Skip to content
Capability/Compliance Frameworks

PCI DSS

Payment card industry data security

01 / Overview

PCI DSS establishes security requirements for organizations that store, process, or transmit cardholder data. Thalorin provides comprehensive PCI compliance with scope reduction documentation, continuous control monitoring, and assessment preparation that simplifies the path to compliance.

PCI DSS v4.0.1 is the only active version of the standard. It replaced v4.0 on 31 December 2024, and v3.2.1 retired on 31 March 2024. Every assessment conducted in 2026 runs against v4.0.1, and the transition period that made parts of the standard optional is over.

That last point is the one organisations most often miss. When v4.0 published in March 2022, 51 requirements were designated future-dated — best practice until 31 March 2025, mandatory after. That date has passed. There is no longer any requirement in v4.x that can be treated as aspirational, and assessments now test the full set.

Scope remains the dominant cost driver. PCI DSS applies to the cardholder data environment and to any system component that connects to or could affect its security, which reliably includes more infrastructure than the initial estimate. Reducing scope through segmentation, tokenisation, or moving to a compliant service provider usually saves more than optimising controls inside a large environment.

Thalorin models the cardholder data environment as an explicit boundary with connected-to and security-impacting systems classified deliberately, so segmentation decisions show up as assessment scope rather than as an assumption tested for the first time by a QSA.

02 / Challenges

Framework compliance requires sustained effort

Every future-dated requirement is now live

The 51 requirements that were best practice under v4.0 became mandatory on 31 March 2025. Programmes built around the transition period are testing against a standard that no longer exists.

Scope is wider than the card systems

The environment includes systems connected to, or capable of affecting the security of, the cardholder data environment. Jump hosts, monitoring, directory services, and CI/CD routinely fall in scope after being excluded from the estimate.

Segmentation must be proven, not asserted

Where segmentation is used to reduce scope, it has to be validated by testing. An assumed boundary that penetration testing traverses expands the assessment mid-engagement.

Service provider dependencies

Responsibility is shared with providers, and their compliance status and the specific requirements they cover must be tracked. A provider's Attestation of Compliance rarely covers everything an organisation assumes it does.

03 / Capabilities

How Thalorin helps

PCI DSS v4.0PA-DSSP2PE

PCI DSS v4.0 compliance

Track all twelve requirement areas under v4.0.1, including the requirements that became mandatory on 31 March 2025.

Scope reduction documentation

Model the cardholder data environment explicitly, classifying connected-to and security-impacting systems rather than inferring scope, and hold the segmentation validation evidence alongside the scope claim it supports.

SAQ and ROC preparation

Support the applicable validation path, whether a self-assessment questionnaire or a full Report on Compliance.

Continuous compliance monitoring

Keep evidence current between assessments so the annual validation is a confirmation rather than a reconstruction.

Compensating control documentation

Record each compensating control with the constraint that forced it, the objective it meets and the additional risk it carries, kept current rather than written in the week before the assessment.

QSA collaboration support

Give the assessor direct access to evidence and to the service provider responsibility matrices, so shared obligations are assigned rather than assumed mid-assessment.

Questions

PCI DSS: common questions

Which version of PCI DSS applies in 2026?

v4.0.1, exclusively. It replaced v4.0 on 31 December 2024, and v3.2.1 retired on 31 March 2024. All assessments conducted in 2026 are against v4.0.1, and every requirement in it is in scope.

Are the future-dated requirements still optional?

No. The 51 requirements designated future-dated when v4.0 published in March 2022 became mandatory on 31 March 2025. The v4.0.1 release did not move that date. Any programme still treating them as best practice is out of step with how it will be assessed.

Do I need a QSA or can I self-assess?

It depends on your merchant or service provider level, which is driven by transaction volume and by what your acquirer or the card brands require. Higher volumes generally require a Report on Compliance produced with a Qualified Security Assessor; lower volumes may use a Self-Assessment Questionnaire, of which there are several types matched to how you handle card data.

How do I reduce PCI DSS scope?

Handle less cardholder data and isolate what remains. Network segmentation, tokenisation, point-to-point encryption, and moving payment capture to a compliant service provider all remove systems from scope. Where segmentation is the mechanism, it must be validated by testing — an asserted boundary that a penetration test crosses does not reduce scope.

Does PCI DSS apply if a third party processes our payments?

Usually yes, in reduced form. Outsourcing payment processing shifts many requirements to the provider but rarely all of them — you retain responsibility for provider due diligence, for the requirements the provider does not cover, and typically for the pages that redirect to them. The provider's Attestation of Compliance defines the boundary, and reading it carefully is the exercise.

Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.

05 / Get Started

Talk to us about PCI DSS.

See how one evidence artifact satisfies PCI DSS requirements alongside every other framework you carry.