Free checklist
PCI DSS v4 evidence checklist
What a QSA will ask for at each of the twelve requirements, and the scoping mistakes that make assessments expensive.
What is inside
- Scoping and segmentation validation
- Evidence per requirement
- Customised approach vs defined approach
- Common findings and remediation cost
Who it is for
Merchants, PSPs and acquirers. It is written to be usable on its own, without a consultant sitting next to you. If you want one anyway, that is what the consultation is for.
What PCI DSS 4.0 changed, and what it did not
PCI DSS 4.0 kept the twelve requirements and changed how they are satisfied. Two changes matter more than the rest for anyone preparing evidence.
The first is the customised approach. Alongside the defined approach, where you implement the control as written, you may now meet the security objective by another means, provided you document the objective, the control, the risk analysis and the testing. That flexibility is genuinely useful for modern architectures and it is also a considerably heavier evidence burden. Do not choose it because the defined control is inconvenient; choose it because the defined control does not fit your architecture, and expect to justify that.
The second is targeted risk analysis. Several requirements now let you set your own frequency, which sounds like relief and is actually an obligation to document why your frequency is appropriate and to review it.
What did not change is the fundamental economics: scope determines cost. Every hour spent reducing scope before an assessment saves considerably more during it.
Scope is the whole game
The cardholder data environment includes every system that stores, processes or transmits account data, and every system connected to or that could affect the security of those. That second clause is the one that expands scope past what people expect: a jump host, a monitoring agent, an authentication service, a flat network segment.
The single most effective control on a PCI programme is not a control at all. It is not holding the data. Tokenisation and a properly integrated hosted payment page remove entire requirements from your assessment rather than helping you satisfy them.
Where data must be held, segmentation determines how much of your estate is in scope. Segmentation that is asserted in an architecture diagram and not enforced by a rule is not segmentation, and it will be tested. Expect to demonstrate the rule and the change record for it.
Get scope agreed with your assessor in writing before evidence collection begins. Discovering a scope disagreement halfway through is the most expensive way to run an assessment.
The evidence that is hardest to produce after the fact
- Twelve months of quarterly internal and external vulnerability scans, with rescans showing remediation
- Change records for firewall and segmentation rules, tying each rule to a business justification
- Evidence that logs were reviewed, not merely collected and retained
- Records of the annual segmentation test, performed by an independent party
- Access reviews with a decision recorded and revocations traceable
- Targeted risk analyses supporting every self-determined frequency under 4.0
How to sequence a first assessment
Reduce scope first. Every subsequent step costs less for having done it, and it is the only step that reduces both effort and risk simultaneously.
Then confirm your SAQ eligibility or ROC path, because the evidence you need differs substantially and collecting the wrong set is a common and expensive mistake.
Then start the evidence that has a time dimension immediately. Quarterly scans and log review records cannot be produced retrospectively, so an assessment date twelve months out means starting them today rather than in month nine.
Then close the technical gaps, which are usually the least interesting part and the part organisations start with because it feels like progress.
Who owns each piece of evidence
PCI evidence cuts across teams in a way that catches organisations out. Network and segmentation evidence sits with infrastructure. Scanning and remediation sits with security. Change records sit wherever change management lives, which is frequently a different function again. Access reviews sit with whoever owns each system.
The commonest cause of a stalled programme is not a missing control but an unassigned artefact. Assign an owner per requirement, as a named person rather than a team, and record where the artefact lives and how often it is produced.
If an artefact is produced only when somebody asks, it will not exist when the assessor asks.
The twelve months before validation
Work backwards from the assessment date. Anything with a time dimension has to start immediately: quarterly internal and external scans with rescans showing remediation, log review records, and the annual segmentation test.
Then confirm your validation route in writing with your acquirer. Preparing evidence for the wrong questionnaire is one of the more expensive mistakes available.
Then reduce scope, which lowers the effort of everything that follows and continues paying every year afterwards.
Then close technical gaps, which is where teams instinctively begin and is the least effective starting point.
Compensating controls, and when they are worth using
Where a requirement genuinely cannot be met as written, PCI DSS has always allowed a compensating control, and 4.0 adds the customised approach alongside it. Both are legitimate and both are heavier than the defined control they replace.
A compensating control has to meet the intent and rigour of the original, provide a comparable level of defence, be above and beyond other requirements, and be commensurate with the additional risk. Each of those is tested, and the documentation burden is where organisations underestimate the cost.
The practical guidance is simple. Use them where your architecture makes the defined control genuinely inapplicable. Do not use them because the defined control is inconvenient or because the deadline is close, because you will carry the documentation and the annual re-justification for as long as the control exists.
Working with your QSA rather than around them
The assessment goes considerably better when the assessor sees the estate early rather than at evidence review. Agreeing scope in writing before collection begins is the single most valuable conversation in the programme.
Raise the difficult areas yourself. An assessor who discovers a segmentation weakness is in a different position from one who was told about it in week two alongside your plan for it.
Ask what evidence format they prefer for each requirement. Reformatting a year of collected evidence because it was gathered in a shape the assessor cannot use is avoidable and depressingly common.












