Compliance & Regulations/Global (Payments)/PCI-DSS v4.0
Payments · Global — any merchant or service provider handling cardholder data

PCI-DSS v4.0

The global payment-card data security standard, now in v4.0 with future-dated requirements becoming mandatory in March 2025.

Regulator
PCI Security Standards Council
Jurisdiction
Global — any merchant or service provider handling cardholder data
Status
v4.0 active; future-dated requirements mandatory from 31 March 2025.
In force since
April 2022 (v4.0).
Regulator's source
Who it applies to

Any entity that stores, processes, or transmits cardholder data — merchants, processors, acquirers, issuers, service providers.

Audit / certification status

Safeguard's hosted environment maintains a Level 1 Service Provider AoC.

What it requires

What PCI-DSS v4.0 actually requires.

These are the obligations a regulated entity owes — the things an assessor or supervisor will ask about.

01

12 high-level requirements expanded to ~280 sub-requirements at v4.0.

02

Customised approach allowed for compensating controls (new in v4.0).

03

Targeted Risk Analyses (TRAs) for every customised control — annual review.

04

Quarterly external ASV scans for in-scope systems.

05

Annual penetration testing of segmentation controls.

06

Continuous evidence retention — minimum 12 months for most control families.

How Safeguard maps to it

Pre-mapped controls. Continuous evidence.

Each requirement above is bound to live telemetry — not screenshots. The mapping below is what your auditor or regulator sees.

Pre-mapped to all 12 PCI-DSS v4.0 requirements with sub-requirement traceability.

Cardholder data flow diagrams auto-generated from telemetry — required by Req 1.2.4.

TRAs templated and stored alongside the customised control they justify.

Quarterly ASV scan integration with results bound to the relevant requirement.

Network segmentation tests automated and timestamped.

Evidence we produce

Artifacts your auditor accepts.

Each evidence artifact is signed and timestamped. Auditors can verify integrity without trusting Safeguard.

Self-Assessment Questionnaire (SAQ) — auto-populated by SAQ type (A through D).

Report on Compliance (RoC) evidence bundle — QSA-ready.

Quarterly ASV scan reports with remediation tracking.

Cardholder data flow diagrams (current + historical).

Penetration test results with segmentation validation.

Ready for PCI-DSS v4.0?

Bring the framework. We'll walk the controls with you — section by section, evidence packet by evidence packet, with the regulators you actually have to answer to.

Safeguard | Software Supply Chain Security Platform | Zero CVE + Self-Healing