Payments
PCI DSS v4.0.1 Compliance & ROC Readiness Checklist
A requirement-by-requirement checklist to scope cardholder data, implement PCI DSS v4.0.1 controls, and prepare for SAQ or ROC evidence.
- Estimated time
- 3–9 Months
- Audience
- Merchants, Payment Processors, and SaaS Billing Teams
- Last updated
Operational reference for PCI DSS v4.0.1 readiness. A QSA or ISA must complete the formal assessment for in-scope entities.
Progress is saved in this browser only. Nothing is sent to a server.
Phase 1: Scoping & CHD Inventory
Phase 2: Build & Maintain Secure Networks
Phase 3: Access, Monitoring & Testing
Phase 4: Evidence & Assessment
FAQ
Who can sign a PCI ROC?+–
A Qualified Security Assessor (QSA) for most service providers and higher merchant levels. Some merchants complete an SAQ with an Internal Security Assessor.
Does tokenization remove PCI scope?+–
It can reduce scope if PAN never touches your environment. Connected systems and the tokenization provider still need documented due diligence.
Is PCI DSS a law?+–
It is a contractual standard of the payment brands, enforced through acquirers. Fines and loss of processing rights are commercial, not a criminal statute.
When are v4 future-dated controls due?+–
PCI SSC published future-dated requirements with staggered dates. Confirm the current ROC/SAQ version your acquirer expects for 2026.
Related field notes
The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer