PCI DSS 4.0
What is PCI DSS 4.0?
Payment Card Industry Data Security Standard version 4.0, published by PCI Security Standards Council.. It comprises 168 controls organised across 12 domains, published by PCI Security Standards Council, and applies in International.
How PCI DSS 4.0 maps to other frameworks
All 168 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 12 domains PCI DSS 4.0 groups its controls into
Frameworks that share controls with PCI DSS 4.0
Each of these has at least one control mapped to a control in PCI DSS 4.0. The number is how many PCI DSS 4.0 controls are shared, counted from the mapping graph.
Implementation guides for frameworks that overlap PCI DSS 4.0
Where PCI DSS 4.0 overlaps with the standards you already hold
What PCI DSS 4.0 means in your sector
What PCI DSS 4.0 means for your job
Questions people ask about PCI DSS 4.0
What is PCI DSS 4.0?
How many controls does PCI DSS 4.0 have?
Where does PCI DSS 4.0 apply?
What frameworks does PCI DSS 4.0 map to?
How do I get started with PCI DSS 4.0 compliance?
Query PCI DSS 4.0 programmatically
PCI DSS 4.0, its 168 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
PCI DSS 4.0 API reference and MCP config →What PCI DSS 4.0 requires, control by control
Each page carries the requirement text for one PCI DSS 4.0 control and what an assessor expects to see as evidence.
- 1-1-1 NSC policies and procedures documented
- 1-1-2 Roles and responsibilities for Requirement 1
- 1-2-1 NSC configuration standards defined
- 1-2-2 Changes to NSC reviewed and approved
- 1-2-3 Network diagrams maintained
- 1-2-4 Data flow diagram of account data
- 1-2-5 Services, protocols, ports inventoried and justified
- 1-2-6 Security features for insecure services defined
- 1-2-7 NSC rule sets reviewed every six months
- 1-2-8 Configuration files secured and synchronised
How much of another standard PCI DSS 4.0 already covers
Each crosswalk is judged control by control, and the mappings that were rejected are kept alongside the ones that held.
- ACSC Essential Eight to PCI DSS 4.0 crosswalk
- ANSSI Guide d'hygiene informatique (42 mesures, v2.0) to PCI DSS 4.0 crosswalk
- PCI DSS 4.0 to APRA CPS 234 crosswalk
- ASD Strategies to Mitigate Cyber Security Incidents to PCI DSS 4.0 crosswalk
- Australia Consumer Data Right - Banking (CDR) to PCI DSS 4.0 crosswalk
- AWS Well-Architected Security Pillar to PCI DSS 4.0 crosswalk
- Azure Security Benchmark to PCI DSS 4.0 crosswalk
- C5 (Germany) to PCI DSS 4.0 crosswalk
How ready are you for PCI DSS 4.0?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.