Sentrix

Framework · PCI DSS v4.0.1

PCI DSS v4.0.1: 12 requirements, one evidence program

Payment Card Industry Data Security Standard: twelve requirements, quarterly vulnerability scans and annual validation by a QSA report or self-assessment.

PCI DSS is the PCI Security Standards Council standard for any organization that stores, processes, or transmits cardholder data, anywhere in the world. Version 4.0.1, published in June 2024, replaces version 4.0. Version 4 introduced the customized approach, which allows more flexible control implementation but requires more documentation, as well as new requirements for phishing-resistant MFA, targeted risk analysis, and application security testing.

Key facts

  • 12 requirements: grouped into six control objectives, from the network to organizational policies.
  • v4.0.1: current version, published in June 2024.
  • March 2025: date on which all version 4 requirements became mandatory.
  • Quarterly and annual: internal and external vulnerability scans every quarter; annual validation by a QSA (ROC) or by self-assessment questionnaire (SAQ).

What PCI DSS requires

The scope is the cardholder data environment (CDE). Every validation requires a CDE inventory, network segmentation verification and current data flow diagrams.

  1. Req. 1–2: network security controls and secure configuration
  2. Req. 3–4: protect cardholder data at rest and in transit
  3. Req. 5–6: protect against malicious software and vulnerable systems
  4. Req. 7–9: restrict access, authentication and physical security
  5. Req. 10–11: log monitoring, vulnerability management, and quarterly scanning
  6. Req. 12: support information security with organizational policies

What Sentrix provides for PCI DSS

CDE scoping and data flow

Automated cardholder data environment inventory with network segmentation verification. Data flow diagrams updated continuously as your infrastructure changes.

Quarterly scan tracking

PCI DSS requires quarterly internal and external vulnerability scans. Sentrix tracks scan schedules, ingests results from your vulnerability scanners, and alerts you before the deadline.

Version 4 requirements

Tracking of the requirements specific to version 4: targeted risk analysis, phishing-resistant MFA documentation, and application security testing evidence collection.

SAQ preparation

For merchants and service providers validating with SAQ A, A-EP, B, B-IP, C, D, or P2PE, Sentrix pre-populates the Self-Assessment Questionnaire from your actual control configuration.

QSA workspace

Give your Qualified Security Assessor read-only access to your complete evidence set. Pre-formatted ROC documentation; all evidence linked and timestamped.

Drift alerts

CDE controls are monitored continuously; a changed segmentation or a missed scan surfaces before the annual review.

Crosswalks

  • SOC 2: PCI DSS controls mapped to the Trust Services Criteria.
  • ISO 27001: PCI DSS controls mapped to Annex A.
  • OSFI B-10 / B-13: for federally regulated financial institutions holding both.
  • DORA: for EU financial entities.

Further reading

Financial services solution.

See your PCI DSS coverage on your real CDE.

Contact us

Frequently asked questions

Who does PCI DSS apply to?
PCI DSS applies to any organization that stores, processes, or transmits cardholder data, whatever its country or size: merchants, service providers and financial institutions. The scope is the cardholder data environment (CDE), whose inventory, network segmentation and data flow diagrams are required for every validation.
What is the difference between an SAQ and a Report on Compliance (ROC)?
The Self-Assessment Questionnaire (SAQ) is the validation method for eligible merchants and service providers; it comes in several types (A, A-EP, B, B-IP, C, D, P2PE) depending on how cards are handled. The Report on Compliance (ROC) is produced by a Qualified Security Assessor (QSA) after an on-site assessment. Sentrix pre-populates the SAQ from your actual configuration and gives the QSA read-only access to the evidence.
What is the customized approach in version 4?
Version 4 of PCI DSS introduced the customized approach, which allows a control to be implemented differently from the defined method, provided the organization demonstrates that the security objective is met. It offers more flexibility but requires more documentation, including a targeted risk analysis. Version 4 also added requirements for phishing-resistant MFA and application security testing.

Let's talk about your compliance program.

Last updated: 2026-09-17