PCI DSS Compliance Checklist (v4.0)
PCI DSS scope is where most assessments go sideways. This checklist covers 78 controls across all twelve PCI DSS v4.0 requirement areas, with SAQ-A and SAQ-D annotations, so you can define your cardholder data environment, segment it, and close gaps before your QSA does.
See exactly what you're buying before you pay, no email, no account. One-time purchase · instant download · 78 controls with verification & remediation steps.
What's inside
78 controls across 12 categories
Every control is plain-language, prioritized by severity, and paired with how to verify it and how to fix it. Organized into 12 sections.
Real sample controls
A look at the highest-severity controls
These are taken directly from the checklist, no paraphrasing.
- PCI-SCOPE-01CRITICALScoping
Define and document the Cardholder Data Environment (CDE).
- PCI-SCOPE-02CRITICALScoping
Isolate the CDE from out-of-scope systems with network segmentation.
- PCI-NET-01CRITICALNetwork
Install firewalls at every internet connection and between the DMZ and internal network.
- PCI-NET-02CRITICALNetwork
Allow no direct public access between the internet and any CDE component.
PCI DSS Compliance Checklist
- 78 prioritized controls
- Verify & fix steps for each control
- 12 categories across 12 sections
- Instant download · lifetime access
Upgrade to the Complete Bundle, save $285
Get all 6 checklists for $497 ($782 bought separately).
Add the bundle instead ›By purchasing you agree to our Terms. Digital products are non-refundable once accessed.
See it first, free
Preview the checklist before you pay
Open the first 10 controls in your browser, real, unredacted, exactly as they appear in the checklist. No login, no email, no card. See precisely what you're buying before you spend a cent.
Why teams buy with confidence
Instant access
Pay and the download link lands in your inbox immediately, no waiting, no sales call.
Lifetime updates
Frameworks change. When the controls do, you get the updated version at no extra cost.
Built by practitioners
Controls drawn from CIS benchmarks, framework requirements, and real assessment findings.
Secure checkout
Payment is processed by Stripe. We never see or store your card details.

Built by practitioners, not a content mill
Built by Jason Dobbs, a technology leader and cybersecurity strategist with more than two decades of experience hardening Microsoft 365, Azure, and AWS for small and mid-sized businesses across regulated industries, healthcare, finance, law, real estate, energy, and the public sector. These controls are drawn from real assessments and the security questions cyber insurers actually ask.
We'll always make it right.
If a checklist isn't what you needed, email us, we'll get you to the right one or find a resolution that works.
Exactly 78 controls, no inflated counts. One-time purchase · digital product · non-refundable once accessed.
“Before we worked with Strondex, SOC 2 felt like a moving target. Jason simplified the entire process. His team performed a thorough assessment, developed clear action plans, helped us implement the controls, and made sure we had the evidence the audit required. They were responsive at every step. We completed our SOC 2 audit successfully and came away with a much stronger understanding of security governance.”
“We engaged Strondex to prepare for a PCI DSS assessment and expected guidance. What we received was a true partnership. Jason and his team helped us close longstanding compliance gaps, improve our documentation, validate technical controls, and prepare our staff for the auditor’s questions. By the time the audit arrived, everything was organized and ready. We passed with ease and earned positive feedback from the assessor on the maturity of our security program.”
Frequently asked questions
Does this checklist cover PCI DSS v4.0?
Yes. All 78 controls are written for PCI DSS v4.0 and annotated for SAQ-A and SAQ-D so you can focus on the requirements that apply to your validation type.
What is the difference between SAQ-A and SAQ-D here?
SAQ-A applies to merchants who fully outsource cardholder data handling; SAQ-D is the most comprehensive. Controls are annotated so you only work through what your SAQ type requires.
Does completing this make me PCI compliant?
It prepares you for compliance and a QSA assessment. Formal PCI DSS validation is performed by a Qualified Security Assessor or via the appropriate self-assessment questionnaire and attestation.
Explore the rest of the library
Cyber Insurance Prep Checklist
47 controls underwriters actually check, know exactly where you stand before renewal.
View $47 ›M365 Security Hardening Checklist
80 CIS-based controls for Microsoft 365, close the gaps before attackers find them.
View $97 ›AWS Hardening Checklist
95 CIS L1/L2 controls for AWS, IAM, logging, networking, storage, and more.
View $147 ›Azure Hardening Checklist
88 CIS-based controls for Microsoft Azure, identity to networking to Defender.
View $147 ›SOC 2 Checklist
85 controls mapped to AICPA Trust Services Criteria, know your audit readiness score.
View $197 ›