Skip to main content

Pro audit program · v1.0

PCI-DSS Quick Scope

Even if you are a SAQ-A merchant, a quick check of CHD scope, segmentation, vendor responsibilities and key PCI controls.

  • General target area
  • PCI-DSS v4 framework
  • 7 controls in this program
  • Cyentrix Cyentrix Trusted Author

About this program

Even if you are a SAQ-A merchant, a quick check of CHD scope, segmentation, vendor responsibilities and key PCI controls.

Risks addressed

  • Critical Cardholder data stored where you did not expect
  • Critical Untested segmentation makes the whole network in-scope
  • High Third-party payment page not validated PCI-compliant

Controls (7)

  1. Documented scope + data-flow diagram

    Critical

    This control requires the organization to maintain formal documentation defining the scope of systems, data, and business processes covered by its cybersecurity program, accompanied by data-flow diagrams that visually map how sensitive data moves between systems, networks, and external parties.…

    How to test + evidence

    Testing procedure: Current CHD flow diagram, dated within 12 months.

    Evidence to collect: CHD diagram.

  2. No storage of full PAN / SAD beyond what is allowed

    Critical

    This control prohibits the storage of full Primary Account Numbers (PAN), magnetic stripe data, CAV2/CVC2/CVV2 codes, and PINs beyond the timeframes explicitly permitted by PCI DSS (e.g., for authorization purposes only). Organizations must implement technical controls such as truncation, hashing,…

    How to test + evidence

    Testing procedure: Scan systems for PAN; track-2 / CVV never stored.

    Evidence to collect: Scan report.

  3. Segmentation tested annually

    High

    Network segmentation testing validates that logical and physical boundaries between security zones effectively prevent unauthorized lateral movement and data flow. Annual testing uses penetration testing, firewall rule audits, and traffic simulation to confirm that segmentation controls remain properly configured and…

    How to test + evidence

    Testing procedure: Segmentation pen-test confirms isolation from non-CDE.

    Evidence to collect: Pen-test report.

  4. Payment provider attestation on file

    High

    This control requires the organization to obtain and maintain current attestation reports (such as SOC 2 Type II, PCI DSS AOC, or ISO 27001 certificates) from third-party payment service providers that process, store, or transmit payment card data on behalf…

    How to test + evidence

    Testing procedure: AoC from PSP confirming their PCI compliance.

    Evidence to collect: AoC document.

  5. MFA on all CDE access

    Critical

    This control requires multi-factor authentication (MFA) for all users, systems, and processes accessing the Cardholder Data Environment (CDE), including interactive logins, administrative access, and privileged accounts. MFA combines something the user knows (password), something the user has (token, smart card,…

    How to test + evidence

    Testing procedure: MFA for all admin + remote access to CDE.

    Evidence to collect: MFA evidence.

  6. Critical patches within 30 days for CDE

    High

    This control requires all critical-severity patches and security updates to be applied to systems within the Cardholder Data Environment (CDE) within 30 calendar days of vendor release. Organizations must maintain a vulnerability management process that identifies, prioritizes, and tracks critical…

    How to test + evidence

    Testing procedure: Patch SLA met on every CDE system.

    Evidence to collect: Patch report.

  7. Quarterly external + internal scans

    High

    This control mandates authenticated vulnerability scanning of all in-scope systems at least once every calendar quarter, using both external scanners (simulating internet-facing threats) and internal scanners (detecting lateral movement risks). External scans target public IP ranges and externally accessible services,…

    How to test + evidence

    Testing procedure: ASV + internal vuln scans run quarterly with rescans on findings.

    Evidence to collect: Scan reports.