Frameworks

PCI DSS 4.0, continuously, not annually.

Version 4.0 pushed PCI DSS toward security as a continuous process. TruOps helps you keep the evidence continuous too.

PCI DSS 4.0 · readinessevidence current
PCI DSS 4.0 · coverage by requirement
1 Network security controlssatisfied · 96%
2 Secure configurationssatisfied · 87%
3 Protect stored account datasatisfied · 90%
4 Encrypt in transmissionsatisfied · 86%
5 Anti-malwaresatisfied · 95%
6 Secure systems & softwarepartial · 73%
7 Restrict accesssatisfied · 87%
8 Identify & authenticatepartial · 69%
10 Log & monitorsatisfied · 98%
11 Test regularlypartial · 68%
12 Policies & programsatisfied · 94%
The same work also counts toward
SOC 270% · partials shown
ISO 2700164% · partials shown
NIST CSF68% · partials shown

Mappings are typed exact, partial, or inferred, each with a citation.

Illustrative example
In short

The Payment Card Industry Data Security Standard (PCI DSS) is maintained by the PCI Security Standards Council and applies to any entity that stores, processes, or transmits cardholder data. It has 12 principal requirements. Version 4.0.1 is current; version 3.2.1 was retired in March 2024, and requirements that were future-dated in 4.0 became mandatory on 31 March 2025. Compliance is validated by a Report on Compliance (ROC) or a Self-Assessment Questionnaire (SAQ).

This page is for you if
  • v4.0.1 made several activities continuous and your evidence is still annual
  • SAQ or ROC prep is a fire drill every cycle
  • Card data touches more vendors than your scope document admits
Maintained by
PCI Security Standards Council
Current version
v4.0.1
Requirements
12 principal requirements
Validation
ROC (by a QSA) or SAQ

The 12 requirements

  • 1. Install and maintain network security controls
  • 2. Apply secure configurations to all system components
  • 3. Protect stored account data
  • 4. Protect cardholder data with strong cryptography during transmission
  • 5. Protect all systems and networks from malicious software
  • 6. Develop and maintain secure systems and software
  • 7. Restrict access to system components and cardholder data by business need to know
  • 8. Identify users and authenticate access
  • 9. Restrict physical access to cardholder data
  • 10. Log and monitor all access to system components and cardholder data
  • 11. Test security of systems and networks regularly
  • 12. Support information security with organizational policies and programs

The actual challenge

PCI 4.0 pushed the standard toward security as a process. Teams that still collect evidence in the month of the QSA visit will fail the process, even if they pass the checklist.

  • Targeted risk analyses are supposed to set frequency; they were done once.
  • Scope changes with new stores, sites, and payment flows, and the ROC does not.
  • Requirement 12.8 (service providers) is a vendor program in disguise, run from email.

Bring one real document. Watch the program get set up from it.

What you are probably using today

Almost nobody starts PCI DSS 4.0 from zero. You already have a program somewhere. TruOps is built to take that over, not make you start again.

What you use nowWhere it breaksWith TruOps
Spreadsheets, shared drives, and emailThe program lives in folders named after last year's audit. Owners paste screenshots the week before fieldwork. Nothing is dated, so you cannot show what was true last quarter.Upload those same files. TruOps pre-fills the assessment from them, cites every answer, and keeps technical checks running so evidence exists for the whole period.
SOC 2 automation toolsThey are strong at certification: automated tests, a broad framework library, and often a trust center. Maturity scoring, custom frameworks, and deep risk or vendor work can sit outside that model.Keep the automation. Run any framework as the anchor, map the rest with partials shown as partial, and run vendor and risk on the same engine. Upload the policies and reports you already have.
Enterprise GRC suitesThey can model almost anything. That flexibility usually comes through implementation partners and administrators, so a change can become a project.AI reads your existing documents and sets up the program. The first assessment opens pre-filled from them, with sources. Changes are a request in plain language, not a project.

What 4.0 changed

Version 4.0 introduced a customized approach for meeting requirements, targeted risk analyses to set the frequency of some activities, stronger authentication requirements, and a heavier emphasis on security as a continuous process. The future-dated requirements became mandatory on 31 March 2025.

How TruOps helps with PCI DSS

Pick PCI DSS as your anchor, or map it to the framework you already run. TruOps keeps PCI DSS's own structure, down to the individual requirement, and shows coverage per requirement as satisfied, partial, or open, with the evidence behind each.

Upload what you have (prior reports, policies, spreadsheets) and TruOps pre-fills your PCI DSS assessment with cited answers. Connected tools keep technical controls current on the schedule you set, and failed checks become findings with a recommended fix.

If this is your situation

Bring last year's ROC or SAQ. TruOps keeps the 12 requirements assessed and technical controls monitored, and puts service-provider oversight on the same vendor engine.

How TruOps helps

Anchor or map
Run PCI DSS as your spine or map it to another framework; work counts once.
Pre-filled assessment
Your PCI DSS assessment opens with the answers your evidence supports already filled, each cited.
Honest coverage
Partial coverage is reported as partial, with the remaining requirements listed.
Continuous monitoring
Technical controls checked against your tools hourly to quarterly.
Findings with fixes
Failed checks become grouped findings with a recommended action.
Audit-ready snapshots
Results saved as of their date, with the evidence trail attached.

Questions

What is the current version of PCI DSS?

Version 4.0.1. Version 3.2.1 was retired on 31 March 2024, and the future-dated requirements of 4.0 became effective on 31 March 2025.

What is the difference between a ROC and an SAQ?

A Report on Compliance is completed by a Qualified Security Assessor for larger merchants and service providers; a Self-Assessment Questionnaire is completed by eligible smaller entities themselves.

Can TruOps certify PCI compliance?

No. Validation comes from a QSA or your SAQ. TruOps prepares the assessment and keeps the evidence current.

Do we have to rip out the tools we already use?

No. Connectors are read-only: they observe cloud, identity, endpoint, vulnerability, and code tools; they do not change them. Spreadsheets, prior reports, and policies upload into the Data Room. If you are on a SOC 2 automation tool or an enterprise GRC suite, you migrate the program (frameworks, evidence, vendors, risks), not the business.

Can we bring our existing assessments, control lists, and vendor files?

Yes. Upload workbooks, reports, policies, and vendor exports. TruOps turns them into structured questionnaires, controls, and register entries, each cited back to the file they came from, for you to review.

Does TruOps replace our auditor, QSA, or certification body?

No. Only a licensed auditor, QSA, C3PAO, or accredited certification body can issue the opinion. TruOps gets the evidence current, cited, and dated so fieldwork is a review, not an archaeology project.

See it run on your own data.

Thirty minutes with a GRC expert, not an SDR. Bring one real document (a SOC 2 report, a risk register, a vendor list; redacted is fine) and watch TruOps set up a live program from it, with an assessment already pre-filled.