PCI DSS Compliance Checklist
A working checklist against PCI DSS v4.0 for merchants and service providers handling cardholder data. Pair this with our full PCI DSS compliance program for implementation detail.
Network Security
- Cardholder Data Environment (CDE) is segmented from the rest of the network
- Firewall and router configurations reviewed and documented on a defined schedule
- Default vendor credentials and security parameters have been changed everywhere
Cardholder Data Protection
- Stored cardholder data is minimized — only what's strictly necessary is retained
- Primary Account Numbers (PANs) are rendered unreadable wherever stored (encryption, tokenization, or truncation)
- Cardholder data is encrypted in transit across open, public networks
Vulnerability Management
- Anti-malware protection deployed on all systems commonly affected
- Secure development practices applied to any custom software touching the CDE
- Continuous vulnerability scanning covers all in-scope systems, internal and external
Access Control
- Access to cardholder data restricted on a need-to-know basis
- Unique IDs assigned to every user with system access
- MFA enforced for all access into the CDE, including remote access
- Physical access to systems storing cardholder data is restricted and monitored
Monitoring & Testing
- All access to network resources and cardholder data is logged
- Log reviews happen daily or through an automated alerting mechanism
- Penetration testing performed at least annually and after significant infrastructure changes — continuously where v4.0's targeted risk analysis calls for it
- Intrusion detection or file integrity monitoring deployed on critical systems
Policy & Governance
- Information security policy addresses PCI DSS requirements and is reviewed annually
- Formal risk assessment process is documented and followed
- Incident response plan is tested and includes payment-brand notification procedures
Where Alastor InfoSec Fits
Alastor Shield automates evidence collection against PCI DSS v4.0 requirements, keeping documentation audit-ready year-round. Alastor Pulse and Attack Surface Management provide the continuous testing and CDE visibility that v4.0's targeted risk analysis approach increasingly expects over a single annual test.
Talk to our team about a PCI DSS readiness assessment scored against this checklist.