PCI DSS compliance

Get PCI DSS compliant without building a security team first.

If you store, process, or transmit cardholder data, or can affect its security, PCI DSS applies. A dedicated SecureSlate compliance lead scopes your cardholder data environment, prepares your SAQ or supports your Report on Compliance, and closes the gaps, while our compliance automation platform keeps the evidence current. One fixed price covers the work.

PCI DSS v4.0.163 sub-requirements

PCI DSS v4.0.1: 63 sub-requirements, 5 Network security controls, 3 Secure configurations, 7 Stored account data, 2 Encryption in transit, 4 Malware protection, 5 Secure systems and software, 3 Access by need to know, 6 Identification and authentication, 5 Physical access, 7 Logging and monitoring, 6 Security testing, 10 Policies and programs. 8 highlighted: Evidenced by included security scanning.

Evidenced by included security scanningScoped with your compliance lead
Current version
PCI DSS v4.0.1
Validation
SAQ or Report on Compliance
Set by
PCI Security Standards Council
The standard

PCI DSS compliance is validated every year, and scope decides how hard it is.

PCI DSS is the payment card industry's security standard. The PCI Security Standards Council sets it, and card brands and acquiring banks enforce it through their contracts rather than through law.

12 requirements under 6 goals

The standard covers network security, secure configuration, stored and transmitted account data, malware, secure software, access control, physical security, logging, testing, and policy. Version 4.0.1 is current, and its future-dated requirements became mandatory on 31 March 2025.

Scope is the biggest lever

Every system that stores, processes, or transmits cardholder data, or can affect its security, is in scope. Tokenization, hosted payment pages, and network segmentation shrink the cardholder data environment and the number of requirements that apply to you.

SAQ or Report on Compliance

Depending on your merchant or service provider level, you validate with a self-assessment questionnaire or a Report on Compliance by a Qualified Security Assessor, submitted with an attestation of compliance and, where required, quarterly external scans by an Approved Scanning Vendor.
How it works

We run your PCI DSS program so the annual assessment is not a scramble.

Four stages from the scoping call to a validated assessment, with a named compliance lead accountable at every one.

Scope the cardholder data environment

We trace how card data flows through your product and vendors, confirm whether you are assessed as a merchant, a service provider, or both, and look for ways to reduce scope before any control work starts.

Choose the validation path and close gaps

Your compliance lead works out which SAQ applies or whether you need a Report on Compliance, then runs a gap assessment against every applicable requirement and gives you a dated plan with named owners.

Implement and evidence the requirements

Policies, access and authentication controls, logging, secure development, vulnerability management, and third-party service provider oversight put in place, with integrations and scanning collecting evidence continuously.

Validate, then stay compliant all year

We complete the SAQ with you or prepare for the QSA's fieldwork, coordinate ASV scans and penetration tests, and keep evidence current through the year so the next annual assessment starts from a clean baseline.
What is included

Everything your PCI DSS assessment asks for, prepared before they ask.

PCI DSS compliance software and the expert who runs it arrive together under one fixed price, so the program does not land on your engineers.

A dedicated compliance lead

One experienced practitioner owns your PCI DSS program end to end. They scope the cardholder data environment, run the gap assessment, draft policies, and work with your QSA directly, so your team reviews and approves instead of decoding the standard.

Scoping and a gap assessment

Card data flows, system inventory, and segmentation documented, with every applicable requirement assessed and the gaps turned into a dated plan with owners.

Evidence from the stack you already run

Connect your cloud provider, identity provider, code host, and devices once. Access, MFA, logging, and configuration settings are tested continuously, and when one fails, SecureSlate AI finds the gap and prepares a fix for your team to approve.

Access reviews and authentication

Access reviews, joiner and leaver tasks, and MFA coverage tracked on a schedule, giving you evidence for requirements 7 and 8 that an assessor can sample.

Third-party service providers

Payment processors, hosting providers, and other service providers tracked with their responsibilities and attestations of compliance, which is what requirement 12.8 expects you to monitor.

Security awareness and incident response

Security awareness training that covers phishing and social engineering, tracked for everyone with access to the cardholder data environment, alongside an incident response plan you have actually tested.
Technical requirements evidence

Several PCI DSS requirements need evidence from your code and cloud, not a policy.

Secure software, vulnerability management, and configuration are tested against what actually runs. Security scanning is part of the engagement, so the evidence comes from your real repositories, domains, and cloud accounts.
Requirements 6.2, 6.3

Code security scanning

Bespoke and custom code scanned for vulnerabilities, with findings classified by CWE and ranked by severity, which evidences secure development and vulnerability identification.
Requirement 8.6

Secrets detection

API keys, tokens, and credentials committed to source code, found and pinpointed to the file and line, so application and system account credentials are not left hard-coded unnoticed.
Requirement 6.3

Dependency and license risk

An SBOM for every repository, supporting the inventory of bespoke software and third-party components that requirement 6.3.2 asks for, with vulnerable components flagged.
Requirements 6.4, 11.3

Public surface monitoring

Public-facing web applications and domains scanned on a schedule and when you ship. It supports ongoing vulnerability management alongside the quarterly external ASV scans the standard still requires.
Requirement 8.3

Dark web monitoring

Company email addresses checked against known breach data, so compromised credentials are found and reset before they are used against systems in the cardholder data environment.
Requirements 1.2, 2.2

Cloud misconfiguration checks

AWS, Azure, and GCP configurations checked through read-only access for risky network, access, encryption, and logging settings around the cardholder data environment.
Beyond PCI DSS

One program, several frameworks.

PCI DSS controls overlap with the frameworks fintech and SaaS buyers ask for next, so each new framework extends the program instead of starting a new one.

SOC 2

Enterprise buyers still ask for a SOC 2 report. Access, logging, change management, and vendor controls serve both assessments.

ISO 27001

The certificate international buyers expect, with a management system around the same risk, access, and vulnerability work.

GDPR

Cardholder names and billing details are personal data too, so European customers bring GDPR obligations alongside PCI DSS.

DORA

EU financial entities and their ICT providers face DORA's resilience, incident reporting, and third-party risk rules in addition to PCI DSS.

HIPAA

Healthcare payments can put the same systems in scope for PCI DSS and HIPAA, and much of the access and logging evidence overlaps.

Financial services

How SecureSlate runs PCI DSS alongside SOC 2, DORA, and ISO 27001 for fintech and financial services teams.
PCI DSS guides

What your PCI DSS assessment actually tests

Three guides your team can read before the scoping call, from validation levels to what changed in version 4.

Levels 1 to 4
Merchant and service provider levels, and which ones need a Report on Compliance
SAQ
Which self-assessment questionnaire fits your payment setup
v4.0
What changed in PCI DSS version 4 and how the new requirements affect your assessment
Resources

Read up before your scoping call.

Practical guides to PCI DSS, from who it applies to what an assessment costs.

FAQs

What teams ask before starting PCI DSS compliance.

Find out what your PCI DSS assessment will take

Bring your payment flow and the acquirer or customer asking for proof. You will leave the call with a scope summary, a timeline, and a fixed price, whether or not you work with us.

Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?