Skip to main content
PCI DSS

PCI DSS Compliance
for Cardholder Data Environments

PCI DSS v4.0 defines how organisations that store, process or transmit cardholder data must protect payment information. Basenorm centralises scope, the 12 PCI DSS requirements, evidence collection and QSA collaboration in one governance model.

CDE Scoping and Segmentation

Define the cardholder data environment, document flows and segmentation, and maintain accurate network diagrams linked to controls and evidence.

  • CDE definition and data flow documentation
  • Network segmentation and scope reduction
  • Tokenisation and storage minimisation strategies
  • Asset inventory linked to the Governance Graph
  • Merchant and service provider level determination

12 PCI DSS Requirements

v4.0

Network Security

Requirements 1-2

24 controls

Data Protection

Requirements 3-4

18 controls

Access Control

Requirements 7-9

32 controls

Monitoring

Requirements 10-11

28 controls

Policy

Requirements 12

14 controls
Total Controls116

Cardholder Data Environment

Corporate Network
CDE Boundary
Payment Server
Card Database
POS Systems
Systems in CDE12
Segmentation StatusVerified
Last Scope ReviewJan 2026

Network segmentation reduces scope

The 12 PCI DSS Requirements

Operate the 12 PCI DSS requirements in the Unified Control Library, with automated evidence from systems and integrations to reduce audit effort.

  • Network security and system configuration
  • Protect stored and transmitted cardholder data
  • Vulnerability management and secure development
  • Access control, authentication and logging
  • Regular testing and information security policy

QSA Collaboration and Continuous Compliance

Work with your QSA or ISA through structured request lists, evidence repositories and issue tracking, and maintain continuous compliance between ROC / SAQ cycles.

  • Structured QSA and ISA workspace
  • ROC and SAQ preparation workflows
  • Continuous testing and evidence collection
  • Customized Approach and compensating controls
  • PCI DSS v4.0 timeline and maturity tracking

Quarterly Scan & Pen Test

ASV Scan

Q4 2025

Passed

Penetration Test

Dec 2025

Passed

ASV Scan

Q1 2026

Scheduled

Internal Scan

Weekly

Passed
Vulnerability Status

0

Critical

0

High

3

Medium

PCI DSS v4.0 validation schedule

Ready to operationalise PCI DSS?

Join merchants and service providers using Basenorm to manage PCI DSS across scoping, the 12 requirements, QSA collaboration and continuous compliance.

Frequently Asked Questions

Explore frequently asked questions about PCI DSS and related compliance topics.