PCI DSS v4.0: 64 new requirements. The same deadline. One platform to close the gap.
PCI DSS version 4.0 introduced the “customized approach”—more flexibility, but also more documentation burden. Sentrix automates continuous evidence collection across all 12 PCI DSS requirements and maps your cardholder data environment controls automatically, so your QSA review becomes a formality rather than a fire drill.
12 requirements. 300+ controls. Quarterly scans. Annual QSA review.
PCI DSS applies to any organization that stores, processes, or transmits cardholder data. Version 4.0 added a “customized approach” that allows more flexible control implementation—but requires more documentation. It also introduced new requirements for phishing-resistant MFA, targeted risk analysis, and application security testing.
- Req. 1–2: Network security controls and secure configuration
- Req. 3–4: Protect cardholder data at rest and in transit
- Req. 5–6: Protect against malicious software and vulnerable systems
- Req. 7–8: Restrict access and authentication
- Req. 10–11: Log monitoring, vulnerability management, and quarterly scanning
- Req. 12: Support information security with organizational policies
PCI DSS v4.0 · Requirement coverage
CDE MAPPEDEverything your PCI compliance program requires.
CDE scoping & data flow
Automated cardholder data environment inventory with network segmentation verification. Data flow diagrams updated continuously as your infrastructure changes. Required for every QSA engagement.
Quarterly scan tracking
PCI DSS requires quarterly internal and external vulnerability scans. Sentrix tracks scan schedules, ingests results from Tenable, Qualys, and Rapid7, and alerts you before scan SLAs expire.
v4.0 new requirements
All 64 new v4.0 requirements tracked including targeted risk analysis, phishing-resistant MFA documentation, and application security testing evidence collection.
SAQ automation
For merchants using SAQ A, A-EP, B, B-IP, C, D, or P2PE: Sentrix pre-populates your Self-Assessment Questionnaire from your actual control configuration, reducing completion time from weeks to hours.
QSA workspace
Give your Qualified Security Assessor read-only access to your complete evidence set. Pre-formatted ROC documentation. All evidence linked and timestamped for defensibility.
Cross-framework mapping
PCI DSS controls mapped to SOC 2, ISO 27001, and OSFI B-10 simultaneously. Financial institutions managing multiple standards satisfy all of them from one evidence set.
See your PCI DSS v4.0 coverage on your real CDE.
We connect to your environment live and show your control status before the call ends.