NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new

PCI DSS: scope, which SAQ, the 12 requirements and tools

The PCI DSS obligation comes from your acquirer and payment processor, not a regulator, and two facts decide the shape of the programme. The first is whether you store, process or transmit cardholder data, and through which channels. The second is the validation route that follows: a self-assessment questionnaire, or a Report on Compliance for a Level 1 entity. Settle both first, because they decide how much of the 12 requirements you must evidence. Then work the requirements against v4.0.1, including the controls that became mandatory in March 2025, and only then compare platforms, remembering that no software replaces an Approved Scanning Vendor.

4 pages on PCI DSS, in the order the work happens. Jump to the stage you are at, or read straight through.

Stop reading. Start scoring.

The free compliance check runs the PCI DSS gap assessment in about five minutes and gives you a scored report you can take to a board meeting.

14-day free trial · no credit card · unlimited users