PCI DSS v4.0.1 Toolkit

Get to PCI compliance — without the guesswork.

A readiness assessment across the 12 requirements, a controls matrix covering all 250 defined-approach requirements, an SAQ selector, facilitation guides, board-ready templates, and a phased roadmap to your SAQ or ROC. Built for PCI DSS v4.0.1.

Is this right for you?

Built for teams that handle payment cards.

✓ Built for you if…

  • You store, process, or transmit cardholder data
  • You are preparing an SAQ or a QSA-led ROC (PCI DSS v4.0.1)
  • You need to scope your cardholder data environment
  • You want the full defined-approach requirements matrix to work from

Maybe not the fit if…

  • Your business never touches cardholder data
  • You already have a QSA managing the entire assessment for you
Choose your tier

Start your path to compliance.

Scope your cardholder data environment, score your readiness, track all 250 requirements to evidence, and work the roadmap to your SAQ or ROC. Instant download — no subscription.

Starter
$299

For teams beginning their PCI DSS journey and needing a structured read.

  • Readiness Assessment (Excel)
  • Quick Start Guide
  • Interview Guide & templates
  • Exec summary, findings & roadmap templates
  • Email support
  • 1 user license
Enterprise
$1,999

For the full compliance programme, end to end.

  • Everything in Professional
  • Controls Matrix — all 250 requirements
  • SAQ selector & scoping guide
  • Control implementation guidance & ISP template
  • Evidence / ROC-readiness checklist
  • RACI & remediation roadmap
  • 3 industry vertical packs
  • Executive workshop kit & unlimited users
30-day money-back guarantee Instant download after purchase Secure checkout via Stripe

Redirecting to secure checkout…

Try it first

Not sure yet? Start with the free readiness assessment.

The free PCI DSS readiness assessment scores you across the twelve requirements and shows your gaps and automatic-failure blockers. The toolkit is how you close them — and the controls tracker turns it into your 250-requirement evidence trail.

  • Free readiness assessment — a score, a requirement breakdown, and your gaps in plain language.
  • Controls tracker — set status and evidence against all 250 defined-approach requirements.
  • Expert help on request — scoping, an internal review, or a partner to reach your SAQ or ROC.
Run the free assessment Open the controls tracker
Questions

PCI DSS, answered

It gets you ready. Validation happens through a Self-Assessment Questionnaire (SAQ) or a QSA-led Report on Compliance (ROC), depending on your level. This toolkit prepares you for either and shortens the path.

PCI DSS v4.0.1 — the current version. The future-dated v4 requirements are now in effect, and the toolkit reflects them.

It depends on your merchant or service-provider level and how you handle card data. The toolkit includes an SAQ selector and scoping guide to point you to the right validation path.

Not necessarily — your SAQ type and scope determine which apply. The Controls Matrix covers all defined-approach requirements so you can scope precisely and exclude what is out of scope.

Scope reduction — segmentation, not storing card data, using compliant providers — is the biggest lever on PCI effort. The scoping guide walks through it before you assess.

Yes. Our team can scope your cardholder data environment, remediate gaps, and manage the QSA relationship. Start with the free assessment or book a consultation.

Need a hand?

Want to be taken all the way to your SAQ or ROC?

If you'd rather we scope the CDE, remediate the gaps, and get you validated, that's what our vCISO engagements are for. Tell us where you are and we'll recommend the right scope.