---
title: "PCI DSS Compliance Checklist"
description: "A practical checklist for PCI DSS v4.0 readiness — network segmentation, cardholder data protection, access control, and continuous testing requirements."
keywords:
  - PCI DSS checklist
  - PCI compliance checklist
  - PCI DSS v4.0 checklist
  - cardholder data security checklist
---

# PCI DSS Compliance Checklist

A working checklist against PCI DSS v4.0 for merchants and service providers handling cardholder data. Pair this with our full [PCI DSS compliance program](/compliance/pci-dss) for implementation detail.

## Network Security

- [ ] Cardholder Data Environment (CDE) is segmented from the rest of the network
- [ ] Firewall and router configurations reviewed and documented on a defined schedule
- [ ] Default vendor credentials and security parameters have been changed everywhere

## Cardholder Data Protection

- [ ] Stored cardholder data is minimized — only what's strictly necessary is retained
- [ ] Primary Account Numbers (PANs) are rendered unreadable wherever stored (encryption, tokenization, or truncation)
- [ ] Cardholder data is encrypted in transit across open, public networks

## Vulnerability Management

- [ ] Anti-malware protection deployed on all systems commonly affected
- [ ] Secure development practices applied to any custom software touching the CDE
- [ ] Continuous vulnerability scanning covers all in-scope systems, internal and external

## Access Control

- [ ] Access to cardholder data restricted on a need-to-know basis
- [ ] Unique IDs assigned to every user with system access
- [ ] MFA enforced for all access into the CDE, including remote access
- [ ] Physical access to systems storing cardholder data is restricted and monitored

## Monitoring & Testing

- [ ] All access to network resources and cardholder data is logged
- [ ] Log reviews happen daily or through an automated alerting mechanism
- [ ] Penetration testing performed at least annually and after significant infrastructure changes — continuously where v4.0's targeted risk analysis calls for it
- [ ] Intrusion detection or file integrity monitoring deployed on critical systems

## Policy & Governance

- [ ] Information security policy addresses PCI DSS requirements and is reviewed annually
- [ ] Formal risk assessment process is documented and followed
- [ ] Incident response plan is tested and includes payment-brand notification procedures

## Where Alastor InfoSec Fits

[Alastor Shield](/products/alastor-shield) automates evidence collection against PCI DSS v4.0 requirements, keeping documentation audit-ready year-round. [Alastor Pulse](/products/alastor-pulse) and [Attack Surface Management](/features/attack-surface-management) provide the continuous testing and CDE visibility that v4.0's targeted risk analysis approach increasingly expects over a single annual test.

[Talk to our team](/about-us) about a PCI DSS readiness assessment scored against this checklist.
