Governance. Risk. Compliance. Cybersecurity.
guide

PCI DSS v4.0.1 Self-Assessment Toolkit

A practical toolkit for SAQ A, SAQ A-EP and SAQ D environments — covering the new v4.0.1 requirements that became mandatory on 31 March 2025.

23 June 2026PCI DSSGuidePayments

What changed in v4.0.1

The PCI Council retired v3.2.1 in March 2024 and made every "future-dated" v4.0 requirement mandatory on 31 March 2025. Acquirers across the GCC now expect evidence of the new controls — including targeted risk analyses, customised approach worksheets, and phishing-resistant MFA on cardholder-data environments.

The toolkit covers

  • Scoping worksheet for SAQ A, SAQ A-EP and SAQ D
  • Targeted Risk Analysis (TRA) template for Req 12.3.1
  • Customised Approach Objective (CAO) worksheet for any tailored control
  • Network-segmentation evidence pack
  • Page-integrity monitoring runbook for e-commerce (Req 6.4.3 / 11.6.1)

Section 1 — Confirm your SAQ

If you... Use
Fully outsource e-commerce to a PCI-validated provider SAQ A
Host the payment page but redirect to a provider SAQ A-EP
Store, process or transmit cardholder data SAQ D

Section 2 — The 13 v4.0.1 requirements most teams miss

  1. 6.4.3 — Inventory of payment-page scripts with authorisation evidence
  2. 8.3.6 — Password length minimum increased to 12 characters
  3. 8.4.2 — MFA on all access into the CDE, including admins
  4. 8.5.1 — Phishing-resistant MFA for service providers
  5. 10.4.1.1 — Automated log review using a SIEM, not weekly spot-checks
  6. 11.3.1.1 — Authenticated internal vulnerability scans
  7. 11.4.7 — Multi-tenant penetration test segmentation
  8. 11.5.1.1 — Intrusion-detection on internal segments
  9. 11.6.1 — Tamper-detection on payment pages
  10. 12.3.1 — Targeted risk analysis for every flexible control
  11. 12.3.3 — Cryptographic cipher inventory reviewed annually
  12. 12.5.2.1 — Scope confirmation every six months for service providers
  13. 12.10.7 — Incident response when stored PAN is found outside the CDE

Section 3 — Evidence pack

For every requirement, capture: control owner, policy reference, technical artefact, last test date, residual risk.

Next step

MAST QSAs run a one-day v4.0.1 gap clinic across the UAE and India. Book a clinic and we will bring this toolkit pre-populated for your environment.

Related resources