PCI compliance software that tracks PCI DSS 4.0.1 changes
PCI compliance software helps a merchant or service provider meet the Payment Card Industry Data Security Standard: it maps the 12 PCI DSS requirements to the controls you already run, points you at the right Self-Assessment Questionnaire, keeps the evidence a QSA or your acquiring bank asks for, and tracks quarterly ASV scans. Complianceofficer adds the part most PCI tools skip: it watches what the PCI Security Standards Council actually publishes, so when the next standard revision or e-commerce script requirement lands you hear it from the tool, not from your assessor.
Scan your PCI DSS obligations now
Pick your sector and PCI DSS below. The scan returns the obligation register with the last 12 months of regulatory movement, sources linked. No signup, nothing stored.
§ Live · Compliance scan
No signup. Nothing you pick is stored.
Sample register · fintech, US · what a scan returns
- § 01 Written AML program with a named officer
- § 02 KYC and customer due diligence
- § 03 Sanctions screening lists Changed
- § 04 PCI DSS v4.0 validation
The 12 PCI DSS requirements, mapped to your controls
PCI DSS groups its 12 requirements under six control objectives. The register below is what the scan builds for a card-handling business, each line tied to the policies and technical controls you already have.
- § 01 Network security controls and secure configurations Req 1 to 2
- § 02 Protect stored account data and encrypt it in transit Req 3 to 4
- § 03 Anti-malware and secure software development Req 5 to 6
- § 04 Payment page scripts and change detection Req 6.4.3, 11.6.1
- § 05 Access control, authentication and physical access Req 7 to 9
- § 06 Log and monitor all access to cardholder data Req 10
- § 07 ASV scans and regular penetration testing Req 11 · quarterly
- § 08 Information security policy and risk program Req 12
Each line maps to a policy, a control and the evidence your assessor will sample. When the Council revises the standard, issues new guidance, or an e-commerce requirement changes, the affected lines flag seal-red, the alert explains what moved in plain language, and the policy edit is drafted for your review. The loop is described on how it works.
PCI DSS v4.0.1 is the standard you are assessed against now
A lot of buyer confusion comes from pages that still describe v3.2.1 or treat the v4.x requirements as optional. They are not. Here is the state of play as of July 2026.
PCI DSS v4.0.1 was published in June 2024 as a limited revision: it corrects errata and clarifies intent, and it adds and deletes no requirements. It fully replaced v4.0 on 31 December 2024, so v4.0.1 is the only version an assessment references today. More importantly, the 51 future-dated requirements introduced in v4.x became mandatory on 31 March 2025, with no grace period. Every PCI DSS assessment since then must validate them.
Two of those newly mandatory items catch e-commerce merchants off guard. Requirement 6.4.3 means you must manage and authorize every script that loads on a payment page, and Requirement 11.6.1 means you must detect unauthorized changes to that page. These exist because of digital skimming, and a SAQ A merchant who assumed they were out of scope often is not. This is exactly the kind of change a regulatory change management engine is meant to surface before your assessor does.
Which PCI validation path applies to you
Your merchant level decides how you validate. Read the row that matches your transaction volume and how you take payments.
| Level | Roughly who | How you validate |
|---|---|---|
| Level 1 | Over 6 million card transactions a year, or any merchant a brand designates | Annual Report on Compliance by a QSA, plus quarterly ASV scans |
| Level 2 | 1 to 6 million transactions a year | Annual SAQ and Attestation of Compliance, plus ASV scans |
| Level 3 | 20,000 to 1 million e-commerce transactions a year | Annual SAQ and Attestation of Compliance, plus ASV scans |
| Level 4 | Under 20,000 e-commerce, or up to 1 million other transactions | Annual SAQ; scanning and scope set by your acquiring bank |
Thresholds vary slightly by card brand, and your acquiring bank has the final say on what you must submit. The right Self-Assessment Questionnaire also depends on how you accept payments, from SAQ A for fully outsourced e-commerce to SAQ D for everyone who stores account data. If you also carry SOC 2 or ISO 27001, the control overlap is large, and our SOC 2 compliance software and ISO 27001 compliance software pages explain how to reuse the same evidence.
PCI compliance software questions, answered
What is the current version of PCI DSS?
PCI DSS v4.0.1 is the current standard. It was published in June 2024 as a limited revision that corrects errata and clarifies intent, and it fully replaced v4.0 on 31 December 2024. The 51 future-dated requirements from v4.x became mandatory on 31 March 2025 with no grace period, so every assessment now validates against them. Any tool or guide still built around v3.2.1 is out of date.
Do I need a QSA or can I self-assess?
It depends on your merchant level. Level 1 merchants, generally those over 6 million card transactions a year, need an annual Report on Compliance signed by a Qualified Security Assessor plus quarterly ASV scans. Levels 2 to 4 usually validate with the correct Self-Assessment Questionnaire and an Attestation of Compliance. Your acquiring bank can always require more, so confirm your obligations with them.
Can PCI compliance software make me compliant?
No single product makes you PCI compliant, and no vendor can sell you a PCI certification the Council recognizes. Compliance is validated through an assessment or a Self-Assessment Questionnaire against your actual environment. What software does is reduce the work: it scopes your cardholder data environment, maps the 12 requirements to your controls, collects evidence, and tracks scans and findings so validation is faster.
What are the new payment page script requirements?
Requirements 6.4.3 and 11.6.1, mandatory since 31 March 2025, target digital skimming on e-commerce checkout pages. 6.4.3 requires you to inventory and authorize every script that loads on a payment page and confirm its integrity. 11.6.1 requires a change and tamper-detection mechanism that alerts on unauthorized modifications to the page as received by the browser. Many SAQ A merchants who thought they were out of scope are not.
How does PCI relate to SOC 2 and ISO 27001?
They overlap heavily on access control, encryption, logging, vulnerability management and incident response, so evidence collected for one covers much of another. PCI is narrower and prescriptive, scoped to cardholder data, while SOC 2 and ISO 27001 assess a broader security program. Most teams that take cards end up carrying more than one, which is why reusing controls across frameworks is the practical way to keep the cost down.
Last updated July 2026. General regulatory information, not legal advice.
Run the compliance scanRelated registers
- Continuous Compliance Monitoring
- Compliance Monitoring Software
- Compliance Software Pricing
- Enterprise Compliance Software for CCOs and CISOs
- GRC Software Without the Six-Figure Suite
- GDPR Compliance Software That Tracks the Regulators
- Compliance Automation Software, AI-First
- AML Transaction Monitoring Plus Regulatory Watch
- SOC 2 Compliance Software Beyond Audit Readiness
- Policy Management Software Tied to the Regulation
- Regulatory Change Management Software, Continuous
- HIPAA Compliance Software with Security Risk Analysis
- ISO 27001 Compliance Software and ISMS Monitoring
- Vendor Risk Management Software for Third Party Risk
- Audit Management Software for Continuous Readiness
- SOX Compliance Software for SOX 404 Controls
- Best Compliance Software in 2026, Compared
- Vanta Alternative for Regulatory Change Monitoring
- Drata Alternative Focused on Regulatory Change
- Secureframe Alternative for Regulatory Change
- Sprinto Alternative for Regulatory Change
§ 99 · Final entry
Get on the early-access list
Leave your work email, confirm the 6-digit code, and we will email you when your spot opens. Nothing is charged before launch.