Compliance

PCI-DSS Checklist

A PCI DSS checklist tracks the twelve requirements every merchant and service provider that stores, processes or transmits cardholder data must meet. This one saves progress locally and is a self-assessment aid; it does not replace the Self-Assessment Questionnaire or a Qualified Security Assessor.

Last reviewed by the Radiatus Cloud team

PCI-DSS Checklist

Checklist for Payment Card Industry Data Security Standard compliance.

0%

Going for ISO 27001, SOC 2, HIPAA or GDPR?

Radiatus runs end-to-end compliance & GRC programs.

Get a free readiness review

The twelve requirements, grouped

  • Secure network: 1, install and maintain network security controls; 2, apply secure configurations and remove vendor defaults.
  • Protect account data: 3, protect stored data; 4, encrypt it in transit over public networks.
  • Vulnerability management: 5, protect systems from malware; 6, develop and maintain secure systems and software.
  • Access control: 7, restrict access by need to know; 8, identify users and authenticate access; 9, restrict physical access.
  • Monitoring and testing: 10, log and monitor all access; 11, test security regularly.
  • Policy: 12, support security with organisational policies and programmes.

Version 4.0 is the standard now

PCI DSS 4.0 was published in March 2022 and became the only valid version when 3.2.1 retired on 31 March 2024. The 64 future-dated requirements became mandatory on 31 March 2025, and 4.0.1 in mid-2024 clarified wording without adding controls. The twelve headline requirements survived but were reworded: firewalls became network security controls, anti-virus became anti-malware. Notable new duties include multi-factor authentication for all access into the cardholder data environment, automated log review, a documented targeted risk analysis for each flexible frequency, and scripts on payment pages being inventoried and integrity-checked. The checklist wording here follows the traditional phrasing; map each item to its 4.0 clause when you fill in the SAQ.

Scope before controls

Most of the cost of PCI DSS comes from scope. If card numbers never touch your systems because a hosted payment page or a tokenising gateway handles them, you fall under SAQ A with around 30 questions rather than SAQ D with over 250. Network segmentation that keeps the cardholder data environment small has the same effect. Decide scope, document it, then work the checklist for what remains.

Using the checklist

Tick items as you gather evidence, not as you believe them done. Progress is stored in your browser and can be reset. Each item corresponds to a section of the SAQ or Report on Compliance that will need policies, configurations, logs or scan results behind it. Quarterly external scans by an Approved Scanning Vendor and, for some levels, annual penetration tests are part of requirement 11 and cannot be self-attested.

Related tools

Frequently Asked Questions

Which SAQ applies to my business?

SAQ A for fully outsourced card handling with a hosted payment page, A-EP if your site controls the redirect, B or B-IP for standalone terminals, C for connected payment applications, and D for everything else including service providers. Your acquirer confirms the level and SAQ.

Is PCI DSS a law?

No. It is a contractual obligation imposed by the card brands through your acquiring bank. Non-compliance leads to fines from the acquirer, higher fees, and after a breach, liability for fraud losses and card reissuance.

What changed in PCI DSS 4.0?

A customised approach alongside the defined controls, MFA for all access to the cardholder data environment, stronger password rules, automated log analysis, e-commerce script integrity checks, and targeted risk analyses to justify control frequencies. The future-dated items became mandatory in March 2025.

Does using Stripe or a similar gateway make me compliant?

It reduces scope to SAQ A if card data goes directly from the customer's browser to the gateway. You still complete and sign the SAQ, keep your site free of malicious scripts, and manage access to the gateway dashboard.

Is the checklist progress shared with anyone?

No. It is saved in your browser's local storage and stays on this device.

Privacy & Security

Local storage only.

Data: None
Client-side-Side
Active
v1.0

About This Tool

This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.