PCI DSS v4.0 — Gap Analysis
Payment Card Industry Data Security Standard — v4.0About PCI DSS v4.0
PCI DSS v4.0 (published March 2022, with full effective date 31 March 2025) is the latest version of the global Payment Card Industry Data Security Standard. It introduces a customised approach for compliance, expanded multi-factor authentication, increased password length, automated detection, targeted risk analysis, and many new clarifications. It is mandatory for any organisation handling cardholder data on behalf of major card brands (Visa, Mastercard, AmEx, Discover, JCB).
Issuing Body
PCI Security Standards Council
Edition
2022
Coverage
12 requirements organised into 6 goals — building secure networks, protecting cardholder data, vulnerability management, access control, monitoring, and policy.
Typical Users
Merchants, service providers, payment processors and any organisation that stores, processes or transmits cardholder data.
How to use this tool
1. Work through each clause. For each requirement, choose Compliant, Partial, Non-compliant, or leave as Not assessed.
2. Add notes against any requirement to record evidence, gaps, or corrective actions.
3. Click Save progress — data is stored locally in your browser, never uploaded.
4. Export the report as TXT, CSV, JSON or print to PDF for your audit file.
Note: This tool is a guided self-assessment. It does not replace a third-party audit and the authoritative version of the standard must be obtained from the issuing body.
ISO Xpert — Get in touch
UK-based consultancy specialising in management-system gap analysis, training and certification preparation across ISO, API, Halal, GFSI, ESG, cybersecurity and industry-specific standards.
Phone / WhatsApp
Office
71-75 Shelton Street, Covent Garden, London WC2H 9JQ, UK