Now partnering with TechDefence to deliver stronger cyber security outcomes — Learn more

Cyber News
All news →
Compliance · PCI DSS

PCI DSS readiness and penetration testing

PCI DSS is the global security standard for protecting payment card data, maintained by the PCI Security Standards Council. It applies to any organisation that stores, processes or transmits cardholder data, or can affect its security.

Overview

In plain English

Version 4 introduced new requirements, many of which were future-dated and became effective on 31 March 2025. Good scoping — keeping card data in as few systems as possible — reduces cost and effort.

Instruments covered

  • Payment Card Industry Data Security Standard (PCI DSS) v4.0.1

Last reviewed:

Key requirements

What PCI DSS expects

  1. Scoping

    Identify every system that stores, processes or transmits cardholder data, or connects to those systems.

  2. Network security controls

    Segment and protect the cardholder data environment.

  3. Protect stored account data

    Minimise storage and protect stored data with strong cryptography.

  4. Vulnerability management

    Keep systems patched, protect against malware and develop software securely.

  5. Access control

    Restrict access by business need, identify users and use multi-factor authentication.

  6. Logging and monitoring

    Log and monitor all access to system components and cardholder data.

  7. Regular testing

    Perform vulnerability scans and penetration testing, including segmentation testing.

  8. Policies and programmes

    Maintain an information security policy and a security awareness programme.

How TrustNet helps

From gap to evidence

  • Scoping and data-flow mapping
  • Gap assessment against PCI DSS v4.x
  • Penetration testing and segmentation testing
  • Remediation guidance and retesting

Aligned with, not endorsed by any regulator. This page is a plain-English summary for awareness — confirm obligations against the latest official circulars or with your compliance officer.

Services mapped to PCI DSS

FAQ

PCI DSS FAQ

Are you a QSA?

We help with readiness, testing and remediation. Formal assessments that need a Qualified Security Assessor are done by a QSA; we will say clearly who signs what.

What changed in PCI DSS v4?

Version 4 added and updated requirements, including stronger authentication and targeted risk analyses. Future-dated requirements became effective on 31 March 2025.

How can we reduce PCI scope?

Tokenisation, hosted payment pages and network segmentation can reduce the systems in scope. We help you design for less scope.

Book a consultation

Get PCI DSS-ready

We assess where you stand, close the gaps and prepare the evidence your auditors and regulator will ask for.

support@trustnetsecure.com · +91 93229 37312 · +91 88300 61438

Under attack right now? Go to emergency help →

Today in Cyber

What's happening in cyber security

See all news →

Source: The Hacker News — headlines only, each linking to the original article.

Chat with us