PCI DSS: cardholder data controls, checked where the data lives
Map the twelve PCI DSS requirements to controls with automated checks on your cloud, network and identity systems, keep the scope and the segmentation evidence current, and prepare the Report on Compliance or Self-Assessment Questionnaire from the same evidence base.
What is PCI DSS?
PCI DSS, the Payment Card Industry Data Security Standard, is the security standard the major card brands require of every organization that stores, processes or transmits cardholder data, administered by the PCI Security Standards Council. Version 4.0.1 is the current edition; the requirements version 4.0 had future-dated became mandatory on 31 March 2025. The standard has twelve requirements grouped under six goals: a secure network and systems, protection of account data, a vulnerability management program, strong access control, regular monitoring and testing, and an information security policy. How an organization validates compliance depends on its level, set by transaction volume. Level 1 merchants and service providers have an annual on-site assessment by a Qualified Security Assessor that produces a Report on Compliance; lower levels complete a Self-Assessment Questionnaire; all have quarterly external vulnerability scans by an Approved Scanning Vendor and sign an Attestation of Compliance. The scope, the cardholder data environment and the segmentation that limits it, decides most of the work.
The Payment Card Industry Data Security Standard is the card brands' standard for any organization that stores, processes or transmits cardholder data. Version 4.0.1 is current, with the requirements that were future-dated in version 4.0 mandatory since 31 March 2025. Compliance is validated every year: large merchants and service providers through a Report on Compliance by a Qualified Security Assessor, smaller ones through a Self-Assessment Questionnaire, both with quarterly external vulnerability scans by an Approved Scanning Vendor and an Attestation of Compliance.
Merchants, payment service providers and any SaaS company whose product touches card data or whose customers' acquirers ask for an Attestation of Compliance.
How Viglyn runs PCI DSS
- The twelve requirements mapped to controls, with automated checks on encryption, access, logging, configuration and patching across your cloud, network and identity systems
- The cardholder data environment and its segmentation recorded as dated evidence, with the scope decisions and their reasons
- Quarterly external scans and penetration tests tracked with their findings and remediation in the vulnerability module
- Policies, training records and the responsibility matrix for shared providers held as controlled documents with a full audit trail
- The Report on Compliance or Self-Assessment Questionnaire prepared from the evidence base, with your QSA working through scoped access
The PCI DSS questions that decide it
Do we need a QSA for PCI DSS?
Level 1 merchants and service providers do: a Qualified Security Assessor performs the annual assessment and signs the Report on Compliance. Lower levels can self-assess with a questionnaire, though acquirers and customers often ask for a QSA anyway. Either way the evidence is the same, and Viglyn keeps it ready.
How long does PCI DSS take?
It depends almost entirely on scope. A tokenized SaaS product that never touches card data can validate in weeks; a platform that stores cardholder data has a cardholder data environment to secure, segment and prove, which takes months. Viglyn's practitioners scope the environment with you first, so the work is sized before it starts.
How much does PCI DSS cost with Viglyn?
PCI DSS counts as one of the frameworks included in your plan, from $2,699 a year with implementation by our practitioners included. The QSA's fee and the ASV scans are separate and paid by you directly; we take no commission.
More PCI DSS questions
What changed in PCI DSS 4.0?
Can PCI DSS share evidence with SOC 2 and ISO 27001?
What are the merchant levels?
See PCI DSS run on your stack
A 30-minute walkthrough with your systems and your framework. No commitment.
