> ## Documentation Index
> Fetch the complete documentation index at: https://docs.matproof.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Getting Started with PCI DSS

> A practical guide to meeting PCI DSS v4.0 requirements for organizations that store, process, or transmit cardholder data using Matproof.

# Getting Started with PCI DSS

The Payment Card Industry Data Security Standard (PCI DSS) is a set of security requirements for any organization that stores, processes, or transmits cardholder data. PCI DSS v4.0 is the current version, with the transition period from v3.2.1 completed on **March 31, 2024**. Additional future-dated requirements in v4.0 become mandatory on **March 31, 2025**.

PCI DSS is maintained by the PCI Security Standards Council and enforced through the payment card brands (Visa, Mastercard, American Express, Discover, JCB). Compliance is validated through Self-Assessment Questionnaires (SAQs) or on-site assessments by a Qualified Security Assessor (QSA), depending on your transaction volume and merchant level.

Matproof maps PCI DSS v4.0 requirements to controls, policies, and evidence workflows so you can prepare for your annual assessment.

<Note>
  Activate PCI DSS under **Settings - Frameworks - PCI DSS**. Controls are pre-populated across all 12 requirements and their sub-requirements.
</Note>

***

## Am I in Scope?

PCI DSS applies to any entity that stores, processes, or transmits **cardholder data** or **sensitive authentication data**, including:

* Merchants (online and physical)
* Payment processors and acquirers
* Issuers
* Service providers that handle cardholder data on behalf of other entities

<Tip>
  Reduce your scope by minimizing where cardholder data is stored and processed. Using a PCI-compliant payment processor (like Stripe or Adyen) that tokenizes card data can significantly reduce the number of applicable requirements.
</Tip>

***

## The 12 PCI DSS Requirements

PCI DSS is organized into six goals and 12 requirements:

| Goal                                            | Requirement                                                                          | Matproof Module       |
| ----------------------------------------------- | ------------------------------------------------------------------------------------ | --------------------- |
| **Build and Maintain a Secure Network**         | 1. Install and maintain network security controls                                    | Controls              |
|                                                 | 2. Apply secure configurations to all system components                              | Controls              |
| **Protect Account Data**                        | 3. Protect stored account data                                                       | Controls, Evidence    |
|                                                 | 4. Protect cardholder data with strong cryptography during transmission              | Controls              |
| **Maintain a Vulnerability Management Program** | 5. Protect all systems and networks from malicious software                          | Controls              |
|                                                 | 6. Develop and maintain secure systems and software                                  | Controls, Policies    |
| **Implement Strong Access Control Measures**    | 7. Restrict access to system components and cardholder data by business need to know | Controls, People      |
|                                                 | 8. Identify users and authenticate access to system components                       | Controls              |
|                                                 | 9. Restrict physical access to cardholder data                                       | Controls              |
| **Regularly Monitor and Test Networks**         | 10. Log and monitor all access to system components and cardholder data              | Controls, Evidence    |
|                                                 | 11. Test security of systems and networks regularly                                  | Controls, Cloud Tests |
| **Maintain an Information Security Policy**     | 12. Support information security with organizational policies and programs           | Policies, People      |

***

## PCI DSS v4.0 Key Changes

If you were compliant with v3.2.1, these are the most significant changes in v4.0:

| Change                           | Impact                                                                                                                                                    |
| -------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Customized approach**          | Organizations can now meet requirements using alternative controls with a customized validation approach, in addition to the traditional defined approach |
| **Targeted risk analysis**       | Required for certain requirements where frequency or scope is determined by the entity                                                                    |
| **Enhanced authentication**      | Multi-factor authentication required for all access to the cardholder data environment (not just remote access)                                           |
| **Automated technical controls** | Greater emphasis on automated mechanisms for detection and response                                                                                       |
| **Security awareness**           | Enhanced training requirements including phishing awareness                                                                                               |

***

## Recommended Implementation Plan

<Steps>
  ### Step 1 - Define your cardholder data environment (CDE)

  1. Identify all systems that store, process, or transmit cardholder data
  2. Map data flows showing how cardholder data enters, moves through, and exits your environment
  3. Identify all connected systems and networks
  4. Document the CDE scope in **Settings - Organization**
  5. Review scope annually and after any significant change to your environment

  <Warning>
    Scope creep is the most common PCI DSS compliance failure. Any system connected to the CDE is in scope. Use network segmentation to limit scope and reduce the number of applicable controls.
  </Warning>

  ### Step 2 - Generate PCI DSS policies

  Go to **Policies - Generate** and create the required policy set:

  * Information Security Policy
  * Acceptable Use Policy
  * Access Control Policy
  * Network Security Policy
  * Encryption and Key Management Policy
  * Incident Response Policy
  * Change Management Policy
  * Vulnerability Management Policy
  * Physical Security Policy

  Each policy must be reviewed at least annually and updated when the environment changes.

  ### Step 3 - Network security and secure configurations

  Requirements 1 and 2 establish the foundation:

  1. Document and implement network security controls (firewalls, network segmentation)
  2. Establish secure configuration standards for all system components
  3. Remove or disable unnecessary services, protocols, and accounts
  4. Link configuration evidence to the relevant controls in Matproof

  ### Step 4 - Protect account data

  Requirements 3 and 4 address data protection:

  1. Inventory all locations where cardholder data is stored
  2. Implement strong cryptography for stored data (Requirement 3) and data in transit (Requirement 4)
  3. Document your encryption key management procedures
  4. Implement data retention and disposal policies
  5. Never store sensitive authentication data after authorization

  ### Step 5 - Vulnerability management

  Requirements 5 and 6:

  1. Deploy anti-malware solutions on all systems commonly affected by malware
  2. Establish a vulnerability management program with regular scanning
  3. Apply critical security patches within one month of release
  4. Implement secure software development practices if you develop payment applications
  5. Conduct vulnerability scans quarterly (internal and external ASV scans)

  ### Step 6 - Access control and authentication

  Requirements 7, 8, and 9:

  1. Implement role-based access control - restrict access to cardholder data by business need to know
  2. Assign unique IDs to all users with access to system components
  3. Implement multi-factor authentication for all access to the CDE
  4. Implement physical access controls for facilities housing cardholder data
  5. Document and link access reviews as evidence in Matproof

  ### Step 7 - Logging, monitoring, and testing

  Requirements 10 and 11:

  1. Enable audit logging for all system components in the CDE
  2. Review logs daily (automated log monitoring tools are recommended)
  3. Conduct quarterly internal and external vulnerability scans
  4. Perform annual penetration testing of the CDE
  5. Implement change detection mechanisms for critical files

  ### Step 8 - Security policy and training

  Requirement 12:

  1. Ensure all policies are current and reviewed annually
  2. Conduct security awareness training for all personnel upon hire and annually
  3. Include phishing simulation exercises (new in v4.0)
  4. Maintain an incident response plan and test it annually
  5. Conduct a targeted risk analysis where required by specific sub-requirements

  ### Step 9 - Assessment preparation

  1. Go to **Audit Programs - New Audit - PCI DSS**
  2. Run an internal assessment against all applicable requirements
  3. Remediate gaps documented as Corrective Actions
  4. Determine your merchant level and appropriate validation method (SAQ or QSA assessment)
  5. Engage a QSA if required, or complete the appropriate SAQ
</Steps>

***

## Merchant Levels

| Level | Transaction Volume (Visa)                                                   | Validation                                         |
| ----- | --------------------------------------------------------------------------- | -------------------------------------------------- |
| 1     | Over 6 million transactions per year                                        | Annual on-site QSA assessment + quarterly ASV scan |
| 2     | 1-6 million transactions per year                                           | Annual SAQ + quarterly ASV scan                    |
| 3     | 20,000 - 1 million e-commerce transactions per year                         | Annual SAQ + quarterly ASV scan                    |
| 4     | Fewer than 20,000 e-commerce or up to 1 million other transactions per year | Annual SAQ + quarterly ASV scan (recommended)      |

<Note>
  Merchant levels and validation requirements vary by card brand. The table above reflects Visa's classification. Check with your acquiring bank for your specific obligations.
</Note>

***

## Next Steps

* [Controls](/features/controls) - working through PCI DSS requirement controls
* [Evidence Collection](/features/evidence-collection) - automated evidence from integrations
* [Cloud Tests](/features/cloud-tests) - vulnerability scanning and penetration testing evidence
* [Vendor Risk](/features/vendor-risk) - service provider compliance management
