pci-dss-review
Installation
SKILL.md
PCI DSS v4.0 Compliance Review
When to Use
If a target is provided via arguments, focus the review on: $ARGUMENTS
- Organization processes, stores, or transmits cardholder data and must validate PCI DSS compliance
- Preparing for a Qualified Security Assessor (QSA) assessment or self-assessment questionnaire (SAQ)
- Transitioning from PCI DSS v3.2.1 to v4.0 (mandatory after March 31, 2025)
- Evaluating scope reduction strategies (tokenization, P2PE, network segmentation)
- Assessing readiness for new v4.0 requirements with future-dated applicability (March 31, 2025)
- Service providers need to validate compliance for clients
- Post-breach assessment of payment card security posture
Context
PCI DSS v4.0, published March 2022 by the PCI Security Standards Council, is the current version of the Payment Card Industry Data Security Standard. It replaced v3.2.1, with v3.2.1 retirement on March 31, 2024. PCI DSS v4.0 introduced 64 new requirements, many of which were best practices until March 31, 2025, when they became mandatory.