All frameworks
PCIv4.0.1

PCI DSS compliance

Protecting cardholder data, end to end.

PCI DSS is the security standard for organisations that store, process or transmit payment-card data. Version 4.0.1 modernises requirements with more flexibility (the customised approach) and a stronger focus on continuous security rather than annual point-in-time checks.

Start from the basics

The standard

PCI DSS v4.0.1 — Payment Card Industry Data Security Standard

Who needs it

Merchants and service providers of every size that handle cardholder data — with validation scope tied to transaction volume and the way you process payments.

12

Requirements tracked

The basics

What is PCI DSS?

PCI DSS is the security standard for anyone who stores, processes or transmits payment-card data. It isn't a law but a contractual requirement from the card brands — and the moment a card number touches your systems, it applies to you.

Version 4.0.1 modernised the standard: it adds flexibility through a 'customised approach' (meet the objective your own way, and evidence it), and shifts the emphasis from an annual point-in-time check to security you maintain continuously.

Why it matters

What PCI DSS does for your business

You can't take payments without it

Handling cards without PCI compliance risks fines, higher processing fees, and losing the ability to accept payments at all. Non-negotiable if money moves through you.

It shrinks your risk and your scope

Good PCI practice — segmentation, tokenisation — reduces both the data you hold and the blast radius if you're ever breached.

It reassures partners

Banks, processors and enterprise customers all sleep better knowing you're PCI compliant. It's table stakes for fintech and commerce.

What it covers

12 requirements

Organised under six goals, from secure networks to access control and monitoring.

Customised approach

v4.0 lets you meet an objective with alternative controls, evidenced accordingly.

Continuous validation

Many requirements are now business-as-usual activities, not annual events.

Scope reduction

Segmentation and tokenisation shrink the cardholder-data environment you must secure.

The hard way

PCI's 12 requirements sprawl across your whole environment, and v4.0.1's move to continuous, business-as-usual activities means the old 'cram before the annual assessment' approach quietly falls apart.

The easier way, with Compliance One

  • Tracks all 12 requirements with mapped evidence and clear ownership.
  • Supports the customised approach with structured objective-and-evidence records.
  • Schedules the recurring activities v4.0.1 expects so they never slip.
  • Shares network, access and monitoring evidence with your other frameworks.

Do it once, reuse it everywhere. Evidence you collect for PCI DSSis automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.

Common questions

Which PCI level are we?
It depends on your annual transaction volume and how you process cards — from self-assessment questionnaires for smaller merchants to a full assessment for the largest. We help you scope it correctly.
What's the customised approach in v4.0?
It lets you meet a requirement's objective with your own controls rather than the prescribed method, as long as you document and evidence it. Compliance One gives you the structure to do that cleanly.
Can we reduce PCI scope?
Yes — tokenisation and network segmentation keep card data out of most of your systems, shrinking what's in scope. Less scope, less work, less risk.

Ready to tackle PCI DSS?

See exactly how Compliance One maps PCI DSS to your environment in a 30-minute walkthrough — and how much of it we handle for you.