Skip to content

PCI DSS 4.0.1 Compliance Consulting

PCI DSS 4.0.1 Consulting

PCI DSS compliance is more than just meeting payment card requirements. It helps your company protect cardholder data, reduce security risks, and maintain the controls expected by your bank, payment brands, customers, and partners.

Tanner Security provides PCI DSS consulting, gap assessments, policy development, security and vulnerability assessments, and penetration testing. We help businesses understand their PCI obligations and build a clear path to compliance.

PCI DSS v4.0.1 is the newest version of the Payment Card Industry Data Security Standard. The PCI Security Standards Council released it in June 2024 to address and clarify parts of v4.0. Since v4.0 was retired on December 31, 2024, companies should now follow v4.0.1.

Tanner Security helps leaders and IT teams understand PCI DSS requirements, identify which controls apply, find gaps, and decide what to address first.

Talk With a PCI Compliance Expert

Schedule a consultation to discuss your PCI environment, compliance needs, and security goals.

PCI DSS 4.0.1 Compliance Consulting

What Is PCI DSS?

The Payment Card Industry Data Security Standard (PCI DSS) is a set of rules for companies that store, process, or send payment card data. PCI DSS sets technical and operational requirements to protect payment data at every stage.

PCI DSS is not just a single product or checklist. What you need to do depends on how your company handles payment card data, which systems connect to your payment setup, what services you outsource, and the rules set by payment brands or your bank.

PCI SSC supports the standard and supporting assessment tools, while payment brands and acquirers determine validation and reporting requirements for many merchants and service providers.

This distinction matters.

A company might need to complete a Self-Assessment Questionnaire (SAQ), a Report on Compliance (ROC), certain technical tests, or meet additional requirements from payment partners. The right steps depend on your company’s setup and the applicable rules.

PCI DSS v4.0.1: What Companies Need to Know

PCI DSS v4.0.1 keeps the 12 main requirements and clarifies certain sections of the standard. These requirements cover network security, secure configurations, stored account data, encryption, malware protection, secure software development, access control, authentication, physical access, logging, monitoring, security testing, and security policies.

The 12 requirements are designed to protect your payment environment, not just to complete paperwork. For many companies, the biggest challenge is determining which systems, applications, users, service providers, and processes fall within the PCI scope.

PCI DSS v4.x gives companies more flexibility through the Defined and Customized Approaches. The Customized Approach allows a company to meet security goals with its own controls instead of following standard requirements, but it does require more documentation and risk analysis.

Tanner Security can help your team choose the best approach for your environment and guide you on how to document your decisions for your assessment.

Who Needs PCI DSS Compliance?

PCI DSS usually applies to any company that accepts processes, stores, or sends payment card data.

This includes retailers, e-commerce businesses, healthcare providers, financial firms, software companies, hospitality businesses, professional services, manufacturers, and any other business that takes card payments.

Your company’s PCI scope can change significantly depending on how you handle payments.

For example, if your company sends customers to a third-party payment processor, your environment is very different from a company that hosts its own payment pages, runs point-of-sale systems, stores account data, or connects internal systems to its Cardholder Data Environment.

PCI SSC notes that SAQ eligibility is determined by the criteria for each assessment type. Companies should check with the appropriate compliance authority to confirm their eligibility and validation requirements, rather than assuming a specific SAQ applies.

We love working with the Information Security team at Tanner Security. They customized their service offerings to fit our PCI needs and put together a team of well-qualified individuals to work with us. Their team has exceeded my expectations.

Brad B. – President

Understanding Your Cardholder Data Environment

The Cardholder Data Environment (CDE) includes the systems and components that store, process, or transmit cardholder data, as well as other systems and components that can affect the security of that environment.

Understanding the CDE is one of the most important parts of a PCI compliance program.

If you do not define your scope clearly, you face two main problems.

First, your company might waste time checking systems that have little or nothing to do with payment security. Second, and more importantly, you could overlook a key system or connection in your assessment.

Tanner Security helps companies examine network architecture, payment applications, cloud services, endpoints, access controls, third-party connections, and other relevant components to establish a defensible understanding of PCI scope.

We also help businesses review segmentation and other controls that can reduce unnecessary risks and make ongoing compliance easier.

PCI DSS Compliance Consulting Services

Tanner Security approaches PCI compliance as a security and risk management issue, not just a paperwork task.

PCI Gap Assessments: A PCI gap assessment compares your current security controls and practices against the PCI DSS requirements that apply to your environment. We find gaps, explain why they matter, help you set priorities, and work with your team to create a practical plan that addresses the most serious issues first. A gap assessment is especially helpful if your company is preparing for its first PCI assessment, moving to PCI DSS v4.0.1, changing payment platforms, expanding its payment environment, or responding to past assessment findings.

PCI DSS Compliance Assessments: A PCI compliance assessment provides a wider review of your security controls against applicable PCI DSS requirements. Tanner Security evaluates areas such as access control, authentication, vulnerability management, network security, security policies, logging, monitoring, incident response, and security testing. The goal goes beyond simply answering “yes” or “no.” We want your leadership team to understand where risks exist, why the controls matter, and what your company should do next.

PCI Policy Consulting: PCI DSS requires more than technical controls. Your company also needs policies and procedures that support the security of payment card data. Tanner Security can review and develop policies covering information security, acceptable use, access management, vulnerability management, incident response, third-party risk, security awareness, data retention, and other areas relevant to your PCI program. We focus on practical policies your employees can use, not just generic documents that get ignored.

PCI CDE Penetration Testing: Penetration testing goes beyond identifying possible vulnerabilities. It attempts to determine whether an attacker can exploit weaknesses and what access that attacker could obtain. Tanner Security performs PCI CDE penetration testing to evaluate the security of systems and networks that support payment card processing. Our testing can include vulnerability identification, manual validation, exploitation, privilege escalation, lateral movement, and other techniques that fit the approved scope.

Protect Your Organization

Contact us today to discuss the requirements and embark on a compliance journey that ensures the trust and security of your customers’ sensitive information.

PCI DSS Compliance and E-Commerce Security

E-commerce businesses face additional concerns because attackers can target web apps, payment pages, scripts, APIs, browsers, third-party services, and other components of online transactions.

PCI DSS v4.x introduced important e-commerce security requirements, including requirements addressing payment page scripts and mechanisms for detecting and stopping unauthorized changes. PCI SSC has issued additional guidance around these requirements because their implementation can create challenges for e-commerce merchants.

Your payment processor might handle some security tasks, but outsourcing payment functions does not automatically remove your company’s responsibilities.

Tanner Security can review your payment setup and help you understand which responsibilities remain with your company, and which belong to your third-party providers.

PCI Compliance

PCI DSS and Third-Party Service Providers

Many businesses rely on payment processors, cloud providers, managed service providers, e-commerce platforms, hosting companies, and other third parties.

Those relationships can reduce your PCI scope, but they do not automatically remove your PCI responsibilities.

PCI SSC makes an important distinction between merchant and service-provider assessments. A service provider cannot simply use the eligibility criteria from a merchant SAQ to determine its own PCI requirements.

Your company should understand:

  • Which PCI responsibilities remain with your business
  • Which controls your service providers support
  • What evidence those providers can provide
  • How you monitor critical third-party relationships
  • Whether contracts and policies clearly define security responsibilities

Tanner Security can help your team evaluate these relationships as part of a broader PCI compliance program.

PCI DSS v4.0.1 Compliance Process

Every PCI project should match your company’s real payment environment, but the process usually starts with understanding your scope.

  1. Define the Environment: We start by learning how your company accepts, processes, stores, and sends payment card data. We review the systems, applications, networks, users, vendors, and integrations that support these processes.
  1. Assess Current Controls: We check your security controls against PCI DSS requirements and find any gaps that could affect your compliance or security.
  1. Prioritize Risk: Not every gap carries the same risk. We help leaders and IT teams set priorities based on how easy a gap is to exploit, its possible impact, scope, and importance to your company’s operations.
  1. Remediate Gaps: Your team can then address the issues we found. Tanner Security can guide you on policies, security controls, fixing vulnerabilities, penetration testing, network setup, access management, and more.
  1. Validate Compliance: The appropriate validation and reporting process depends on the applicable requirements and the entity receiving the assessment results. PCI SSC notes that payment brands, acquirers, and other compliance-accepting entities can establish validation and reporting requirements.
  1. Maintain Compliance: PCI compliance needs ongoing attention. Changes to payment applications, infrastructure, vendors, network architecture, personnel, and security controls can affect your compliance obligations and security posture.

Why Choose Tanner Security for PCI Compliance Consulting?

PCI compliance combines cybersecurity, business operations, risk management, and regulations. Your consultant should understand more than just the rules in the standard.

Tanner Security has over twenty years of cybersecurity consulting experience and works with PCI DSS, NIST, CMMC, ISO 27001, HIPAA, CIS Controls, penetration testing, IT audits, and cybersecurity risk assessments. Our approach focuses on identifying practical security risks instead of selling security products.

We look at PCI compliance from both perspectives: the official requirements and the real security risks behind them.

This is important because a company can complete a compliance checklist but still face serious cybersecurity risks.

Our team helps businesses understand what needs to change, why it matters, and how to set priorities.

We also offer clear, fixed-fee services tailored to your project’s scope.

PCI DSS 4.0.1 Compliance FAQ’s

PCI DSS 4.0.1 is the current version of the Payment Card Industry Data Security Standard. PCI SSC published it in June 2024 as a limited revision to PCI DSS v4.0, correcting errors and clarifying requirements and guidance. It did not add or remove requirements from v4.0.

PCI DSS v4.0 retired on December 31, 2024. Companies conducting PCI assessments today should use PCI DSS v4.0.1 and the applicable supporting assessment documents.

PCI DSS applies to companies that store, process, or transmit payment card account data, as well as to other parties that can affect the security of payment card data. The exact validation requirements depend on the company’s environment and the applicable payment brand, acquirer, or other compliance requirements. Read more about how to navigate PCI compliance for small businesses.

Yes, your company may still have PCI responsibilities even when you outsource payment processing. Outsourcing can reduce certain aspects of PCI scope, but it does not automatically eliminate your responsibilities. Your company should understand the responsibilities that remain after outsourcing. Read more about when a company can say they are PCI complaint.

The Cardholder Data Environment includes systems and components that store, process, or transmit cardholder data as well as other components that can affect the security of that environment. Properly defining the CDE represents an important part of a PCI assessment.

PCI DSS contains 12 core requirements covering network security controls, secure configurations, stored account data, encryption, malware protection, secure software development, access control, authentication, physical access, logging and monitoring, security testing, and information security policies.

A PCI gap assessment compares your current security controls and practices against applicable PCI DSS requirements. The assessment identifies deficiencies and gives your company a roadmap for remediation.

Some environments require PCI CDE penetration testing as part of PCI DSS validation. The specific testing requirements depend on the applicable PCI DSS requirements, scope, and validation method. Tanner Security can help determine where penetration testing fits within your PCI program and perform appropriate testing.

A vulnerability scan primarily identifies known weaknesses. A PCI penetration test takes it further by attempting to exploit vulnerabilities and determine their possible impact. PCI DSS can require both vulnerability scanning and penetration testing depending on the environment and applicable requirements. Read more about the difference between external penetration test vs vulnerability assessment.

PCI DSS includes vulnerability management and security testing requirements, but the exact testing frequency and methods depend on the applicable requirements and the assessment type. Companies should review their current PCI DSS requirements rather than assume that a single scanning schedule applies to every environment.

A Self-Assessment Questionnaire, or SAQ, helps eligible merchants or service providers assess and document compliance with applicable PCI DSS requirements. Companies should confirm that they meet the eligibility criteria for the specific SAQ and confirm validation requirements with the relevant compliance-accepting entity.

PCI DSS v4.0 introduced changes intended to offer flexibility, strengthen security practices, and handle evolving payment threats. It introduced the Customized Approach, added targeted risk analysis requirements for certain areas, and introduced new requirements that would take effect after a future-dated transition period.

The Customized Approach lets a company meet the security objective of a PCI DSS requirement through customized controls rather than following the Defined Approach. The company must document customized controls and perform the required targeted risk analysis and supporting assessment work.

No. PCI DSS serves as its own payment security standard. A company can use other frameworks and security practices to strengthen its program, but those frameworks do not replace applicable PCI DSS requirements.

PCI compliance requires ongoing management rather than a once-a-year paperwork exercise. Your company should monitor changes to its payment environment, systems, vendors, applications, network architecture, and security controls and determine whether those changes affect PCI scope or requirements.

Schedule a PCI Compliance Consultation

Talk with a Tanner Security consultant about your environment and discover the best next step for your PCI DSS program.

Start Your PCI DSS Compliance Assessment

PCI compliance should give your company more than just a completed checklist. It should give you confidence that your systems have the right security controls and that your team understands what risks remain.

Tanner Security can help you find gaps, set priorities, improve security controls, and prepare for your next PCI assessment.