Skip to content
New · AI governance: inventory your AI systems, check the controls, certify ISO 42001.See it
PCI DSS

PCI DSS: cardholder data controls, checked where the data lives

Map the twelve PCI DSS requirements to controls with automated checks on your cloud, network and identity systems, keep the scope and the segmentation evidence current, and prepare the Report on Compliance or Self-Assessment Questionnaire from the same evidence base.

What is PCI DSS?

PCI DSS, the Payment Card Industry Data Security Standard, is the security standard the major card brands require of every organization that stores, processes or transmits cardholder data, administered by the PCI Security Standards Council. Version 4.0.1 is the current edition; the requirements version 4.0 had future-dated became mandatory on 31 March 2025. The standard has twelve requirements grouped under six goals: a secure network and systems, protection of account data, a vulnerability management program, strong access control, regular monitoring and testing, and an information security policy. How an organization validates compliance depends on its level, set by transaction volume. Level 1 merchants and service providers have an annual on-site assessment by a Qualified Security Assessor that produces a Report on Compliance; lower levels complete a Self-Assessment Questionnaire; all have quarterly external vulnerability scans by an Approved Scanning Vendor and sign an Attestation of Compliance. The scope, the cardholder data environment and the segmentation that limits it, decides most of the work.

In one paragraph

The Payment Card Industry Data Security Standard is the card brands' standard for any organization that stores, processes or transmits cardholder data. Version 4.0.1 is current, with the requirements that were future-dated in version 4.0 mandatory since 31 March 2025. Compliance is validated every year: large merchants and service providers through a Report on Compliance by a Qualified Security Assessor, smaller ones through a Self-Assessment Questionnaire, both with quarterly external vulnerability scans by an Approved Scanning Vendor and an Attestation of Compliance.

Who it's for

Merchants, payment service providers and any SaaS company whose product touches card data or whose customers' acquirers ask for an Attestation of Compliance.

With Viglyn

How Viglyn runs PCI DSS

  • The twelve requirements mapped to controls, with automated checks on encryption, access, logging, configuration and patching across your cloud, network and identity systems
  • The cardholder data environment and its segmentation recorded as dated evidence, with the scope decisions and their reasons
  • Quarterly external scans and penetration tests tracked with their findings and remediation in the vulnerability module
  • Policies, training records and the responsibility matrix for shared providers held as controlled documents with a full audit trail
  • The Report on Compliance or Self-Assessment Questionnaire prepared from the evidence base, with your QSA working through scoped access
Straight answers

The PCI DSS questions that decide it

Do we need a QSA for PCI DSS?

Level 1 merchants and service providers do: a Qualified Security Assessor performs the annual assessment and signs the Report on Compliance. Lower levels can self-assess with a questionnaire, though acquirers and customers often ask for a QSA anyway. Either way the evidence is the same, and Viglyn keeps it ready.

How long does PCI DSS take?

It depends almost entirely on scope. A tokenized SaaS product that never touches card data can validate in weeks; a platform that stores cardholder data has a cardholder data environment to secure, segment and prove, which takes months. Viglyn's practitioners scope the environment with you first, so the work is sized before it starts.

How much does PCI DSS cost with Viglyn?

PCI DSS counts as one of the frameworks included in your plan, from $2,699 a year with implementation by our practitioners included. The QSA's fee and the ASV scans are separate and paid by you directly; we take no commission.

FAQ

More PCI DSS questions

What changed in PCI DSS 4.0?
A customized approach to meeting requirements alongside the defined one, targeted risk analyses, stronger authentication and encryption requirements, and more explicit roles and responsibilities. The requirements that were future-dated in 4.0 became mandatory on 31 March 2025, and 4.0.1 is the current edition.
Can PCI DSS share evidence with SOC 2 and ISO 27001?
Much of it. Access control, logging, vulnerability management, change management and policy evidence serves all three. In Viglyn one evidence base maps across them, so PCI DSS is a scoped addition rather than a separate program.
What are the merchant levels?
Four levels set by annual card transaction volume, with Level 1 the largest. The level decides how you validate: an on-site QSA assessment and Report on Compliance at Level 1, a Self-Assessment Questionnaire below it, and quarterly ASV scans for everyone with internet-facing systems in scope.

See PCI DSS run on your stack

A 30-minute walkthrough with your systems and your framework. No commitment.