← Strondex

PCI DSS Compliance Checklist

Free preview. You're seeing the first 10 of 78 controls. 78 PCI DSS v4.0 controls with SAQ-A and SAQ-D scoping guidance.
Scope & Network Segmentation 6 controls
CRITICAL PCI-SCOPE-01 Scoping

Define and document the Cardholder Data Environment (CDE).

How to verify / fix

Produce a current data-flow diagram and inventory identifying every system that stores, processes, or transmits cardholder data, plus connected systems. A QSA expects a dated CDE definition and data-flow diagrams that match the live environment.

CRITICAL PCI-SCOPE-02 Scoping

Isolate the CDE from out-of-scope systems with network segmentation.

How to verify / fix

Use firewalls, VLANs, or access controls so only required traffic reaches the CDE; without segmentation, the entire network is in scope. Evidence is network/segmentation diagrams plus firewall or ACL rules enforcing the boundary.

HIGH PCI-SCOPE-03 Scoping

Test segmentation controls at least annually and after any change.

How to verify / fix

Have a tester confirm out-of-scope networks cannot reach the CDE; re-test after changes affecting segmentation. A QSA expects a dated segmentation penetration-test report with results and methodology.

HIGH PCI-SCOPE-04 Scoping

Maintain an inventory of all in-scope system components.

How to verify / fix

Keep a current list of in-scope hardware, software, and cloud resources with owner and function. Evidence is a maintained asset inventory that reconciles to the CDE definition and data-flow diagrams.

MEDIUM PCI-SCOPE-05 Scoping

Review scope at least annually and after significant changes.

How to verify / fix

Run a documented annual scoping exercise (and after acquisitions, new payment channels, or architecture changes) to confirm nothing fell out of scope by mistake. Evidence is a dated scoping review record.

LOW PCI-SCOPE-06 Scoping

Select the correct SAQ type with qualified guidance.

How to verify / fix

Confirm which SAQ (A, A-EP, B, C, D) matches how you accept payments, ideally validated by a QSA or your acquirer. Evidence is documentation of the chosen validation type and the rationale behind it.

Network Security Controls 4 controls
CRITICAL PCI-NET-01 Network

Install firewalls at every internet connection and between the DMZ and internal network.

How to verify / fix

Deploy network security controls at each trust boundary so internet-facing traffic terminates in a DMZ, never directly on internal systems. Evidence is the firewall configuration and a network diagram showing controls at every boundary.

CRITICAL PCI-NET-02 Network

Allow no direct public access between the internet and any CDE component.

How to verify / fix

Ensure no CDE system has a public IP or inbound internet route; all access passes through controlled, proxied paths. Evidence is firewall/routing rules and a network diagram proving the CDE has no direct internet exposure.

HIGH PCI-NET-03 Network

Document, review, and approve firewall rules at least every six months.

How to verify / fix

Keep a rule-set with documented business justification and run a formal semi-annual review with sign-off. A QSA expects dated rule-review records showing approval and removal of stale rules.

HIGH PCI-NET-04 Network

Restrict inbound and outbound CDE traffic to only what is necessary.

How to verify / fix

Apply default-deny rules and allow only documented, business-justified ports, protocols, and destinations. Evidence is the rule-set with per-rule justification and a default-deny posture for everything not explicitly permitted.

68 more controls — unlock the full checklist

The full PCI DSS Compliance Checklist has 78 controls with the interactive self-assessment tool (track Pass / Fail / Partial, see your readiness score, and export a PDF report). One-time purchase, instant access.

Not ready to buy? Try the free Cyber Insurance Readiness Score.