Standard · PCI DSS v4.0.1
PCI DSS compliance, run as a three-stage workflow.
One workspace from the SAQ scoping questionnaire through self-rated risk and per-control evidence, ending in a micro dashboard ready for the QSA. Roles split across creator, business liaison, GRC liaison and control owner. Editing follows the platform billing state.
First month free. No card required.
The three stages.
- Stage 1 — Initial assessment and SAQ scoping
- Answer a short questionnaire about your entity type and how you process card payments.
- The workflow figures out which SAQ applies to you — SAQ-A, SAQ-B, SAQ-C, SAQ-D, and the P2PE variants — or whether you need a full ROC via QSA instead.
- Capture a per-question justification as you answer.
- Submit. Stage 1 is the hard gate — the remaining stages unlock once it is submitted.
- Stage 2 — Risk scoring
- Open every PCI DSS requirement that applies to your chosen SAQ.
- Score each one with a self-rated risk level and a short justification.
- Review the macro dashboard for risk distribution across the requirement set, so you know which clusters need the most work.
- Stage 3 — Certification readiness
- Capture evidence per control, assign owners, and upload files.
- Use AI-assisted policy generation alongside to draft any missing policies.
- The GRC liaison fills the internal audit findings column — compliance status, notes, and required actions.
- Output — Assessor-ready dashboard
- The micro dashboard rolls every control into a single table — status, evidence count, and PCI verdict.
- Ready for handoff to your QSA or internal assessor for review.
- Exportable so the QSA can take their copy and work it offline.
Self-serve, or guided by a consultant.
- Self-serve
- Your team holds every role. The creator, business liaison, GRC liaison and control owners are all teammates you assign. No external party joins the workspace. You pay only the platform fee.
- Guided
- An independent consultant from the SME directory joins as the GRC liaison. They sit inside the same workspace and review the audit findings — compliance status, consultant notes, required actions — while your team owns the implementation columns. You pay the platform fee plus the consultant's review fee, prorated by the day.
Two rates. One while you work. One after.
Activewhile the SAQ and evidence are still in motion.
Passiveonce the assessor-ready dashboard ships and the workspace becomes a read-only record.
Self-serve
Your team runs the workflow end to end.
$550 / month
$50 / month
Guided
Platform fee plus an independent consultant from the SME directory. Browse rates after you sign in.
See directory
See directory
Rates shown are indicative. The exact daily number is displayed inside the product before any assessment is launched.
How the meter works.
- Why two rates
- PCI readiness runs over months, not days. The meter is split so you pay full rate while controls and evidence are still in motion, and a much lower rate once the assessor signs off and the workspace becomes a read-only record.
- Prorated daily
- Charges add up by the day. No annual contract. No per-seat fee. Cancel any time and the meter stops on the cancel date.
- First month free
- The first assessment on your first workflow is free for the first month. No card required at sign-up.
- Switch when the QSA signs off
- Flip the assessment to passive and the meter drops to the lower rate. The SAQ, evidence, and assessor-ready dashboard stay accessible and exportable.
What PCI DSS compliance involves — and how a guided workflow helps
PCI DSS is the Payment Card Industry Data Security Standard — the contractual security baseline every organisation that stores, processes or transmits cardholder data must meet, enforced through your acquiring bank or payment processor rather than a government regulator. Version 4.0.1 organises roughly 250 requirements under twelve headline controls, from network segmentation and encryption of cardholder data to access control, logging, vulnerability management and security testing. Miss your compliance validation and the consequences are commercial: higher processing fees, liability for breaches, and ultimately losing the ability to take card payments.
The first and most consequential step is scoping: which Self-Assessment Questionnaire (SAQ) applies to you, and how much of your environment is in scope. A SaaS business that fully outsources payment handling to a provider like Stripe may validate under SAQ A with a few dozen requirements; a company that touches card data itself may face SAQ D with over two hundred. Getting the SAQ wrong in either direction means wasted work or a failed assessment.
regXperience runs PCI DSS as a guided three-stage workflow built for fintech startups and payment-adjacent companies without a dedicated security team. Stage one determines your SAQ type and scopes the cardholder data environment. Stage two scores risk across the applicable requirements so remediation effort goes where exposure is highest. Stage three is certification readiness: evidence per requirement, gaps and owners visible, ending in an assessor-ready dashboard your QSA or acquirer can review directly. Day-based pricing means a focused compliance push does not require an annual platform contract.
See pricing — pay by the day, no annual contract — or browse the compliance guides to go deeper.
Frequently asked questions
What triggers a PCI DSS requirement?
Accepting card payments, in any volume, through any channel. The obligation arrives through your merchant agreement with your acquirer or payment processor the moment you store, process or transmit cardholder data — or can affect the security of it. Even fully outsourced payment flows leave you with a reduced but real validation obligation (typically SAQ A).
Which SAQ do I need?
It depends on how card data flows through you: SAQ A for fully outsourced e-commerce (payment pages served entirely by a compliant provider), SAQ A-EP when your site affects how card data is redirected, and SAQ D for merchants that handle card data directly or don’t fit a narrower type — with other variants for card-present and terminal scenarios. Scoping this correctly is stage one of the regXperience workflow.
Do startups need a QSA for PCI DSS?
Usually not. Most SMB merchants self-assess with an SAQ signed by an officer of the company; a Qualified Security Assessor is required only for the largest merchant levels (driven by transaction volume) or when your acquirer demands a Report on Compliance. An assessor-ready evidence trail still matters either way — it is what your acquirer asks for when they have questions.
What changed in PCI DSS v4.0.1?
Version 4 modernised the standard — stronger authentication (MFA broadly required), tighter e-commerce script controls, targeted risk analyses, and a "customized approach" that lets mature organisations meet control objectives their own way. v4.0.1 is a clarification release of v4.0. All future-dated v4 requirements became mandatory on 31 March 2025, so assessments today validate against the full set.
How much does PCI DSS compliance software cost on regXperience?
Per workflow, per day: an active rate during the readiness push and a lower passive rate for maintenance, with no annual contract or per-seat fee. Your first month on your first workflow is free — see the pricing page for current rates.
Start your first workflow — first month free
Sign in to start