PCI DSS v4.0 checklist: all 12 requirements (and the v4 future-dated items)
PCI DSS v4.0's 12 requirements mapped to the evidence auditors expect, with each control flagged for what a platform can automate.
What PCI DSS requires
PCI DSS v4.0 is assessed against 12 requirements, grouped into six control objectives: build and maintain a secure network, protect account data, maintain a vulnerability management program, implement strong access control, monitor and test networks, and maintain an information security policy. Each must be both designed and operating — auditors want evidence it worked throughout the period, not just that it existed on paper.
The control checklist
All 12 PCI DSS v4.0 requirements, including the future-dated items that became mandatory March 2025. Use the table below as your working checklist — 12 line items. Controls marked Auto can be monitored continuously by SBCMSP; Manual controls need a documented process and human evidence.
| Control | Requirement | Coverage |
|---|---|---|
| Build & maintain a secure network | ||
| Req 1 | Install & maintain network security controls | Auto |
| Req 2 | Apply secure configurations to all system components | Auto |
| Protect account data | ||
| Req 3 | Protect stored account data | Auto |
| Req 4 | Strong cryptography for transmission over open networks | Auto |
| Vulnerability management | ||
| Req 5 | Protect systems & networks from malicious software | Auto |
| Req 6 | Develop & maintain secure systems & software | Auto |
| Access control | ||
| Req 7 | Restrict access by business need-to-know | Auto |
| Req 8 | Identify users & authenticate access (MFA for all CDE access) | Auto |
| Req 9 | Restrict physical access to cardholder data | Manual |
| Monitor & test | ||
| Req 10 | Log & monitor all access to system components | Auto |
| Req 11 | Test security of systems & networks regularly | Auto |
| Information security policy | ||
| Req 12 | Support security with organizational policies & programs | Manual |
Evidence you must collect
For every control, an auditor expects evidence it operated throughout the review period. Common examples:
- Access reviews with timestamps and approver
- Change tickets linked to deployments
- Encryption and configuration snapshots
- Vendor / supplier risk assessments on file
Automating the checklist
Roughly two-thirds of PCI DSS controls can be monitored automatically. SBCMSP watches those continuously, collects timestamped evidence, and flags drift — so the audit becomes a review of a report you already have, not a month-long scramble.
Frequently asked questions
How many requirements are in PCI DSS v4.0?
12 principal requirements, grouped into six control objectives. Each requirement contains many individual sub-requirements and testing procedures.
What changed in v4.0?
A customized-approach validation option, expanded authentication (including MFA for all access into the cardholder data environment), and future-dated requirements that became mandatory on 31 March 2025.
Who must comply with PCI DSS?
Any organization that stores, processes, or transmits cardholder data, plus service providers that could affect the security of that data. The validation level depends on annual transaction volume.
Which PCI DSS requirements can be automated?
Network security, secure configuration, vulnerability management, access control, and logging can be monitored continuously with timestamped evidence. Policy and awareness requirements still need documented processes.