Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

Service

PCI DSS compliance readiness

PCI DSS compliance support for organizations that accept, process, or store payment cards:

  • PCI DSS readiness, scoping, and remediation advisory

Version as of

PCI DSS v4.0.1

Published June 11, 2024

As of 2026-09-26, v4.0.1 is the only active version, and every requirement, including those once future-dated, has applied since March 31, 2025. PCI SSC ran a request for comments on v4.0.1 from June 3 to July 20, 2026, and has announced no successor version or date.

Check the official PCI DSS source (external site)

What is PCI DSS?

Checked on . Standards change, so confirm against the official source before you rely on it.

PCI DSS, the Payment Card Industry Data Security Standard, is a baseline of technical and operational requirements designed to protect payment account data. The PCI Security Standards Council (PCI SSC) maintains it, and it applies to entities that store, process, or transmit cardholder data or sensitive authentication data, or that could affect the security of the cardholder data environment.

PCI SSC doesn't enforce compliance. Whether you must comply, and how you validate, is decided by the organizations that manage compliance programs, such as the payment brands and your acquirer.

Version 4.0.1 was a limited revision of v4.0 with no new or deleted requirements. The 51 requirements that were future-dated in v4.0 became effective on March 31, 2025.

PCI DSS readiness, from scope to evidence

Readiness helps you understand scope, organize controls and evidence, and remediate gaps before your self-assessment or formal QSA assessment.

Readiness

PCI DSS readiness, scoping, and remediation advisory

What’s included

  • Scoping: trace where payment card data flows and which systems, people, and service providers are in scope, and look for ways to reduce it
  • Gap assessment against the PCI DSS v4.0.1 requirements that apply to you
  • Self-Assessment Questionnaire support: preparing the SAQ your acquirer says applies
  • Remediation advisory: a prioritized plan your team carries out, with our review
  • Policy and evidence preparation for your SAQ or formal assessment

A good fit when

  • You’re validating for the first time, or after a change to how you take payments
  • You want to shrink your scope before anyone assesses it
  • You use SAQ A and need to check the 2025 changes

What readiness isn’t

Readiness work doesn't validate your compliance. We don't complete or sign your Self-Assessment Questionnaire or Attestation of Compliance for you; your organization does.

Readiness starting price

Independence from your assessor

PCI SSC rules bind whoever performs your formal assessment. Under its FAQ 1562, a QSA Employee who designed, developed, or implemented controls for a customer may not assess those controls.

Readiness work stays on the preparation side of that line. Your team makes the changes with our advice and review, and the validation itself is a formal assessment by a PCI SSC-listed QSA Company, or your organization’s own SAQ if your acquirer accepts one.

Practitioners who worked on your readiness engagement don't take part in your formal assessment, examination, or certification audit, including as a subcontractor or specialist to the assessor.

Independence rules for every framework we work with

PCI SSC programs we don’t offer

Security Inspect doesn't perform ASV scans, PCI Forensic Investigator (PFI) investigations, or P2PE, Software Security Framework (SSF), PIN, or 3DS assessments. Each is a separate PCI SSC program with its own qualification and listing.

  • ASV scans. Approved Scanning Vendor program: external vulnerability scans for Requirement 11.3.2
  • PFI investigations. PCI Forensic Investigator program: investigations after a suspected payment card compromise
  • P2PE assessments. Point-to-point encryption solution assessments, under the P2PE Assessor program
  • SSF assessments. Software Security Framework assessments, under the Secure Software and Secure SLC Assessor programs
  • PIN assessments. PIN transaction security assessments, under the Qualified PIN Assessor program
  • 3DS assessments. 3-D Secure environment assessments, under the 3DS Assessor program

External vulnerability scans required by PCI DSS Requirement 11.3.2 must come from an ASV listed by PCI SSC. Check the list and engage the ASV directly. PCI SSC list of Approved Scanning Vendors (external site)

Who needs what

Your acquirer or the payment brands decide which validation form you need, so ask them before you plan the work. PCI SSC maintains the standard but doesn’t enforce compliance itself.

PCI DSS validation paths: who performs each and who signs
OutcomeWho performs itWho signs
Report on Compliance (ROC) with an Attestation of Compliance (AOC)A QSA Company listed by PCI SSC, through a QSA Employee. An individual’s QSA qualification is active only while they work for a listed QSA Company.The QSA Company’s assessor signs for the assessment; an officer of your organization signs the attestation of compliance.
Self-Assessment Questionnaire (SAQ) with its attestationYour own organization.An executive officer of your organization. If a QSA or ISA helped, the attestation records that involvement.
External vulnerability scan report (Requirement 11.3.2)An Approved Scanning Vendor (ASV) listed by PCI SSC.The ASV issues the scan report. You engage the ASV directly.

Deliverables

What readiness delivers

  • Scoping summary and data-flow review
  • Gap assessment against PCI DSS v4.0.1
  • Prioritized remediation plan
  • Evidence checklist for your QSA assessment or SAQ

How it works, from scope to validation

From scope to validation, with an independent assessorFour stages in order. Scope, evidence, and remediation form the readiness track, led by a readiness practitioner. Validation sits inside a separate boundary: a PCI SSC-listed QSA Company that had no part in the first three stages performs the formal assessment, or the organization completes its own SAQ if its acquirer accepts one.Readiness: your readiness practitionerValidation, by a listedQSA Company or your SAQIndependent validation01ScopeMap card data flows02EvidenceGather the proof03RemediationClose the gaps04ValidationROC or SAQFrom scope to validation, with an independent assessorFour stages in order. Scope, evidence, and remediation form the readiness track, led by a readiness practitioner. Validation sits inside a separate boundary: a PCI SSC-listed QSA Company that had no part in the first three stages performs the formal assessment, or the organization completes its own SAQ if its acquirer accepts one.Readiness:your readiness practitionerValidation, by a listedQSA Company or your SAQIndependent validation01ScopeMap card data flows02EvidenceGather the proof03RemediationClose the gaps04ValidationROC or SAQ
  1. Scope

    Find where payment card data goes and which systems, people, and providers the standard reaches.

  2. Evidence

    Compare what you do with the v4.0.1 requirements that apply, and collect the records that show it.

  3. Remediation

    Your team fixes what’s missing, in priority order, with advice and review along the way.

  4. Validation · outside the readiness work

    A PCI SSC-listed QSA Company that had no part in the first three stages assesses the controls and documents the result in a ROC. If your acquirer accepts an SAQ, your organization completes and signs it instead.

  1. Confirm how you validate

    Ask your acquirer or the payment brands whether you need a ROC or an SAQ, and which SAQ applies.

  2. Scope

    Map payment card data flows, systems, and service providers, and look for ways to reduce what’s in scope.

  3. Gather evidence

    Compare your controls and evidence with the PCI DSS v4.0.1 requirements that apply to you.

  4. Remediate

    Agree on a prioritized plan. Your team makes the changes; the readiness practitioner advises and reviews.

  5. Validate

    A PCI SSC-listed QSA Company that had no part in the readiness work assesses your controls and documents the result in a ROC, or your organization completes its own SAQ if your acquirer accepts one.

What PCI DSS readiness costs

  • Readiness

    PCI DSS Readiness

    From $8,000

    Typical scoped range: $8,000 to $22,000

    One-time project

Non-binding. Final pricing follows a written scope and proposal.

What affects the final price

Pricing depends on environment size, complexity, testing depth, locations, applications, accounts, user roles, compliance objectives, and delivery timeline. Every engagement begins with a written scope and proposal. Taxes, travel, remediation, third-party audit or certification fees, licensing, and emergency work are separate. Readiness services do not include independent certification, attestation, legal advice, or a guarantee of passing.

Compare published prices for every service

The requirements that took effect in March 2025

PCI DSS v4.0.1 is the only active version of the standard as of 2026-09-27. PCI SSC published it on June 11, 2024 as a limited revision of v4.0, with no added or deleted requirements, and retired v4.0 on December 31, 2024.

Version 4.0 introduced 64 new requirements. Of those, 51 were future-dated: best practice until March 31, 2025, and required since then, so they're fully considered in any assessment after that date. They include the payment page script controls in Requirements 6.4.3 and 11.6.1 and the documented targeted risk analyses that Requirement 12.3.1 describes for requirements that call for one.

If your last validation predates March 31, 2025, expect your next one to cover those requirements in full. Plan the evidence early, because several of them, such as the payment page controls, depend on a working process rather than a single configuration change.

PCI SSC ran a request for comments on v4.0.1 from June 3 to July 20, 2026, to gather input on the standard's future. As of 2026-09-27, it hasn't announced a successor version or a date for one.

Sources: PCI SSC blog: PCI DSS v4.0.1 published (June 2024); PCI SSC blog: adopting the future-dated requirements of PCI DSS v4.x (August 2024); PCI SSC document library: PCI DSS v4.0.1 and the Self-Assessment Questionnaires; PCI SSC blog: request for comments on PCI DSS v4.0.1 (June 2026)

Which validation path fits: a summary

A Self-Assessment Questionnaire (SAQ) is PCI SSC's validation tool for merchants and service providers that are eligible to self-assess. For PCI DSS v4.0.1 there are ten: A, A-EP, B, B-IP, C, C-VT, P2PE, SPoC, D for Merchants, and D for Service Providers. Each one is built for a specific kind of payment environment, defined by the eligibility criteria in the SAQ itself.

PCI SSC's advice on choosing is to ask first: contact your merchant bank (acquirer), the payment brands, or other compliance entity to confirm whether you may self-assess and which SAQ fits your environment. The summaries below are a starting point, not a substitute for each SAQ's own criteria, which PCI SSC clarified for SAQs A, A-EP, and C-VT in the v4.0.1 editions of October 2024.

The ten PCI DSS SAQs, summarized from each SAQ's eligibility criteria
SAQBuilt for
SAQ ACard-not-present merchants (e-commerce or mail and telephone order) that have completely outsourced all account data functions to third parties validated as compliant with PCI DSS, and retain account data, if at all, only on paper that wasn't received electronically
SAQ A-EPE-commerce merchants that partially outsource payment processing, whose website doesn't itself receive account data but can affect the security of the payment transaction or the payment page
SAQ BMerchants that use only imprint machines or standalone, dial-out terminals, with no electronic account data storage
SAQ B-IPMerchants that use only standalone PIN Transaction Security (PTS) point-of-interaction devices, listed by PCI SSC, with an IP connection to the payment processor and no electronic account data storage
SAQ CMerchants with payment application systems, such as point-of-sale systems, connected to the internet, with no electronic account data storage
SAQ C-VTMerchants that key transactions one at a time into a third party's web-based virtual payment terminal on an isolated device, with no electronic account data storage
SAQ P2PEMerchants that enter account data only into payment terminals from a validated point-to-point encryption (P2PE) solution listed by PCI SSC
SAQ SPoCMerchants that accept payments through a Software-based PIN Entry on COTS (SPoC) solution listed by PCI SSC
SAQ D for MerchantsMerchants that are eligible to self-assess but don't meet the criteria for any other SAQ type
SAQ D for Service ProvidersService providers that a payment brand has defined as eligible to self-assess; it's the only SAQ for service providers

Sources: PCI SSC blog: what's new with Self-Assessment Questionnaires (March 2024); PCI SSC bulletin: SAQs for PCI DSS v4.0.1 now available (October 2024); PCI SSC blog: updates for merchants validating with SAQ A (January 2025); PCI SSC document library: PCI DSS v4.0.1 and the Self-Assessment Questionnaires

Protecting the payment page, in brief

Two PCI DSS requirements target e-commerce skimming, where malicious code running in the consumer's browser captures card data from a payment page. Both were best practice until March 31, 2025 and are required now.

Requirement 6.4.3 covers every payment page script loaded and executed in the consumer's browser, including scripts from third and fourth parties. Each needs a method to confirm it's authorized, a method to assure its integrity, and a place in an inventory with a written business or technical justification for why it's necessary.

Requirement 11.6.1 adds a change- and tamper-detection mechanism that alerts personnel to unauthorized modification of the security-impacting HTTP headers and the script contents of payment pages as the consumer's browser receives them. It runs at least weekly, or at a frequency set by a targeted risk analysis under Requirement 12.3.1. For both requirements, scripts inside a third-party service provider's embedded payment form, such as an iframe, are that provider's responsibility.

From March 31, 2025, SAQ A no longer includes 6.4.3, 11.6.1, or 12.3.1. Merchants using it instead confirm that their site isn't susceptible to attacks from scripts that could affect their e-commerce systems, and PCI SSC notes the change doesn't remove or diminish the underlying requirements. Its March 2025 information supplement, Payment Page Security and Preventing E-Skimming, gives guidance on both requirements.

Sources: PCI SSC document library: PCI DSS v4.0.1 and the Self-Assessment Questionnaires; PCI SSC blog: updates for merchants validating with SAQ A (January 2025); PCI SSC blog: Payment Page Security and Preventing E-Skimming information supplement (March 2025)

Guides

Frequently asked questions

Which version of PCI DSS applies right now?

As of 2026-09-26, PCI DSS v4.0.1 is the only active version. PCI DSS v4.0 was retired on December 31, 2024, and every v4.0.1 requirement, including the 51 that were future-dated, has applied since March 31, 2025. PCI SSC ran a request for comments on v4.0.1 in June and July 2026, but it hasn't announced a new version or a date for one.

Do we need a QSA, or can we self-assess?

Your acquirer or the payment brands decide. Some organizations validate with a Report on Compliance completed by a PCI SSC-listed QSA Company; others use a Self-Assessment Questionnaire, which the organization completes and signs itself. Ask your acquirer which validation form applies before you plan the work.

Can we display a PCI badge once we've validated?

PCI SSC says it doesn't issue an official seal, mark, or logo for entities that achieve PCI DSS compliance. Its QSA Program Guide also says the compliant and certified phrases and check-mark logos built on the PCI name may not be used. Your acquirer or the payment brands tell you what evidence of validation to provide and to whom.

How do we check a QSA Company or an ASV?

Use PCI SSC's public lists. The QSA Company list shows whether a company is in good standing or in remediation and which regions it serves, the ASV list shows approved scanning vendors, and the professionals lookup confirms an individual's qualification status. An individual's QSA qualification is active only while they work for a listed QSA Company.

What changed for SAQ A in 2025?

From March 31, 2025, SAQ A no longer includes Requirements 6.4.3, 11.6.1, and 12.3.1, and merchants using it must confirm that their site isn't susceptible to attacks from scripts. PCI SSC says the change doesn't remove or diminish the underlying requirements in PCI DSS itself.

Educational information, not legal advice

Information on this website is general and educational. It isn't legal advice, and it doesn't create a client relationship.

Primary sources

Before you contact us

Warning: Don’t send cardholder data

This website doesn't accept cardholder data. Don't send card numbers, card security codes, or compliance documents such as ROCs and AOCs through our contact form.

Service boundary

Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.

Talk to a PCI DSS practitioner

Tell us how you take payments, who’s asking you to validate, and by when. We’ll identify a sensible readiness scope and explain the next validation step.

What happens next

  1. Tell us about your payment environment and the validation you're working toward.
  2. Talk through readiness scope, timing, and validation expectations with a practitioner.
  3. Review the written proposal and decide whether to go ahead.