What is PCI DSS?
PCI DSS v4.0 (Payment Card Industry Data Security Standard). Merchants, service providers, payment processors and any organisation that stores, processes or transmits cardholder data: e-commerce, payment platforms, fintech, hospitality, healthcare with on-site card payments.
Who needs to comply
- E-commerce merchants accepting card payments online
- SaaS platforms with embedded payment flows (often Level 4 or service-provider scope)
- Payment service providers, ISVs, payment-facilitators
- Hospitality and retail with on-site card terminals
- Healthcare providers with on-site card payments
Key PCI DSS controls covered by Dazr
What auditors look for
PCI DSS assessors sample evidence across the 12 requirements over the audit period: quarterly ASV scans actually ran, annual penetration tests happened, segmentation is provably effective, access reviews were performed, change management was followed. Dazr is the system of record.
How Dazr helps with PCI DSS
Dazr Compliance is an EU-hosted compliance management platform (GRC software) for European organisations of every size, from a five-person team to the enterprise. PCI DSS is one of its eleven frameworks, included in Enterprise, €499 a month. In practice that means:
- Keep the CDE scope and data-flow diagram current, with CDE systems in the asset inventory
- Track quarterly ASV scans and annual penetration tests as recurring controls with vendor evidence
- Keep third-party service providers in the vendor register, with the responsibility matrix linked as evidence
- Run access reviews on cadence with the role and CDE-component scope
- Hand the QSA a read-only view for the RoC sampling, or a single-PDF audit trail
Back to the full Dazr Compliance overview › | Sign up free ›