PCI DSS checklist

The 12 PCI DSS 4.0 requirements a fintech actually walks.

The PCI DSS 4.0 requirements, the cardholder-data segmentation decisions, and the SAQ-vs-ROC determination that drives whether a fintech ships at the $20K Enterprise tier or below. The full 12-requirement walk-through, the segmentation attestation, and the QSA-ready evidence package are written up in the long-form checklist.

12 requirements · segmentation · SAQ vs. ROC

What “PCI DSS-ready” looks like

A working PCI DSS program at the Tier 3 Enterprise (multi-framework fintech) level covers the 12 requirements — from the network segmentation controls all the way to the quarterly vulnerability scans and the annual QSA-on-site — plus the ROC (Report on Compliance) the acquirer pulls on before the next funding round.

The full checklist — the 12 requirements, the custom approach vs. defined approach split, and the cardholder-data segmentation attestation — is being written up against the founder’s first reviewer round. For now, the hub at /resources indexes all four framework checklists; PCI DSS coverage ships only at the $20K Enterprise tier.

See pricing →

More frameworks

See all checklists →

HIPAA, SOC 2, PCI DSS, GDPR — pick by the framework your auditor opens on first.