All workspaces
Payment Card Industry Data Security Standard, PCI DSS v4.0

PCI DSS Compliance: Protect Cardholder Data and Meet Payment Security Requirements

If your business stores, processes, or transmits credit card data, PCI DSS compliance is not optional. Waaqi helps merchants and service providers scope, remediate, and validate compliance under PCI DSS v4.0.

01Inside the workspace

Preloaded and ready on day one

Controls, evidence requests, and reporting views come configured, so your team starts on execution instead of setup.

  • All 12 PCI DSS v4.0 requirements pre-loaded and scoped
  • Cardholder data environment scoping and network diagrams
  • Control ownership, testing, and evidence tracking
  • Vulnerability and penetration test management
  • Service provider and merchant compliance tracking
  • Assessor-ready reporting and compliance attestations

What Is PCI DSS?

The Payment Card Industry Data Security Standard, known as PCI DSS, is a set of security requirements created by the PCI Security Standards Council, whose founding members include Visa, Mastercard, American Express, Discover, and JCB. The standard applies to every organization that stores, processes, or transmits cardholder data, regardless of size or industry.

The current version, PCI DSS v4.0, replaced v3.2.1 and introduces stronger authentication rules, expanded encryption requirements, and a customized implementation approach that gives organizations more flexibility in how they meet control objectives.

The 12 Core Requirements of PCI DSS

  • Install and maintain network security controls
  • Apply secure configurations to all system components
  • Protect stored cardholder data
  • Encrypt cardholder data during transmission over open, public networks
  • Protect systems and networks from malicious software
  • Develop and maintain secure systems and software
  • Restrict access to cardholder data based on business need to know
  • Identify users and authenticate access to system components
  • Restrict physical access to cardholder data
  • Log and monitor all access to system components and cardholder data
  • Test security of systems and networks regularly
  • Support information security with organizational policies and programs

PCI DSS Merchant Levels

LevelAnnual Transaction VolumeValidation Required
Level 1Over 6 million transactionsAnnual on site QSA audit
Level 21 to 6 million transactionsAnnual Self Assessment Questionnaire, may require QSA
Level 320,000 to 1 million e-commerce transactionsAnnual Self Assessment Questionnaire
Level 4Fewer than 20,000 e-commerce transactionsAnnual Self Assessment Questionnaire

Our PCI DSS Compliance Process

PhaseWhat Happens
1. ScopingIdentify all systems that touch cardholder data and define the cardholder data environment.
2. Gap assessmentCompare current controls against the 12 PCI DSS requirements.
3. RemediationClose gaps in network segmentation, encryption, access control, and logging.
4. ValidationComplete the applicable Self Assessment Questionnaire or QSA audit.
5. AttestationSubmit the Attestation of Compliance to acquiring banks and card brands.
6. Ongoing complianceMaintain quarterly scans, penetration testing, and continuous monitoring.
02FAQ

Questions we get asked

PCI DSS, the Payment Card Industry Data Security Standard, is a global security standard created by the major card brands to protect cardholder data. It applies to any organization that stores, processes, or transmits credit card information.

Any merchant, payment processor, or service provider that stores, processes, or transmits cardholder data must comply with PCI DSS, regardless of transaction volume, though requirements scale by merchant level.

Merchant levels are based on annual transaction volume, ranging from Level 1 for merchants processing over six million transactions a year, which requires an on site QSA audit, down to Level 4 for the smallest merchants, which typically requires only a Self Assessment Questionnaire.

PCI DSS v4.0 is the current version of the standard, replacing v3.2.1. It introduces enhanced authentication requirements, expanded encryption rules, and a customized approach that lets organizations meet control objectives through alternative implementations.

Non compliant organizations risk fines from card brands and acquiring banks, increased transaction fees, loss of the ability to process card payments, and greater liability in the event of a data breach.

See the PCI DSS Compliance: Protect Cardholder Data and Meet Payment Security Requirements in action

Book a session with our team and we will provision a sandbox tenant for your organisation with this workspace enabled.

Book a demo