PCI DSS v4.0.1 Readiness

PCI DSS Compliance Consultants Who Get You Ready for the Assessor

Every PCI DSS requirement has been mandatory since March 31, 2025, including the 51 that were best practice until then. Most mid-market merchants and service providers have not caught up on the new ones: payment page script controls, MFA into the cardholder data environment, and targeted risk analyses.

Cloudskope maps where your card data actually lives, finds the gaps against v4.0.1, fixes what can be fixed, runs the testing the standard requires, and hands your assessor an evidence package that holds up. When a Report on Compliance is required, an independent Qualified Security Assessor performs the assessment. We get you ready for it.

Need a PCI pen test? Estimate your cost with our calculator →

v4.0.1
Standard Assessed
51
New Requirements Now Mandatory
<30min
Scoping Call
Enterprise Hero Icon
Independent by Design
Assessor Kept Separate
Enterprise Hero Icon
Scope Reduction
Segmentation Tested
Enterprise Hero Icon
Manual PCI Testing
Requirement 11.4
Enterprise Hero Icon
Remediation Support
Available

Where PCI Programs Fail Under Assessment

Most PCI findings are not exotic.

They come from scope nobody mapped, controls nobody rechecked after v4.0, and evidence nobody can produce on the day of fieldwork.

Enterprise Hero Icon
CRITICAL

Scope That Is Bigger Than You Think

Challenges Highlight  Icon
Scope decides your SAQ, your cost and your risk.
Enterprise Hero Icon

Card data turns up in support tools, call recordings, logs and old integrations. We trace where it actually flows, so your SAQ type and assessment scope match reality.

Enterprise Hero Icon
High

Flat Networks

Challenges Highlight  Icon
Segmentation is the biggest lever on assessment cost.
Enterprise Hero Icon

Without tested segmentation, every connected system is in scope. We confirm what separates the cardholder data environment from everything else, and we test it.

Enterprise Hero Icon
CRITICAL

Payment Page Scripts

Challenges Highlight  Icon
Requirements 6.4.3 and 11.6.1, mandatory since March 31, 2025.
Enterprise Hero Icon

Attackers skim cards by changing the scripts on checkout pages. v4.0.1 expects an inventory of every script on the payment pages you control, a reason for each, and detection of unauthorized changes.

Enterprise Hero Icon
CRITICAL

MFA Gaps Into the Cardholder Environment

Challenges Highlight  Icon
Requirement 8.4.2: MFA for all access into the CDE.
Enterprise Hero Icon

MFA at the VPN is no longer enough. Access into the cardholder data environment needs it everywhere, including admin consoles and cloud tenants such as Microsoft 365 and Azure.

Enterprise Hero Icon
High

Missing Targeted Risk Analyses

Challenges Highlight  Icon
v4.0.1 asks you to justify how often you do things.
Enterprise Hero Icon

Where the standard lets you set a control's frequency, you need a documented targeted risk analysis behind it. Assessors ask for them, and many programs have none.

Enterprise Hero Icon
High

Evidence That Does Not Exist

Challenges Highlight  Icon
A control you cannot prove is a control not in place.
Enterprise Hero Icon

Logs, review records, training completion, scan results, change approvals. We build the evidence trail before fieldwork, so the assessment measures your controls, not your filing.

What Our PCI DSS Consulting Covers

One team from scoping to sign-off: consulting, audit preparation, testing and ongoing compliance.
The goal is not a longer gap list. It is a smaller scope, fewer findings, and an assessment you pass on the evidence.

Services Icon

Scoping & Segmentation Review

Find every place card data lives, then shrink it.

What we assess

Card data flows across every payment channel, tokenization and outsourced processors, connected systems, and network segmentation.

why it matters

Scope drives your SAQ type, your assessment cost and your breach exposure. Most scope reductions pay for the engagement.

typical outputs
Service Feature Icon

Cardholder Data Flow Diagram

Service Feature Icon

Scope Inventory

Service Feature Icon

Segmentation Findings

Service Feature Icon

Scope Reduction Options

Services Icon

PCI DSS v4.0.1 Gap Assessment

Every applicable requirement, checked against evidence.

What we assess

All 12 requirements at your validation level, the 51 requirements that became mandatory in 2025, compensating controls, and the policies and procedures behind them.

why it matters

Gaps you find cost less than gaps your assessor finds.

typical outputs
Service Feature Icon

Requirement-by-Requirement Gap Register

Service Feature Icon

Severity and Effort Ranking

Service Feature Icon

Compensating Control Review

Service Feature Icon

Remediation Roadmap

Services Icon

SAQ Selection & Completion Support

The right questionnaire, answered with proof.

What we assess

Payment channels, processor setups, eligibility for each SAQ type, and the Attestation of Compliance your officer will sign.

why it matters

The wrong SAQ either overstates your burden or understates your risk, and the executive who signs the attestation owns every answer.

TYPICAL OUTPUTS
Service Feature Icon

SAQ Determination Memo

Service Feature Icon

Evidence for Each Answer

Service Feature Icon

Attestation of Compliance Draft

Service Feature Icon

Acquirer-Ready Package

Services Icon

PCI Audit Preparation

Arrive at fieldwork ready.

What we assess

Evidence completeness for each requirement, documentation, prior findings, and how ready your control owners are for assessor interviews.

why it matters

Fixing gaps before fieldwork costs less than fixing them under a deadline, and it keeps assessor hours down. Your QSA performs the assessment and issues the Report on Compliance; we stay with you through it.

TYPICAL OUTPUTS
Service Feature Icon

Evidence Package Mapped to Requirements

Service Feature Icon

Control Owner Preparation

Service Feature Icon

Mock Assessment Walkthrough

Service Feature Icon

Open-Item Tracker for Fieldwork

Services Icon

PCI Penetration Testing

The testing the standard requires, done by hand.

What we assess

External and internal penetration tests under Requirement 11.4, segmentation testing, application testing of payment flows, and retesting after fixes.

why it matters

v4.0.1 requires annual internal and external penetration testing, plus segmentation testing where segmentation reduces scope. A vulnerability scan does not satisfy it.

typical outputs
Service Feature Icon

External and Internal Findings

Service Feature Icon

Segmentation Test Results

Service Feature Icon

Attack Path Narrative

Service Feature Icon

Retest Confirmation

Services Icon

Remediation & Ongoing Compliance

Fix the gaps and keep them closed.

What we assess

Remediation sequencing, MFA and logging fixes, Microsoft 365 and Azure controls, quarterly obligations, and the annual scope confirmation under Requirement 12.5.2.

why it matters

PCI is a year-round obligation. Most failures happen between assessments, not during them.

typical outputs
Service Feature Icon

Done-for-You Remediation

Service Feature Icon

Quarterly Compliance Calendar

Service Feature Icon

Fix Validation and Retest

Service Feature Icon

vCISO Oversight

Beyond the Checklist

Passing an assessment and being secure are not the same thing.

Target passed a PCI assessment in 2013, weeks before its breach. We work toward both.

Enterprise Hero Icon

Smaller Scope

Less to assess, less to protect, and a lower bill from your assessor.

Scope

Reduced Where Possible
Enterprise Hero Icon

Fewer Surprises in Fieldwork

Gaps are found and closed before the assessor arrives.

Findings

Closed Early
Enterprise Hero Icon

Proof Behind Every Answer

Every response is backed by evidence the signing officer can stand behind.

Evidence

Mapped to Requirements
Enterprise Hero Icon

Controls That Stop Attackers

We test whether controls work against a real attacker, not only whether they exist on paper.

Controls

Tested by Hand
Subtitle Icon
Ready to Chat?

What Happens Next

Every engagement is scoped to your payment channels, validation level and deadline.

We find what matters, fix it, and keep it fixed.

A Simple Path From Scoping to Sign-Off

Enterprise Hero Icon

Discover

We map your payment channels and card data flows and confirm your validation level.

Scoping Call in <30min
Enterprise Hero Icon

Assess

We check every applicable requirement and run the testing v4.0.1 requires.

Every Requirement Checked
Enterprise Hero Icon

Remediate

We fix the gaps with your team and validate each fix.

Fixes Validated
Enterprise Hero Icon

Protect

Where needed, Cloudskope stays engaged through vCISO and managed detection.

Only What You Need
Subtitle Icon
FAQ

Frequently Asked Questions

Straight answers on scope, assessors, testing and what happens after the gap assessment.

1
What does a PCI DSS compliance consultant do?
2
Is Cloudskope a QSA? Can you issue our Report on Compliance?
3
Which version of PCI DSS are we assessed against?
4
Do we need a penetration test for PCI compliance?
5
We use Stripe, Square or another processor. Are we still in scope?
6
How long does a PCI consulting engagement take?
7
What does PCI consulting cost?
8
Is there such a thing as a PCI certificate?

Know Your Scope. Close the Gaps.
Walk Into the Assessment Ready.

If your PCI program has not been rechecked since v4.0, or your SAQ was chosen years ago and never revisited, start with scope.

It decides everything else.