PCI DSS v4 COMPLIANCE SOFTWARE FOR MERCHANTS, PROCESSORS & SERVICE PROVIDERS

Manage all 12 PCI DSS v4 requirements at the sub-requirement level — 250+ controls, customized approach support, CDE scoping, ASV scan calendar, pen-test finding tracking, SAQ and ROC generated from live data.

What is PCI DSS v4 and who must comply? The Payment Card Industry Data Security Standard v4.0 (March 2022, mandatory enforcement March 2025) is the global standard for protecting cardholder data. Compliance is mandatory for any entity that stores, processes, or transmits payment card data — merchants of every size, payment processors, and third-party service providers. The standard covers 12 top-level requirements expanded to 250+ controls, and uniquely allows a "customized approach" alongside the traditional "defined approach" for any control where you can demonstrate equivalent objective fulfilment.

PCI SSCQSA-readyASV scansSAQ + ROCCustomized approach
app.venvera.com/pci-dss-v4PCI DSS v4 ComplianceInternational · PCI Security Standards Council · DSS v4.0COMPLIANCE SCORE74%Target 80%Last assessment14 days agoNext internal auditQ3 · on scheduleOpen gaps12CONTROLS252CDE SYSTEMS38OPEN FINDINGS11DAYS TO ASV23Domain readiness% controls implementedBuild & maintain secure networks (Req 1–2)86%Protect account data (Req 3–4)78%Vulnerability management (Req 5–6)72%Access control (Req 7–9)80%Monitor & test (Req 10–11)64%Information security policy (Req 12)90%

ALL 12 REQUIREMENTS, TRACKED AT THE SUB-REQUIREMENT LEVEL

PCI DSS v4 expands to 250+ testing procedures across the familiar 12 requirements. Venvera renders every sub-requirement with implementation status, applicable approach (defined or customized), control owner, evidence link, and the test procedure your QSA will run. Cross-mapping to ISO 27001:2022, NIST CSF 2.0, and SOC 2 means controls implemented for one count for the others where the requirements overlap.

  • Every sub-requirement tracked individually (not just the top 12)
  • Defined approach + customized approach options per requirement
  • Test procedure pre-loaded for QSA walkthroughs
  • Cross-mapping to ISO 27001 Annex A, NIST CSF 2.0, SOC 2 TSC
  • Filter views per requirement, per CDE system, per applicability
app.venvera.com/pci-dss-v4PCI DSS v4 ComplianceInternational · PCI Security Standards Council · DSS v4.0Control LibrarySearch controls…All domains ▾+ Add controlREFCONTROLSTATUSOWNER1.2.1Configuration standards for NSC rulesetsIMPLEMENTEDJLJ. Lewis2.2.3Change default passwords before deploymentIMPLEMENTEDJLJ. Lewis3.5.1PAN rendered unreadable wherever storedIMPLEMENTEDJLJ. Lewis6.3.3Critical vulnerabilities patched within 30 daysPARTIALJLJ. Lewis8.3.1MFA for all non-console admin accessIMPLEMENTEDJLJ. Lewis10.4.1Review audit logs dailyPARTIALJLJ. Lewis11.3.2External vulnerability scans by ASV quarterlyIMPLEMENTEDJLJ. Lewis12.6.1Targeted risk analysis for customized approachPARTIALJLJ. Lewis

CARDHOLDER DATA ENVIRONMENT, SCOPED LIVE

Your CDE is the network of systems that store, process, or transmit cardholder data, plus systems connected to those. Get the scope wrong and the QSA expands the audit. Venvera tags every asset with its CDE relationship (in-CDE / connected / segmented-out), tracks segmentation controls explicitly, and surfaces any system that drifts into scope. The annual scope validation produces itself from the live asset inventory and your data-flow diagrams.

  • Asset register with explicit in-CDE / connected / out-of-scope tagging
  • Segmentation control tracking (network, host, identity)
  • Drift alerts when a connected system gains CDE characteristics
  • Data-flow diagrams kept current — not annually re-drawn
  • Annual scope validation report generated from live state
app.venvera.com/pci-dss-v4PCI DSS v4 ComplianceInternational · PCI Security Standards Council · DSS v4.0COMPLIANCE SCORE86%Target 80%Last assessment14 days agoNext internal auditQ3 · on scheduleOpen gaps12CDE ASSETS38CONNECTED SYSTEMS24SEGMENTED OUT186SCOPE DRIFT ALERTS2Domain readiness% controls implementedNetwork segmentation92%Data-flow diagrams88%Asset tagging coverage100%Scope validation evidence84%

CUSTOMIZED APPROACH FOR THE CONTROLS THAT DON’T FIT

PCI DSS v4 introduces the customized approach: meet the requirement’s objective without following the defined sub-requirement procedure. The price is rigour — a documented Targeted Risk Analysis, the customized approach objective, the implementation, and the testing your QSA will perform. Venvera captures all four for every control where you’re using it.

  • Customized approach toggle per sub-requirement
  • Targeted risk analysis template (OCR-style methodology)
  • Customized approach objective wording, vetted with your QSA
  • Linked compensating controls and their effectiveness evidence
  • Auditor view shows defined vs. customized side-by-side
app.venvera.com/pci-dss-v4PCI DSS v4 ComplianceInternational · PCI Security Standards Council · DSS v4.0LATEST BOARD REPORTPCI DSS v4 · Q2 2026Prepared for: Board of DirectorsGenerated: 2 minutes ago · 18 pages1. Executive summaryp. 22. Control effectivenessp. 53. Key risks & incidentsp. 84. Remediation progressp. 115. Annex — full control matrixp. 14Download DOCXExport to xBRL-CSVRecent exportsTargeted risk analysis — Req 8.3PDF · per customized approachFINALCompensating control matrixXLSX · 4 activeFINALCustomized approach narrativeDOCX · QSA-reviewedDRAFTRisk acceptance — board sign-offPDF · per acceptanceFINALEffectiveness testing planXLSX · per controlDRAFTAnnual customized approach reviewPDF · QSA attendedDRAFT

QUARTERLY ASV SCANS AND ANNUAL PENETRATION TESTS

Requirement 11 mandates quarterly external vulnerability scans by an Approved Scanning Vendor and annual internal + external penetration testing. Venvera schedules both, captures results, links findings to the risk register, and tracks remediation against the requirement-specific timelines. Miss a scan window and Venvera raises it as a finding before the QSA does.

  • ASV scan calendar with auto-overdue alerts (Req 11.3.2)
  • Penetration test results imported with finding-by-finding tracking (Req 11.4)
  • Internal vulnerability scans tracked separately (Req 11.3.1)
  • Network segmentation testing schedule per Req 11.4.5
  • CDE scope re-confirmed per scan cycle
app.venvera.com/pci-dss-v4PCI DSS v4 ComplianceInternational · PCI Security Standards Council · DSS v4.0TOTAL128FRESH96STALE24MISSING8Evidence vaultlinked to 114 controlsASV scan — Q2 (clean)PDF · 0 criticalFRESHASV scan — Q1 (clean)PDF · 0 criticalFRESHPenetration test report (annual)PDF · 24 findingsFRESHInternal vulnerability scan — monthlyCSV · 14 issues openFRESHSegmentation test — Q2PDF · CDE isolation OKFRESHWAF logs — sampleCSV · per Req 6.4STALE

SAQ, ROC, AND AOC — GENERATED FROM LIVE CONTROLS

The Self-Assessment Questionnaires (A through D, plus P2PE-HW) and the Report on Compliance for Level 1 entities are produced directly from your control state. The Attestation of Compliance is one click. No more dragging the auditor through six different SharePoint sites the night before signing.

  • SAQ A / A-EP / B / B-IP / C / C-VT / D-Merchant / D-SP / P2PE-HW supported
  • Report on Compliance (DOCX) generated for Level 1 entities
  • Attestation of Compliance (PDF) one-click export
  • Per-requirement evidence references inserted automatically
  • Version history with diffs for auditor walkthroughs
app.venvera.com/pci-dss-v4PCI DSS v4 ComplianceInternational · PCI Security Standards Council · DSS v4.0LATEST BOARD REPORTPCI DSS v4 · Q2 2026Prepared for: Board of DirectorsGenerated: 2 minutes ago · 18 pages1. Executive summaryp. 22. Control effectivenessp. 53. Key risks & incidentsp. 84. Remediation progressp. 115. Annex — full control matrixp. 14Download DOCXExport to xBRL-CSVRecent exportsSAQ D — Service ProviderDOCX · 370 sub-requirementsFINALReport on Compliance (ROC) draftDOCX · 196 pagesDRAFTAttestation of Compliance (AoC)PDF · signedFINALPCI DSS scope statementPDF · annualFINALAcquirer compliance reportPDF · this quarterFINALCompliance fee submissionCSV · autoFINAL

CONTINUOUS MONITORING — NOT AN ANNUAL SPRINT

PCI DSS v4 requires continuous controls — daily log review (Req 10.4.1), monthly internal scans (Req 11.3.1), quarterly ASV scans, semi-annual segmentation tests. Venvera schedules all of them, integrates with your SIEM and asset inventory, and ensures the recurring requirements actually recur. The annual ROC is the easy part when the daily / monthly / quarterly evidence is already there.

  • Daily log review tracking (Req 10.4.1)
  • Monthly internal vulnerability scan reminders (Req 11.3.1)
  • Quarterly ASV scan windows + overdue alerts
  • Semi-annual segmentation testing schedule
  • Continuous control review with role-based assignment
app.venvera.com/pci-dss-v4PCI DSS v4 ComplianceInternational · PCI Security Standards Council · DSS v4.0COMPLIANCE SCORE72%Target 80%Last assessment14 days agoNext internal auditQ3 · on scheduleOpen gaps12CONTROLS114EVIDENCE86GAPS12OVERDUE3Domain readiness% controls implementedGovernance88%Risk management74%Operations62%Third-party56%

PCI DSS V4 COMPLIANCE: VENVERA VS MANUAL TRACKING

Capability
Manual Tracking
Venvera
Sub-requirement granularity
Spreadsheet at the 12 top-level requirements
All 250+ sub-requirements with status
CDE scoping
Annual diagram; scope drift goes unseen
Asset-tagged live, drift alerts on creation
Customized approach
Documented in scattered Word files
Targeted risk analysis + objective per control
ASV scan tracking
Email reminders, missed windows
Calendar with overdue findings auto-raised
Penetration test findings
PDF in a folder; not tracked to closure
Each finding tracked in the risk register
SAQ / ROC generation
Manual document assembly each year
Generated from live control state

12

Top-level requirements

250+

Sub-requirements (v4 expansion)

60%

Average overlap with ISO 27001

1 click

AoC and SAQ export

FREQUENTLY ASKED QUESTIONS ABOUT PCI DSS V4

GET PCI DSS OFF YOUR SPREADSHEET. KEEP IT THERE.

14-day free trial. Import your CDE asset list and start with the requirement that scares you most. Venvera does the mapping; your QSA gets the paperwork. No credit card required.

AES-256 Encryption
EU Data Residency
SOC 2 Certified