Certification · International

PCI DSS v4, without the spreadsheets.

Secure cardholder data and pass your assessment.

What is PCI DSS v4?

PCI DSS applies to every organisation that stores, processes or transmits payment card data, or that can affect the security of that environment. Version 4.0 introduced a customised approach and a set of future-dated requirements that became mandatory on 31 March 2025.

Who needs it

  • Merchants accepting card payments
  • Payment service providers and processors
  • SaaS platforms that touch the cardholder data environment

What PCI DSS v4 looks at

Network and system security

Network security controls and secure configurations for every system in scope.

Protect account data

Minimise storage, encrypt stored data and protect it in transit.

Vulnerability management

Anti-malware, secure development and timely patching.

Access, logging and testing

Strong authentication, logging of all access and regular security testing.

How Beviso gets you there

  • Requirements pre-loaded with evidence from cloud, endpoint and vulnerability scanning tools
  • MFA and access evidence from your identity provider
  • Policy templates for the documented procedures PCI DSS expects

11 PCI DSS v4 controls, ready on day one

These controls are loaded when you enable PCI DSS v4, each with the tools that can supply its evidence automatically. You can add your own controls alongside them.

Req.1

Install and Maintain Network Security Controls

Network security controls (NSCs) are in place and configured to restrict inbound and outbound traffic.

Evidence from

  • Cloudflare
  • AWS
  • DigitalOcean
  • Hetzner
  • Microsoft Azure

Req.2

Apply Secure Configurations to All System Components

System components are protected from known weaknesses by securing configurations.

Evidence from

  • Terraform Cloud
  • AWS
  • Microsoft Azure
  • Doppler
  • GitHub

Req.3

Protect Stored Account Data

Stored account data is protected through encryption and restricted retention.

Evidence from

  • HashiCorp Vault
  • Doppler
  • Bitwarden
  • 1Password
  • AWS

Req.4

Protect Cardholder Data with Cryptography in Transit

Strong cryptography is used to protect PAN during transmission over open, public networks.

Evidence from

  • Cloudflare
  • HashiCorp Vault
  • AWS

Req.5

Protect All Systems Against Malware

All system components are protected from malware, and anti-malware software or programs are maintained.

Evidence from

  • CrowdStrike
  • SentinelOne
  • Jamf
  • Kandji

Req.6

Develop and Maintain Secure Systems and Software

Vulnerabilities are identified and addressed through security vulnerability management processes.

Evidence from

  • Snyk
  • SonarCloud
  • Veracode
  • GitHub
  • GitLab

Req.7

Restrict Access to System Components by Business Need

Access to system components and cardholder data is limited to only those individuals whose job requires such access.

Evidence from

  • Okta
  • AWS
  • HashiCorp Vault
  • GitHub
  • Microsoft Azure

Req.8

Identify Users and Authenticate Access to System Components

All users are assigned a unique ID before allowing access, and strong authentication is used.

Evidence from

  • Okta
  • Duo
  • Google Workspace
  • Microsoft Azure
  • AWS
  • 1Password

Req.10

Log and Monitor All Access to Network Resources and Cardholder Data

Logging mechanisms are in place and the ability to track and monitor all access to network resources and cardholder data.

Evidence from

  • Datadog
  • AWS
  • Splunk
  • Okta
  • HashiCorp Vault
  • Salesforce

Req.11

Test Security of Systems and Networks Regularly

Security controls, processes, and procedures are tested regularly to ensure they remain effective.

Evidence from

  • Snyk
  • Qualys
  • Rapid7
  • Detectify
  • Wiz
  • Lacework
  • HackerOne

Req.12

Support Information Security with Organizational Policies and Programs

Information security policies and procedures support the protection of the entity's cardholder data environment.

Evidence from

  • KnowBe4
  • Ironclad
  • BambooHR
  • HiBob

PCI DSS v4 questions

We use Stripe. Do we still need PCI DSS?
Using a hosted payment page reduces your scope significantly, often to a short Self-Assessment Questionnaire, but it rarely removes it entirely.

Start your PCI DSS v4 programme today.

Free while Beviso is in beta. No credit card required.

Get started free