Governance. Risk. Compliance. Cybersecurity.
Compliance & Certification

PCI DSS v4.0 Compliance

QSA-aligned readiness, RoC support and SAQ guidance.

PCI DSS v4.0 Compliance — ISO certification stamp on an audit document, MAST Consulting Group

Overview

We help merchants, acquirers, processors and service providers achieve and maintain PCI DSS v4.0 compliance — from scoping and segmentation to RoC, SAQ-D and ASV scan remediation.

NJ
Lead partner for this service
Naval JadhavDirector — GRC & Compliance

Experienced governance, risk management, and compliance (GRC) leader with over 15 years of industry expertise. He heads deep-dive regulatory compliance, data privacy, and AI governance implementations at MAST Consulting.

In depth

A four-layer view of this service.

Context, scope, delivery and impact — written for buyers, boards, auditors and search engines alike.

Layer 01 — Context

Context & Why It Matters

01

PCI DSS v4.0.1 became mandatory on 31 March 2025, ending the v3.2.1 transition period.

  • Every merchant, acquirer, issuer, processor and third-party service provider that stores, processes or transmits cardholder data must now meet the new requirements — including the future-dated controls that take effect from 31 March 2025 onwards.
  • UAE, KSA and Indian payment ecosystems (CBUAE, SAMA, RBI) increasingly expect PCI DSS compliance as a precondition for licensing, sponsorship and PSP partnerships.
Layer 02 — Scope

Scope & What It Covers

02

We cover all 12 PCI DSS v4.0.1 requirements, all six control objectives, and the customised approach where appropriate.

  • Scope work includes cardholder data discovery and flow mapping, CDE definition, network segmentation validation, scoping of connected systems, e-commerce script management (Req 6.4.3), targeted risk analysis (12.3.1), authenticated internal vulnerability scanning (11.3.1.2), expanded MFA (8.4/8.5), continuous monitoring and the 64 future-dated controls covering anti-phishing, automated log review, key management and payment-page integrity.
Layer 03 — Approach

Our Approach & Delivery

03

QSA-aligned delivery led by PCI Professionals (PCIP) and ISA-qualified consultants.

  • We run scoping workshops, perform a gap analysis against every applicable requirement, design segmentation and tokenisation strategies that legitimately reduce scope, coordinate ASV scans and CREST/OSCP-led penetration tests (Req 11.4), prepare evidence in QSA-friendly formats, and sit through the on-site audit with you.
  • For Level 2–4 merchants we walk you through SAQ-A, A-EP, D-Merchant or D-SP and the supporting AoC.
Layer 04 — Impact

Business Impact & Outcomes

04

Clients reach validation in 90–150 days, avoid the four- to six-figure monthly non-compliance fees that acquirers levy, and materially reduce breach exposure: PCI-aligned organisations are ~50 percent less likely to suffer a confirmed card-data breach (Verizon PSR).

  • Maintained year-round, the programme supports new payment rails (Apple Pay, click-to-pay, embedded finance) without triggering a re-scope crisis at every product launch.
At a glance

Process flow, compliance checklist and benefits.

A visual breakdown of how the engagement runs, what evidence we leave behind, and the business outcomes you can defend at the board.

Process flow

How we deliver PCI DSS v4.0 Compliance.

  1. 01
    Scoping & CDE Mapping

    Identify all systems that store, process or transmit cardholder data.

  2. 02
    Gap Analysis

    Detailed assessment against all 12 PCI DSS v4.0 requirements.

  3. 03
    Remediation

    Technical and process fixes, segmentation, key management.

  4. 04
    Validation

    Penetration testing, ASV scans, internal audit.

  5. 05
    RoC / SAQ

    Report on Compliance or Self-Assessment Questionnaire support.

Compliance checklist

What auditors and regulators expect to see.

Aligned to PCI DSS v4.0.1 (mandatory from 31 March 2025) — every item is examined by the QSA before sign-off.

  • Cardholder data discovery and flow diagrams

    Storage, processing and transmission of CHD/SAD fully mapped.

  • Scope and segmentation validation

    CDE boundary, connected systems and segmentation testing evidence.

  • All 12 requirements evidenced

    Control narratives, screenshots, configs and logs per sub-requirement.

  • Targeted risk analyses (12.3.1)

    Documented TRAs for every flexible-frequency control.

  • Authenticated vulnerability scans (11.3.1.2)

    Quarterly internal scans, ASV external scans and remediation evidence.

  • Penetration testing (11.4)

    Annual app and infra tests by CREST or OSCP-qualified testers.

  • MFA on all CDE access (8.4 / 8.5)

    Including admin, remote and console access — phishing-resistant where possible.

  • AoC / RoC / SAQ submission pack

    Final attestation, executive summary and signed responsibility matrix.

Benefits

What you walk away with.

Validation in 90 to 150 days

Predictable timeline from kickoff to QSA sign-off.

Avoid non-compliance fees

Eliminate four- to six-figure monthly acquirer penalties.

Lower breach exposure

Verizon PSR: PCI-aligned firms suffer materially fewer card-data breaches.

Acquirer and PSP partnerships unlocked

Meet onboarding gates for Visa, Mastercard, Amex and regional schemes.

Launch new payment rails safely

Apple Pay, click-to-pay and embedded finance without re-scope crises.

Year-round audit readiness

Continuous evidence pipeline — not a 60-day pre-audit sprint.

FAQ

Frequently asked questions.

Are you a QSA?+

We work alongside accredited QSA firms and prepare you so the formal assessment is a confirmation, not a discovery exercise.

What's new in PCI DSS v4.0?+

Customised approach, expanded MFA, targeted risk analyses and stronger requirements on authenticated scanning, scripts and e-commerce.

We use a payment gateway — do we still need PCI DSS?+

Yes. Even with full tokenisation and a hosted payment page, you remain in scope for SAQ A or SAQ A-EP. The acquirer or scheme determines which SAQ applies.

What is the difference between SAQ, RoC and AoC?+

SAQs are self-assessment questionnaires for lower-volume merchants. A RoC is a Report on Compliance written by a QSA for Level 1 merchants and service providers. An AoC is the Attestation of Compliance signed off either way.

How long does a v4.0.1 programme take?+

Predictable timeline of 90 to 150 days from kickoff to QSA sign-off for mid-size environments. Complex multi-acquirer estates take 6 to 9 months.

Can you reduce our PCI scope?+

Yes — scope reduction through tokenisation, network segmentation, P2PE and outsourcing is usually our highest-ROI workstream. Most clients see 40–70% scope reduction.

How do PCI controls relate to ISO 27001?+

Approximately 70% of ISO 27001 Annex A controls overlap with PCI DSS requirements. We map and evidence once across both frameworks for clients running joint programmes.

What happens if there is a cardholder data breach during the programme?+

We coordinate with the acquirer, card schemes and a PCI Forensic Investigator (PFI) under your incident plan and reset the validation timeline once containment is confirmed.

Methodology

Week-by-week, how PCI DSS v4.0 runs.

A disciplined sequence that compresses 6–9 month programmes into a fixed-fee, board-defensible engagement.

  1. Week 1
    Step 1
    Scope & SAQ vs RoC

    Cardholder data flow mapping, scope reduction analysis, SAQ vs Report on Compliance decision with your acquirer.

  2. Week 2–4
    Step 2
    Gap assessment

    All 12 PCI DSS v4.0 requirements assessed, evidence gaps logged, segmentation tested, third-party service provider register built.

  3. Week 5–9
    Step 3
    Remediation

    Network segmentation hardening, key management, MFA roll-out, secure SDLC, log management, file integrity monitoring, ASV scan baseline.

  4. Week 10–11
    Step 4
    Validation

    Internal vulnerability scans, ASV external scans, penetration testing, segmentation testing, compensating controls documented.

  5. Week 12–14
    Step 5
    QSA assessment

    Report on Compliance walk-through with our QSA partner, evidence handover, on-site validation, AoC issued.

Deliverables

What we leave behind.

Audit-grade artefacts your team continues to operate after handover — not a one-shot consulting deck.

Cardholder Data Environment (CDE) map

Data flow diagrams, network segmentation diagrams, in-scope asset register.

PCI DSS v4.0 control matrix

All 12 requirements with implementation evidence, ownership and validation method.

Penetration test report

External and internal pen test with segmentation validation, mapped to Requirement 11.4.

ASV scan reports

Quarterly external vulnerability scans by an Approved Scanning Vendor.

Attestation of Compliance (AoC)

Signed by our QSA partner and your executive sponsor.

Regulators & frameworks

One engagement, mapped to every applicable obligation.

Evidence designed once, reused across regulators — reducing audit fatigue and total cost of compliance.

FrameworkNameWhy it matters
PCI DSS v4.0Payment Card Industry Data Security StandardMandatory for any entity storing, processing or transmitting cardholder data.
CBUAE PSPUAE Payment Services RegulationPCI DSS compliance is a licensing prerequisite for UAE payment service providers.
SAMA PaymentsSaudi Central Bank Payment Services Provider RegulationsPCI DSS required for KSA acquirers, issuers and processors.
RBI PA-PGRBI Payment Aggregator & Payment Gateway GuidelinesPCI DSS Level 1 mandated for Indian payment aggregators.
Engagement tiers

Pick the model that fits your scope.

Fixed-fee where scope is clear, phased programmes where complexity demands governance — never time-and-materials drift.

Fixed fee
SAQ pathway

Merchants and small service providers eligible for self-assessment questionnaires.

Phased programme
Report on Compliance

Level 1 merchants and service providers requiring on-site QSA assessment.

Programme delivery
Multi-entity programme

Payment aggregators, processors and PSPs with multiple in-scope environments.

Why MAST

What separates this engagement from the alternative.

QSA-led validation

Engagements led by consultants from the PCI SSC QSA Programme — your AoC is signed under formal QSA authority.

Scope reduction first

We aggressively reduce the CDE before remediation — tokenisation, P2PE and segmentation cut cost and audit effort by 40–60%.

v4.0 ready

All engagements delivered against PCI DSS v4.0 with customised approach for advanced requirements (continuous evidence, targeted risk analysis).

Compare

DIY vs Big Four vs MAST.

An honest, side-by-side comparison of what each delivery model typically gets you.

DimensionDIY / InternalBig FourMAST
QSA on engagementHired separately, lateYes, but partner-pricedYes, from day one
Scope reductionRarely attemptedOptional workstreamMandatory first step
ASV scans includedSeparate vendor contractPass-throughBundled
Re-validation Year 2Start from scratchRe-engaged at full feeDiscounted continuation under retainer
Extended FAQs

The questions experienced buyers actually ask.

What changed in PCI DSS v4.0?+

v4.0 introduces the Customised Approach, formal targeted risk analyses, expanded MFA requirements (all access, not just admin), continuous evidence for some controls, and stricter requirements for service providers around client-side script and phishing-resistant authentication. Future-dated requirements become mandatory 31 March 2025.

Do you handle SWIFT CSP alongside PCI DSS?+

Yes — many banking clients run a combined PCI DSS + SWIFT CSP programme. Shared controls (key management, network segmentation, MFA, monitoring) are evidenced once and mapped to both frameworks.

Can we use tokenisation to reduce scope?+

Yes — vault tokenisation, network tokens and P2PE are the three most effective scope-reduction strategies. We help you select the right approach based on payment channels, card-on-file requirements and partner integrations.

Take it with you
Download the PCI DSS v4.0 Compliance 1-pager.

Methodology, deliverables, pricing bands and reference architecture on a single board-ready page.

Request the PDF
Get started

Ready to scope your PCI DSS v4.0 engagement?

Tell us a little about your business — a senior consultant will reach out within one business day.

By submitting you agree to be contacted by a MAST consultant. We never share your details.