Alastor InfoSec
← All Checklists

PCI DSS Compliance Checklist

A working checklist against PCI DSS v4.0 for merchants and service providers handling cardholder data. Pair this with our full PCI DSS compliance program for implementation detail.

Network Security

  • Cardholder Data Environment (CDE) is segmented from the rest of the network
  • Firewall and router configurations reviewed and documented on a defined schedule
  • Default vendor credentials and security parameters have been changed everywhere

Cardholder Data Protection

  • Stored cardholder data is minimized — only what's strictly necessary is retained
  • Primary Account Numbers (PANs) are rendered unreadable wherever stored (encryption, tokenization, or truncation)
  • Cardholder data is encrypted in transit across open, public networks

Vulnerability Management

  • Anti-malware protection deployed on all systems commonly affected
  • Secure development practices applied to any custom software touching the CDE
  • Continuous vulnerability scanning covers all in-scope systems, internal and external

Access Control

  • Access to cardholder data restricted on a need-to-know basis
  • Unique IDs assigned to every user with system access
  • MFA enforced for all access into the CDE, including remote access
  • Physical access to systems storing cardholder data is restricted and monitored

Monitoring & Testing

  • All access to network resources and cardholder data is logged
  • Log reviews happen daily or through an automated alerting mechanism
  • Penetration testing performed at least annually and after significant infrastructure changes — continuously where v4.0's targeted risk analysis calls for it
  • Intrusion detection or file integrity monitoring deployed on critical systems

Policy & Governance

  • Information security policy addresses PCI DSS requirements and is reviewed annually
  • Formal risk assessment process is documented and followed
  • Incident response plan is tested and includes payment-brand notification procedures

Where Alastor InfoSec Fits

Alastor Shield automates evidence collection against PCI DSS v4.0 requirements, keeping documentation audit-ready year-round. Alastor Pulse and Attack Surface Management provide the continuous testing and CDE visibility that v4.0's targeted risk analysis approach increasingly expects over a single annual test.

Talk to our team about a PCI DSS readiness assessment scored against this checklist.

We use cookies to keep the platform secure and understand how our site is used. See our Security & Data policy for details.