Built for PCI DSS v4.0.1

PCI compliance without the annual scramble.

Scope your cardholder data environment, map all 12 PCI DSS requirements to real controls, keep evidence current all year, and walk into your SAQ or QSA assessment with the pack already built.

12
requirements mapped to controls
v4.0.1
current standard, future-dated items included
SAQ + RoC
evidence packs for either route
Cross-mapped
shared with ISO 27001 and SOC 2

PCI compliance is rarely hard because the requirements are obscure. It is hard because the evidence is scattered: scan reports in one inbox, access reviews in a spreadsheet, policies in a shared drive, and a scope diagram nobody has updated since the last payment integration changed.

ISO-STANDARD.app gives you PCI DSS compliance software that keeps scope, controls and evidence together throughout the year, and reuses everything you have already done for ISO 27001 or SOC 2 instead of starting again.

Features

What the PCI compliance workspace gives you

Scope and data-flow register

Record how card data enters, moves and leaves the business, which systems sit in the CDE, and which third parties share responsibility.

PCI DSS v4.0.1 requirement library

All 12 requirements broken down into testable sub-requirements, each linked to a control, an owner and its supporting evidence.

Targeted risk analyses

Version 4 requires documented risk analyses for several controls. Run them in the risk register with a defensible, repeatable method.

SAQ and RoC evidence packs

Export the documentation set your acquirer or QSA asks for, with everything timestamped and attributable.

Scan and remediation tracking

Track ASV scans, internal vulnerability scans and penetration test findings through to verified closure, with due dates that do not slip quietly.

Access reviews and log review records

Scheduled access reviews, MFA coverage over the CDE, and evidence that daily log review actually happened.

Benefits

Why teams move PCI off spreadsheets

Smaller scope, cheaper assessment

Documented data flows make it obvious where card data can be removed, tokenised or segmented out — the single biggest lever on PCI cost.

No annual evidence hunt

Scans, reviews and approvals are captured as they happen, so validation is an export rather than a month of chasing.

Reuse ISO 27001 and SOC 2 work

Cross-mapped controls mean access control, logging and vulnerability management count once across every framework.

Clear ownership

Every requirement has a named owner and a due date, so nothing depends on one person remembering.

Fewer QSA hours

Assessors spend their time reviewing a structured pack instead of reconstructing your environment from emails.

Evidence buyers trust

Share a trust profile showing PCI posture alongside your other certifications when customers ask.

The standard

The 12 PCI DSS requirements, mapped to controls

1–2

Network security controls & secure configuration

Document firewall and router rules, remove vendor defaults, and evidence configuration standards for every in-scope system.

3–4

Protect stored and transmitted account data

Record data flows, retention and disposal, encryption and key management, and TLS across public networks.

5–6

Malware protection & secure development

Anti-malware coverage, patching SLAs, secure coding, change control and payment-page script integrity.

7–8

Access control & authentication

Least-privilege role assignments, unique IDs, MFA for all CDE access, and periodic access reviews with evidence.

9

Physical access

Site controls, media handling, device inventories and tamper inspection records for card-present terminals.

10

Logging and monitoring

Audit trail coverage, time synchronisation, daily log review, and retention aligned to the standard.

11

Testing security of systems

Vulnerability scans, ASV scans, penetration testing schedule and remediation tracking through to closure.

12

Policies and programme governance

Information security policy set, targeted risk analyses, awareness training, incident response and third-party service provider management.

Use cases

Whatever your validation route

E-commerce merchants (SAQ A / A-EP)

Pain: Payments are outsourced, but the acquirer still wants an annual questionnaire and evidence that payment scripts are controlled.

With ISO-STANDARD.app: A recorded scope, script-integrity evidence and a completed SAQ pack you can reproduce next year in an afternoon.

SaaS and service providers (SAQ D / RoC)

Pain: Customers push PCI obligations down the contract chain while you are already maintaining ISO 27001 and SOC 2.

With ISO-STANDARD.app: One cross-mapped control set covering all three, with a RoC-ready evidence pack for the QSA.

Retail and hospitality with terminals

Pain: Device inventories, tamper checks and physical access records live on paper across multiple sites.

With ISO-STANDARD.app: Digital asset register, scheduled inspection tasks and photographic evidence attached to each device.

Consultants and QSAs supporting clients

Pain: Each engagement starts by rebuilding the same scoping and evidence structure from scratch.

With ISO-STANDARD.app: Isolated client workspaces, reusable PCI templates and portfolio-level visibility of remediation progress.

Comparison

Spreadsheets vs legacy GRC vs ISO-STANDARD.app

CapabilityISO-STANDARD.appSpreadsheetsLegacy GRC
PCI DSS v4.0.1 requirement library
Cardholder data flow and scope register Manual
Targeted risk analyses built in Sometimes
Cross-mapping to ISO 27001 / SOC 2 / GDPR
Scan and remediation tracking Manual
SAQ and RoC evidence export
Setup measured in hours, not months
Transparent SME pricing
Implementation

The path to PCI DSS validation

01

Define scope

Map card data flows and record every system, process and third party inside the cardholder data environment.

02

Confirm your route

Check your merchant level with your acquirer and confirm whether an SAQ or a QSA-led RoC applies.

03

Map requirements

Apply the v4.0.1 requirement library, reusing existing ISO 27001 or SOC 2 controls wherever they already satisfy it.

04

Collect evidence

Run access reviews, scans and log reviews on schedule, with evidence filed against each requirement automatically.

05

Validate and attest

Close remaining gaps, complete the SAQ or work through the RoC with your QSA, and submit the attestation.

FAQ

Common questions about PCI compliance

What is PCI compliance?+

PCI compliance means meeting the Payment Card Industry Data Security Standard (PCI DSS), the security standard that applies to any organisation that stores, processes or transmits cardholder data. Compliance is demonstrated annually through a Self-Assessment Questionnaire (SAQ) or, for larger merchants, a Report on Compliance (RoC) signed off by a QSA.

Who has to be PCI DSS compliant?+

Any merchant or service provider that handles payment card data, regardless of size. Your acquiring bank or payment provider sets your merchant level and tells you whether you complete an SAQ or a RoC. Even fully outsourced e-commerce merchants normally complete SAQ A.

Which SAQ applies to my business?+

It depends on how you take payments. SAQ A covers fully outsourced e-commerce, SAQ A-EP covers websites that redirect but influence the payment page, SAQ B and B-IP cover terminals, SAQ C covers payment applications connected to the internet, and SAQ D covers everything else including service providers. The platform helps you record your scope and pick the right questionnaire.

What changed in PCI DSS v4.0.1?+

Version 4 introduced the customised approach, expanded authentication requirements including MFA for all access to the cardholder data environment, targeted risk analyses for several requirements, and stronger scripting and phishing controls. Future-dated requirements became mandatory on 31 March 2025.

Can this replace a QSA?+

No, and it should not. If you need a QSA-signed RoC or an attestation, an assessor must perform the assessment. The platform prepares the evidence, control mappings and documentation your QSA asks for, which is where most of the cost and delay usually sits.

Does PCI DSS work alongside ISO 27001 and SOC 2?+

Yes. Many PCI DSS requirements overlap with ISO 27001 Annex A and SOC 2 criteria — access control, logging, vulnerability management, change control and incident response. Controls in the platform are cross-mapped, so one implementation satisfies several frameworks at once.

How do I reduce PCI scope?+

Scope reduction means keeping cardholder data out of your systems: use hosted payment pages or iframes, tokenise, segment networks that must handle card data, and remove legacy storage. Less scope means a shorter SAQ and a cheaper assessment.

Get PCI-ready and stay that way

Create a workspace, load the PCI DSS v4.0.1 requirement library and see exactly where your evidence gaps are before your next validation date.

AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the Lovable AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.

© 2026 ISO-STANDARD.app · Intelligent compliance software. Practical governance support. Human-led accountability.