Scope and data-flow register
Record how card data enters, moves and leaves the business, which systems sit in the CDE, and which third parties share responsibility.
Scope your cardholder data environment, map all 12 PCI DSS requirements to real controls, keep evidence current all year, and walk into your SAQ or QSA assessment with the pack already built.
PCI compliance is rarely hard because the requirements are obscure. It is hard because the evidence is scattered: scan reports in one inbox, access reviews in a spreadsheet, policies in a shared drive, and a scope diagram nobody has updated since the last payment integration changed.
ISO-STANDARD.app gives you PCI DSS compliance software that keeps scope, controls and evidence together throughout the year, and reuses everything you have already done for ISO 27001 or SOC 2 instead of starting again.
Record how card data enters, moves and leaves the business, which systems sit in the CDE, and which third parties share responsibility.
All 12 requirements broken down into testable sub-requirements, each linked to a control, an owner and its supporting evidence.
Version 4 requires documented risk analyses for several controls. Run them in the risk register with a defensible, repeatable method.
Export the documentation set your acquirer or QSA asks for, with everything timestamped and attributable.
Track ASV scans, internal vulnerability scans and penetration test findings through to verified closure, with due dates that do not slip quietly.
Scheduled access reviews, MFA coverage over the CDE, and evidence that daily log review actually happened.
Documented data flows make it obvious where card data can be removed, tokenised or segmented out — the single biggest lever on PCI cost.
Scans, reviews and approvals are captured as they happen, so validation is an export rather than a month of chasing.
Cross-mapped controls mean access control, logging and vulnerability management count once across every framework.
Every requirement has a named owner and a due date, so nothing depends on one person remembering.
Assessors spend their time reviewing a structured pack instead of reconstructing your environment from emails.
Share a trust profile showing PCI posture alongside your other certifications when customers ask.
Document firewall and router rules, remove vendor defaults, and evidence configuration standards for every in-scope system.
Record data flows, retention and disposal, encryption and key management, and TLS across public networks.
Anti-malware coverage, patching SLAs, secure coding, change control and payment-page script integrity.
Least-privilege role assignments, unique IDs, MFA for all CDE access, and periodic access reviews with evidence.
Site controls, media handling, device inventories and tamper inspection records for card-present terminals.
Audit trail coverage, time synchronisation, daily log review, and retention aligned to the standard.
Vulnerability scans, ASV scans, penetration testing schedule and remediation tracking through to closure.
Information security policy set, targeted risk analyses, awareness training, incident response and third-party service provider management.
Pain: Payments are outsourced, but the acquirer still wants an annual questionnaire and evidence that payment scripts are controlled.
With ISO-STANDARD.app: A recorded scope, script-integrity evidence and a completed SAQ pack you can reproduce next year in an afternoon.
Pain: Customers push PCI obligations down the contract chain while you are already maintaining ISO 27001 and SOC 2.
With ISO-STANDARD.app: One cross-mapped control set covering all three, with a RoC-ready evidence pack for the QSA.
Pain: Device inventories, tamper checks and physical access records live on paper across multiple sites.
With ISO-STANDARD.app: Digital asset register, scheduled inspection tasks and photographic evidence attached to each device.
Pain: Each engagement starts by rebuilding the same scoping and evidence structure from scratch.
With ISO-STANDARD.app: Isolated client workspaces, reusable PCI templates and portfolio-level visibility of remediation progress.
| Capability | ISO-STANDARD.app | Spreadsheets | Legacy GRC |
|---|---|---|---|
| PCI DSS v4.0.1 requirement library | |||
| Cardholder data flow and scope register | Manual | ||
| Targeted risk analyses built in | Sometimes | ||
| Cross-mapping to ISO 27001 / SOC 2 / GDPR | |||
| Scan and remediation tracking | Manual | ||
| SAQ and RoC evidence export | |||
| Setup measured in hours, not months | |||
| Transparent SME pricing |
Map card data flows and record every system, process and third party inside the cardholder data environment.
Check your merchant level with your acquirer and confirm whether an SAQ or a QSA-led RoC applies.
Apply the v4.0.1 requirement library, reusing existing ISO 27001 or SOC 2 controls wherever they already satisfy it.
Run access reviews, scans and log reviews on schedule, with evidence filed against each requirement automatically.
Close remaining gaps, complete the SAQ or work through the RoC with your QSA, and submit the attestation.
PCI compliance means meeting the Payment Card Industry Data Security Standard (PCI DSS), the security standard that applies to any organisation that stores, processes or transmits cardholder data. Compliance is demonstrated annually through a Self-Assessment Questionnaire (SAQ) or, for larger merchants, a Report on Compliance (RoC) signed off by a QSA.
Any merchant or service provider that handles payment card data, regardless of size. Your acquiring bank or payment provider sets your merchant level and tells you whether you complete an SAQ or a RoC. Even fully outsourced e-commerce merchants normally complete SAQ A.
It depends on how you take payments. SAQ A covers fully outsourced e-commerce, SAQ A-EP covers websites that redirect but influence the payment page, SAQ B and B-IP cover terminals, SAQ C covers payment applications connected to the internet, and SAQ D covers everything else including service providers. The platform helps you record your scope and pick the right questionnaire.
Version 4 introduced the customised approach, expanded authentication requirements including MFA for all access to the cardholder data environment, targeted risk analyses for several requirements, and stronger scripting and phishing controls. Future-dated requirements became mandatory on 31 March 2025.
No, and it should not. If you need a QSA-signed RoC or an attestation, an assessor must perform the assessment. The platform prepares the evidence, control mappings and documentation your QSA asks for, which is where most of the cost and delay usually sits.
Yes. Many PCI DSS requirements overlap with ISO 27001 Annex A and SOC 2 criteria — access control, logging, vulnerability management, change control and incident response. Controls in the platform are cross-mapped, so one implementation satisfies several frameworks at once.
Scope reduction means keeping cardholder data out of your systems: use hosted payment pages or iframes, tokenise, segment networks that must handle card data, and remove legacy storage. Less scope means a shorter SAQ and a cheaper assessment.
Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.
AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.
Prompts routed via the Lovable AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.
Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.
We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.
I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.