Standard · PCI DSS v4.0.1

PCI DSS compliance, run as a three-stage workflow.

One workspace from the SAQ scoping questionnaire through self-rated risk and per-control evidence, ending in a micro dashboard ready for the QSA. Roles split across creator, business liaison, GRC liaison and control owner. Editing follows the platform billing state.

Sign in and open PCI DSS

First month free. No card required.

The three stages.

Stage 1 — Initial assessment and SAQ scoping
  1. Answer a short questionnaire about your entity type and how you process card payments.
  2. The workflow figures out which SAQ applies to you — SAQ-A, SAQ-B, SAQ-C, SAQ-D, and the P2PE variants — or whether you need a full ROC via QSA instead.
  3. Capture a per-question justification as you answer.
  4. Submit. Stage 1 is the hard gate — the remaining stages unlock once it is submitted.
Stage 2 — Risk scoring
  1. Open every PCI DSS requirement that applies to your chosen SAQ.
  2. Score each one with a self-rated risk level and a short justification.
  3. Review the macro dashboard for risk distribution across the requirement set, so you know which clusters need the most work.
Stage 3 — Certification readiness
  1. Capture evidence per control, assign owners, and upload files.
  2. Use AI-assisted policy generation alongside to draft any missing policies.
  3. The GRC liaison fills the internal audit findings column — compliance status, notes, and required actions.
Output — Assessor-ready dashboard
  1. The micro dashboard rolls every control into a single table — status, evidence count, and PCI verdict.
  2. Ready for handoff to your QSA or internal assessor for review.
  3. Exportable so the QSA can take their copy and work it offline.

What PCI DSS compliance involves — and how a guided workflow helps

PCI DSS is the Payment Card Industry Data Security Standard — the contractual security baseline every organisation that stores, processes or transmits cardholder data must meet, enforced through your acquiring bank or payment processor rather than a government regulator. Version 4.0.1 organises roughly 250 requirements under twelve headline controls, from network segmentation and encryption of cardholder data to access control, logging, vulnerability management and security testing. Miss your compliance validation and the consequences are commercial: higher processing fees, liability for breaches, and ultimately losing the ability to take card payments.

The first and most consequential step is scoping: which Self-Assessment Questionnaire (SAQ) applies to you, and how much of your environment is in scope. A SaaS business that fully outsources payment handling to a provider like Stripe may validate under SAQ A with a few dozen requirements; a company that touches card data itself may face SAQ D with over two hundred. Getting the SAQ wrong in either direction means wasted work or a failed assessment.

regXperience runs PCI DSS as a guided three-stage workflow built for fintech startups and payment-adjacent companies without a dedicated security team. Stage one determines your SAQ type and scopes the cardholder data environment. Stage two scores risk across the applicable requirements so remediation effort goes where exposure is highest. Stage three is certification readiness: evidence per requirement, gaps and owners visible, ending in an assessor-ready dashboard your QSA or acquirer can review directly. Day-based pricing means a focused compliance push does not require an annual platform contract.

See pricing — pay by the day, no annual contract — or browse the compliance guides to go deeper.

Frequently asked questions

What triggers a PCI DSS requirement?

Accepting card payments, in any volume, through any channel. The obligation arrives through your merchant agreement with your acquirer or payment processor the moment you store, process or transmit cardholder data — or can affect the security of it. Even fully outsourced payment flows leave you with a reduced but real validation obligation (typically SAQ A).

Which SAQ do I need?

It depends on how card data flows through you: SAQ A for fully outsourced e-commerce (payment pages served entirely by a compliant provider), SAQ A-EP when your site affects how card data is redirected, and SAQ D for merchants that handle card data directly or don’t fit a narrower type — with other variants for card-present and terminal scenarios. Scoping this correctly is stage one of the regXperience workflow.

Do startups need a QSA for PCI DSS?

Usually not. Most SMB merchants self-assess with an SAQ signed by an officer of the company; a Qualified Security Assessor is required only for the largest merchant levels (driven by transaction volume) or when your acquirer demands a Report on Compliance. An assessor-ready evidence trail still matters either way — it is what your acquirer asks for when they have questions.

What changed in PCI DSS v4.0.1?

Version 4 modernised the standard — stronger authentication (MFA broadly required), tighter e-commerce script controls, targeted risk analyses, and a "customized approach" that lets mature organisations meet control objectives their own way. v4.0.1 is a clarification release of v4.0. All future-dated v4 requirements became mandatory on 31 March 2025, so assessments today validate against the full set.

How much does PCI DSS compliance software cost on regXperience?

Per workflow, per day: an active rate during the readiness push and a lower passive rate for maintenance, with no annual contract or per-seat fee. Your first month on your first workflow is free — see the pricing page for current rates.

Start your first workflow — first month free

Sign in to start