Home › Frameworks › PCI DSS

PCI DSS compliance software for merchants and service providers.

The 12 PCI DSS v4 requirements as 35 recurring controls with evidence, scope and data-flow documents in Prepare for Audit, a quarterly ASV scan and annual penetration-test cadence. Included in Enterprise, €499 a month.

At a glance

  • Requirements 1-2: Network security: firewalls, secure configurations, segmentation of the cardholder data environment (CDE).
  • Requirements 3-4: Protect cardholder data: storage minimisation, encryption at rest and in transit.
  • Requirements 5-6: Vulnerability management: anti-malware, secure development, change control.
  • Requirements 7-9: Access control: need-to-know, unique IDs, MFA, physical access.

On this page

  1. What is PCI DSS?
  2. Who needs to comply
  3. Key PCI DSS controls covered by Dazr
  4. What auditors look for
  5. How Dazr helps with PCI DSS

What is PCI DSS?

PCI DSS v4.0 (Payment Card Industry Data Security Standard). Merchants, service providers, payment processors and any organisation that stores, processes or transmits cardholder data: e-commerce, payment platforms, fintech, hospitality, healthcare with on-site card payments.

Who needs to comply

  • E-commerce merchants accepting card payments online
  • SaaS platforms with embedded payment flows (often Level 4 or service-provider scope)
  • Payment service providers, ISVs, payment-facilitators
  • Hospitality and retail with on-site card terminals
  • Healthcare providers with on-site card payments

Key PCI DSS controls covered by Dazr

Requirements 1-2Network security: firewalls, secure configurations, segmentation of the cardholder data environment (CDE).
Requirements 3-4Protect cardholder data: storage minimisation, encryption at rest and in transit.
Requirements 5-6Vulnerability management: anti-malware, secure development, change control.
Requirements 7-9Access control: need-to-know, unique IDs, MFA, physical access.
Requirements 10-11Monitoring and testing: logging and monitoring, ASV scans (quarterly), internal vulnerability scans, penetration tests (annual), file-integrity monitoring.
Requirement 12Information-security policy, risk assessment, incident response, third-party management, awareness training.

What auditors look for

PCI DSS assessors sample evidence across the 12 requirements over the audit period: quarterly ASV scans actually ran, annual penetration tests happened, segmentation is provably effective, access reviews were performed, change management was followed. Dazr is the system of record.

How Dazr helps with PCI DSS

Dazr Compliance is an EU-hosted compliance management platform (GRC software) for European organisations of every size, from a five-person team to the enterprise. PCI DSS is one of its eleven frameworks, included in Enterprise, €499 a month. In practice that means:

  • Keep the CDE scope and data-flow diagram current, with CDE systems in the asset inventory
  • Track quarterly ASV scans and annual penetration tests as recurring controls with vendor evidence
  • Keep third-party service providers in the vendor register, with the responsibility matrix linked as evidence
  • Run access reviews on cadence with the role and CDE-component scope
  • Hand the QSA a read-only view for the RoC sampling, or a single-PDF audit trail

Back to the full Dazr Compliance overview › | Sign up free ›

PCI DSS questions, answered.

Does Dazr replace our QSA?

No. The Report on Compliance (RoC) or the Self-Assessment Questionnaire (SAQ) is signed off by your QSA or your own internal team. Dazr is the system of record they sample from.

Do you support the v4.0 customised approach?

Partly. There is no separate customised-approach workflow: you record the approach per requirement in the control evidence and link the targeted risk analysis there.

What about ASV scans and pen tests?

Dazr tracks the cadence (quarterly external scans, annual penetration tests, change-driven scans) and links to the actual scan reports. The scans themselves are run by your ASV / pen-test vendor.

Where is data hosted?

European Union only. Workspace records are encrypted at rest with AES-256-GCM at the application layer; uploaded evidence files rely on the storage provider's at-rest encryption. Italian entity, EU jurisdiction. Note: Dazr does not store cardholder data; we hold compliance evidence about your CDE.

Ready to start your PCI DSS program?

PCI DSS is included in Enterprise (€499/mo, self-serve via Mollie, excl. VAT, cancel any time). Free and Basic cover ISO 27001, GDPR and NIS2; Pro adds NEN 7510, ISO 27701, ISO 22301 and SOC 2. Custom is the only tier on a contract, priced on request.