PCI DSS Compliance Checklist
Scope & Network Segmentation 6 controls
Define and document the Cardholder Data Environment (CDE).
How to verify / fix
Produce a current data-flow diagram and inventory identifying every system that stores, processes, or transmits cardholder data, plus connected systems. A QSA expects a dated CDE definition and data-flow diagrams that match the live environment.
Isolate the CDE from out-of-scope systems with network segmentation.
How to verify / fix
Use firewalls, VLANs, or access controls so only required traffic reaches the CDE; without segmentation, the entire network is in scope. Evidence is network/segmentation diagrams plus firewall or ACL rules enforcing the boundary.
Test segmentation controls at least annually and after any change.
How to verify / fix
Have a tester confirm out-of-scope networks cannot reach the CDE; re-test after changes affecting segmentation. A QSA expects a dated segmentation penetration-test report with results and methodology.
Maintain an inventory of all in-scope system components.
How to verify / fix
Keep a current list of in-scope hardware, software, and cloud resources with owner and function. Evidence is a maintained asset inventory that reconciles to the CDE definition and data-flow diagrams.
Review scope at least annually and after significant changes.
How to verify / fix
Run a documented annual scoping exercise (and after acquisitions, new payment channels, or architecture changes) to confirm nothing fell out of scope by mistake. Evidence is a dated scoping review record.
Select the correct SAQ type with qualified guidance.
How to verify / fix
Confirm which SAQ (A, A-EP, B, C, D) matches how you accept payments, ideally validated by a QSA or your acquirer. Evidence is documentation of the chosen validation type and the rationale behind it.
Network Security Controls 4 controls
Install firewalls at every internet connection and between the DMZ and internal network.
How to verify / fix
Deploy network security controls at each trust boundary so internet-facing traffic terminates in a DMZ, never directly on internal systems. Evidence is the firewall configuration and a network diagram showing controls at every boundary.
Allow no direct public access between the internet and any CDE component.
How to verify / fix
Ensure no CDE system has a public IP or inbound internet route; all access passes through controlled, proxied paths. Evidence is firewall/routing rules and a network diagram proving the CDE has no direct internet exposure.
Document, review, and approve firewall rules at least every six months.
How to verify / fix
Keep a rule-set with documented business justification and run a formal semi-annual review with sign-off. A QSA expects dated rule-review records showing approval and removal of stale rules.
Restrict inbound and outbound CDE traffic to only what is necessary.
How to verify / fix
Apply default-deny rules and allow only documented, business-justified ports, protocols, and destinations. Evidence is the rule-set with per-rule justification and a default-deny posture for everything not explicitly permitted.
68 more controls — unlock the full checklist
The full PCI DSS Compliance Checklist has 78 controls with the interactive self-assessment tool (track Pass / Fail / Partial, see your readiness score, and export a PDF report). One-time purchase, instant access.
Not ready to buy? Try the free Cyber Insurance Readiness Score.