnowBe4
- Ironclad
- BambooHR
- HiBob
PCI DSS v4 questions
- We use Stripe. Do we still need PCI DSS?
- Using a hosted payment page reduces your scope significantly, often to a short Self-Assessment Questionnaire, but it rarely removes it entirely.
Often run alongside PCI DSS v4
SOC 2
Give US customers the SOC 2 report their procurement team asks for.
ISO 27001
Build an information security management system an auditor will certify.
SOC 1
Give customers’ financial auditors the report they need about you.
NIST CSF 2.0
Measure and improve your security programme against a common language.
Start your PCI DSS v4 programme today.
Free while Beviso is in beta. No credit card required.
Get started free