Skip to content
complianceofficer

PCI compliance software that tracks PCI DSS 4.0.1 changes

PCI compliance software helps a merchant or service provider meet the Payment Card Industry Data Security Standard: it maps the 12 PCI DSS requirements to the controls you already run, points you at the right Self-Assessment Questionnaire, keeps the evidence a QSA or your acquiring bank asks for, and tracks quarterly ASV scans. Complianceofficer adds the part most PCI tools skip: it watches what the PCI Security Standards Council actually publishes, so when the next standard revision or e-commerce script requirement lands you hear it from the tool, not from your assessor.

Scan your PCI DSS obligations now

Pick your sector and PCI DSS below. The scan returns the obligation register with the last 12 months of regulatory movement, sources linked. No signup, nothing stored.

§ Live · Compliance scan

No signup. Nothing you pick is stored.

Frameworks you answer to

Sample register · fintech, US · what a scan returns

  • § 01 Written AML program with a named officer
  • § 02 KYC and customer due diligence
  • § 03 Sanctions screening lists Changed
  • § 04 PCI DSS v4.0 validation

The 12 PCI DSS requirements, mapped to your controls

PCI DSS groups its 12 requirements under six control objectives. The register below is what the scan builds for a card-handling business, each line tied to the policies and technical controls you already have.

  • § 01 Network security controls and secure configurations Req 1 to 2
  • § 02 Protect stored account data and encrypt it in transit Req 3 to 4
  • § 03 Anti-malware and secure software development Req 5 to 6
  • § 04 Payment page scripts and change detection Req 6.4.3, 11.6.1
  • § 05 Access control, authentication and physical access Req 7 to 9
  • § 06 Log and monitor all access to cardholder data Req 10
  • § 07 ASV scans and regular penetration testing Req 11 · quarterly
  • § 08 Information security policy and risk program Req 12

Each line maps to a policy, a control and the evidence your assessor will sample. When the Council revises the standard, issues new guidance, or an e-commerce requirement changes, the affected lines flag seal-red, the alert explains what moved in plain language, and the policy edit is drafted for your review. The loop is described on how it works.

§ 12 What actually changed

PCI DSS v4.0.1 is the standard you are assessed against now

A lot of buyer confusion comes from pages that still describe v3.2.1 or treat the v4.x requirements as optional. They are not. Here is the state of play as of July 2026.

PCI DSS v4.0.1 was published in June 2024 as a limited revision: it corrects errata and clarifies intent, and it adds and deletes no requirements. It fully replaced v4.0 on 31 December 2024, so v4.0.1 is the only version an assessment references today. More importantly, the 51 future-dated requirements introduced in v4.x became mandatory on 31 March 2025, with no grace period. Every PCI DSS assessment since then must validate them.

Two of those newly mandatory items catch e-commerce merchants off guard. Requirement 6.4.3 means you must manage and authorize every script that loads on a payment page, and Requirement 11.6.1 means you must detect unauthorized changes to that page. These exist because of digital skimming, and a SAQ A merchant who assumed they were out of scope often is not. This is exactly the kind of change a regulatory change management engine is meant to surface before your assessor does.

Which PCI validation path applies to you

Your merchant level decides how you validate. Read the row that matches your transaction volume and how you take payments.

Level Roughly who How you validate
Level 1 Over 6 million card transactions a year, or any merchant a brand designates Annual Report on Compliance by a QSA, plus quarterly ASV scans
Level 2 1 to 6 million transactions a year Annual SAQ and Attestation of Compliance, plus ASV scans
Level 3 20,000 to 1 million e-commerce transactions a year Annual SAQ and Attestation of Compliance, plus ASV scans
Level 4 Under 20,000 e-commerce, or up to 1 million other transactions Annual SAQ; scanning and scope set by your acquiring bank

Thresholds vary slightly by card brand, and your acquiring bank has the final say on what you must submit. The right Self-Assessment Questionnaire also depends on how you accept payments, from SAQ A for fully outsourced e-commerce to SAQ D for everyone who stores account data. If you also carry SOC 2 or ISO 27001, the control overlap is large, and our SOC 2 compliance software and ISO 27001 compliance software pages explain how to reuse the same evidence.

§ 13 Questions buyers ask

PCI compliance software questions, answered

What is the current version of PCI DSS?

PCI DSS v4.0.1 is the current standard. It was published in June 2024 as a limited revision that corrects errata and clarifies intent, and it fully replaced v4.0 on 31 December 2024. The 51 future-dated requirements from v4.x became mandatory on 31 March 2025 with no grace period, so every assessment now validates against them. Any tool or guide still built around v3.2.1 is out of date.

Do I need a QSA or can I self-assess?

It depends on your merchant level. Level 1 merchants, generally those over 6 million card transactions a year, need an annual Report on Compliance signed by a Qualified Security Assessor plus quarterly ASV scans. Levels 2 to 4 usually validate with the correct Self-Assessment Questionnaire and an Attestation of Compliance. Your acquiring bank can always require more, so confirm your obligations with them.

Can PCI compliance software make me compliant?

No single product makes you PCI compliant, and no vendor can sell you a PCI certification the Council recognizes. Compliance is validated through an assessment or a Self-Assessment Questionnaire against your actual environment. What software does is reduce the work: it scopes your cardholder data environment, maps the 12 requirements to your controls, collects evidence, and tracks scans and findings so validation is faster.

What are the new payment page script requirements?

Requirements 6.4.3 and 11.6.1, mandatory since 31 March 2025, target digital skimming on e-commerce checkout pages. 6.4.3 requires you to inventory and authorize every script that loads on a payment page and confirm its integrity. 11.6.1 requires a change and tamper-detection mechanism that alerts on unauthorized modifications to the page as received by the browser. Many SAQ A merchants who thought they were out of scope are not.

How does PCI relate to SOC 2 and ISO 27001?

They overlap heavily on access control, encryption, logging, vulnerability management and incident response, so evidence collected for one covers much of another. PCI is narrower and prescriptive, scoped to cardholder data, while SOC 2 and ISO 27001 assess a broader security program. Most teams that take cards end up carrying more than one, which is why reusing controls across frameworks is the practical way to keep the cost down.

Last updated July 2026. General regulatory information, not legal advice.

Run the compliance scan

§ 99 · Final entry

Get on the early-access list

Leave your work email, confirm the 6-digit code, and we will email you when your spot opens. Nothing is charged before launch.