💳

Payment Card Industry Data Security Standard v4.0

Global standard for organizations that handle cardholder data. 12 requirements covering network security, data protection, access control, and monitoring.

10 critical14 high3 medium
1.3.1critical

Restrict inbound traffic to system components in the CDE

Inbound traffic to the cardholder data environment must be restricted to only necessary connections.

2.1high

Remove vendor-supplied defaults

Vendor-supplied defaults for system passwords and security parameters must be changed.

3.4critical

Render cardholder data unreadable

Stored cardholder data must be rendered unreadable (encryption, hashing, truncation).

4.1high

Use strong cryptography to protect data in transit

Strong cryptography must be used whenever cardholder data is transmitted over open networks.

8.3.1critical

MFA for all administrative access

Multi-factor authentication is required for all non-console administrative access into the CDE.

10.1high

Audit trails for all system components

All access to system components and cardholder data must be logged.

1.2PCI-1-2high

Network Security Control Configuration

Network security control (NSC) configurations are defined, reviewed, and maintained — including approved network services, port whitelists, and protocols.

1.4PCI-1-4critical

Connections Between Trusted and Untrusted Networks

Connections between the CDE and untrusted networks (internet, corporate network) must be controlled via firewalls/WAFs with documented business need.

2.2PCI-2-2high

System Configuration Standards

System components within the CDE must be configured per industry-accepted hardening standards (CIS benchmarks, vendor security guides).

3.5PCI-3-5critical

PAN Protection

Primary Account Number (PAN) must be protected wherever stored using strong cryptography (encryption, truncation, tokenization, or hashing).

3.7PCI-3-7critical

Key Management Lifecycle

Cryptographic keys used to protect cardholder data must be managed throughout their lifecycle: generation, distribution, storage, rotation, revocation, destruction.

4.2PCI-4-2critical

PAN Encryption Over Open Networks

Strong cryptography (TLS 1.2+) must protect PAN whenever transmitted over open, public networks.

5.2PCI-5-2high

Anti-Malware Coverage

Anti-malware mechanisms must be deployed on all system components commonly affected by malicious software, kept current, and actively running.

6.2PCI-6-2critical

Security Patching

Critical security patches must be installed within one month of release; other applicable security patches within 3 months.

6.3PCI-6-3high

Identify Security Vulnerabilities

Vulnerabilities in CDE systems must be identified and ranked by severity using a vulnerability ranking process (e.g., NVD CVSS).

6.4PCI-6-4critical

Public-Facing Web Application Protection

Public-facing web applications must be protected against known attacks via WAF or via comprehensive testing (annual + after changes).

7.2PCI-7-2high

Access Control System

Access to system components and cardholder data must be controlled via a documented role-based access control (RBAC) system.

8.4PCI-8-4high

Strong Authentication

Authentication to system components in the CDE must use strong methods: minimum 12-char passwords, complexity requirements, MFA for all user access.

8.6PCI-8-6high

Service Account Authentication

Service accounts in the CDE must use unique credentials (no sharing), managed centrally, with documented rotation cadence.

10.4PCI-10-4medium

Time Synchronization

Time synchronization must be implemented across all system components to ensure consistent timestamps in audit logs.

10.5PCI-10-5high

Log Retention

Audit logs must be retained for at least 1 year, with 3 months immediately available for analysis.

10.7PCI-10-7high

Log Review and Anomaly Detection

Audit logs must be reviewed at least daily for anomalies; mechanisms must detect log delivery failures.

11.3PCI-11-3high

Internal Penetration Testing

Internal penetration testing must be performed at least annually + after significant changes.

11.4PCI-11-4high

External Vulnerability Scans

External vulnerability scans must be performed quarterly by an Approved Scanning Vendor (ASV) for organizations subject to PCI Validation.

12.5PCI-12-5medium

Security Awareness Program

Implement a formal security awareness program to make personnel aware of cardholder data protection requirements.

12.10PCI-12-10critical

Incident Response Plan

Implement an incident response plan to respond to suspected or confirmed cardholder data security incidents.

9.1PCI-9-1medium

Physical Access Restriction

Use appropriate facility entry controls to limit and monitor physical access to systems in the CDE.