Home/ Frameworks/ PCI DSS
Framework · PCI DSS v4.0

PCI DSS v4.0: 64 new requirements. The same deadline. One platform to close the gap.

PCI DSS version 4.0 introduced the “customized approach”—more flexibility, but also more documentation burden. Sentrix automates continuous evidence collection across all 12 PCI DSS requirements and maps your cardholder data environment controls automatically, so your QSA review becomes a formality rather than a fire drill.

12
PCI DSS v4.0 requirements—all monitored continuously with automated evidence from your CDE
Mar ’25
PCI DSS v4.0 mandatory enforcement date—v3.2.1 is retired, v4.0 is now the only valid standard
64
New v4.0 requirements added vs. v3.2.1—Sentrix tracks all of them with pre-built controls
1-click
QSA-ready evidence package with network diagrams, data flows, and control evidence on demand
What PCI DSS v4.0 requires

12 requirements. 300+ controls. Quarterly scans. Annual QSA review.

PCI DSS applies to any organization that stores, processes, or transmits cardholder data. Version 4.0 added a “customized approach” that allows more flexible control implementation—but requires more documentation. It also introduced new requirements for phishing-resistant MFA, targeted risk analysis, and application security testing.

  • Req. 1–2: Network security controls and secure configuration
  • Req. 3–4: Protect cardholder data at rest and in transit
  • Req. 5–6: Protect against malicious software and vulnerable systems
  • Req. 7–8: Restrict access and authentication
  • Req. 10–11: Log monitoring, vulnerability management, and quarterly scanning
  • Req. 12: Support information security with organizational policies

PCI DSS v4.0 · Requirement coverage

CDE MAPPED
Req. 1–2: Network & config✓ PASS
Req. 3–4: Cardholder data protection✓ PASS
Req. 5–6: Malware & vulnerabilities✓ PASS
Req. 7–9: Access control & physical✓ PASS
Req. 10–11: Logging & testing▲ REVIEW
Req. 12: Security policy✓ PASS
⚠ Req. 11.3: Quarterly internal scan due in 18 days
Full PCI DSS v4.0 capabilities

Everything your PCI compliance program requires.

CDE scoping & data flow

Automated cardholder data environment inventory with network segmentation verification. Data flow diagrams updated continuously as your infrastructure changes. Required for every QSA engagement.

Quarterly scan tracking

PCI DSS requires quarterly internal and external vulnerability scans. Sentrix tracks scan schedules, ingests results from Tenable, Qualys, and Rapid7, and alerts you before scan SLAs expire.

v4.0 new requirements

All 64 new v4.0 requirements tracked including targeted risk analysis, phishing-resistant MFA documentation, and application security testing evidence collection.

SAQ automation

For merchants using SAQ A, A-EP, B, B-IP, C, D, or P2PE: Sentrix pre-populates your Self-Assessment Questionnaire from your actual control configuration, reducing completion time from weeks to hours.

QSA workspace

Give your Qualified Security Assessor read-only access to your complete evidence set. Pre-formatted ROC documentation. All evidence linked and timestamped for defensibility.

Cross-framework mapping

PCI DSS controls mapped to SOC 2, ISO 27001, and OSFI B-10 simultaneously. Financial institutions managing multiple standards satisfy all of them from one evidence set.

See your PCI DSS v4.0 coverage on your real CDE.

We connect to your environment live and show your control status before the call ends.