Your security lead is three weeks from a PCI audit. A vendor just turned up in scope that nobody tracked all year. The network diagram is eight months old and three infrastructure changes behind. The Verizon 2024 Payment Security Report found that only 14% of organisations maintain full PCI DSS compliance at any point in time. The other 86% carry gaps that cost them in fines, failed audits, and suspended card-processing accounts. This checklist tells you exactly what PCI DSS v4.0.1 requires, what your auditor needs to see, and where Indian BFSI and fintech teams get caught out. Start with CyRAACS’s GRC and compliance readiness services before your next validation window opens.
A PCI DSS compliance checklist covers the 12 core PCI DSS requirements that any organisation storing, processing, or transmitting payment card data must meet. PCI DSS v4.0.1 is the only active standard in 2026. Controls must be proven through continuous, documented evidence throughout the year, not captured once in a policy document before an audit.
Key Takeaways
- PCI DSS compliance is mandatory for every Indian organisation handling card payments. PCI SSC enforces it through your acquiring bank. The RBI Master Direction on Cyber Resilience (30 July 2024) adds a second independent obligation for non-bank payment operators.
- PCI DSS v4.0.1 introduced 64 new or updated requirements versus v3.2.1. Thirteen became mandatory in April 2024. The remaining 51 became mandatory on 31 March 2025. Any assessment in 2026 must reflect all 64.
- This PCI DSS compliance checklist covers 12 requirements across six control objectives: network security, data protection, vulnerability management, access control, monitoring, and security policy. Every one applies unless your SAQ type specifically excludes it.
- Scoping your Cardholder Data Environment (CDE), the boundary of all systems that store, process, or touch card data, is the first step in how to implement PCI DSS compliance. Every control you build after that is only as reliable as your scope.
- Selecting the wrong SAQ (Self-Assessment Questionnaire) type is the most expensive and most avoidable compliance mistake Indian fintech and BFSI teams make. One conversation with your acquiring bank before you start prevents it.
Who Needs PCI DSS Compliance?
Who needs PCI DSS compliance is straightforward: if your systems store, process, or transmit payment card data in any form, you are in scope. That includes:
- Merchants accepting card payments online or in-store
- Payment aggregators and fintech platforms
- NBFCs processing card transactions
- Third-party service providers whose systems can affect cardholder data security, even without directly handling card numbers
Do I need PCI DSS compliance if payments run through a gateway? Yes. Your checkout page, your integration, and any script loading on that page still put you in scope.
In India, two obligations apply independently:
| Obligation | Enforced By | Applies To |
| PCI DSS compliance | PCI SSC via your acquiring bank | All entities handling card data |
| RBI Master Direction on Cyber Resilience (30 July 2024) | Reserve Bank of India | Non-bank Payment System Operators including aggregators and gateways |
Both apply at the same time. Meeting one does not satisfy the other.
Your compliance level sets how you validate each year and what it costs:
| Level | Annual Card Transactions | Validation Method | Approx. India Cost |
| Level 1 | Over 6 million | On-site QSA audit plus Report on Compliance | ₹10 lakh to ₹30 lakh |
| Level 2 | 1 million to 6 million | Annual SAQ plus quarterly ASV scans | ₹3 lakh to ₹8 lakh |
| Level 3 | 20,000 to 1 million (e-commerce) | SAQ plus quarterly ASV scans | ₹1 lakh to ₹5 lakh |
| Level 4 | Under 20,000 (e-commerce) | SAQ recommended | ₹50,000 to ₹3 lakh |
India cost estimates per IncorpX India PCI DSS Compliance Guide, 2026. Costs vary by scope and assessor.
What Does the PCI DSS Compliance Checklist Cover Across All 12 Requirements?
The PCI DSS compliance checklist maps 12 requirements to six control objectives. The evidence column is what most teams underestimate. Documenting a control is not the same as proving it works. Your assessor wants to see operational records, not a written policy.
| Req. | Control Objective | What to Implement | Evidence Your Auditor Needs | Key v4.0.1 Change |
| 1 | Network Security | Firewall and network security controls restricting all CDE traffic | Network diagrams, rule review records every 6 months | Controls are now technology-neutral, not firewall-specific |
| 2 | Network Security | Remove all vendor-supplied defaults before any system goes live | Hardening standards, system inventory with assigned owners | Targeted Risk Analysis (TRA) now required per system component |
| 3 | Data Protection | Encrypt or tokenise all stored cardholder data | Data retention policy, encryption key management records | Disk-level encryption alone no longer satisfies this requirement |
| 4 | Data Protection | Encrypt card data in transit over public networks | TLS configuration evidence, certificate records | TLS 1.2 minimum; TLS 1.3 strongly recommended |
| 5 | Vulnerability Management | Anti-malware on all in-scope systems | Scan logs, update frequency records | Anti-phishing controls now explicitly required |
| 6 | Vulnerability Management | Secure development practices plus payment page script inventory | Change control records, authorised script inventory | Req. 6.4.3: every payment page script must be authorised and integrity-checked (SAQ A-EP and SAQ D only) |
| 7 | Access Control | Role-based access to the CDE by business need only | Access matrix, documented review schedule | Formal access review frequency must now be documented |
| 8 | Access Control | MFA for all CDE access, unique IDs per user | MFA configuration evidence, user account audit | MFA now required for all CDE access, not admin accounts only |
| 9 | Access Control | Physical access controls on all CDE hardware | Visitor logs, media destruction records, chain of custody | Physical media tracking requires a documented chain of custody |
| 10 | Monitoring | Log all access to CDE systems and card data | Log retention records, 12 months minimum, plus review evidence | Automated log review permitted; the mechanism must be documented |
| 11 | Testing | Quarterly internal and external scans plus annual penetration test | ASV scan reports, pen test report, segmentation test evidence | Req. 11.6.1: HTTP header and payment page tamper detection mandatory for SAQ A-EP and SAQ D merchants |
| 12 | Security Policy | Documented information security policy covering all personnel | Signed policy acknowledgements, annual review records | TRA documents required per control frequency decision |
Which SAQ Mistake Is Costing Indian Teams the Most?
Indian fintech and e-commerce merchants lose more audit time and money to wrong SAQ selection than to any technical control gap.
Raksha runs payments for a mid-size D2C brand. A gateway handles checkout. She files SAQ A, around 30 questions, because the payment page is outsourced. The QSA visits. Google Tag Manager is firing on the checkout URL. A live chat widget loads from the brand’s own domain. Neither was flagged internally. SAQ A no longer applies. She needed SAQ A-EP, which runs to roughly 190 questions. The reassessment adds four more, and, per the IncorpX India PCI DSS Compliance Guide 2026, wrong selections can cost Indian merchants up to ₹5 lakh in unnecessary audit work. This is how the SAQ types map to your architecture:
| SAQ Type | Who It Applies To | Questions | The Trap |
| SAQ A | Fully outsourced card-not-present payments, no scripts from your domain on checkout | ~30 | Any JS from your domain on the payment page disqualifies you |
| SAQ A-EP | E-commerce with third-party payment page but your domain scripts load on checkout | ~190 | GTM, analytics tags, or chat widgets on checkout trigger this |
| SAQ B | Card-present only, standalone terminals, no electronic card data storage | ~45 | Terminals on your network move you to SAQ C |
| SAQ C | Payment apps connected to the internet, no card data stored | ~160 | Legacy POS systems with network connectivity fall here |
| SAQ D | All merchants storing, processing, or transmitting card data directly | ~350 | Partial outsourcing does not reduce your scope to SAQ A |
Confirm your SAQ type with your acquiring bank and payment gateway before you start. Review your PCI DSS certification readiness approach before filing anything with your assessor.
How Do You Check and Maintain PCI DSS Compliance All Year?
How to check PCI DSS compliance is a year-round discipline, not a pre-audit sprint. These actions keep your controls evidenced and your assessor satisfied across all 12 months:
- Run internal vulnerability scans on all in-scope systems every quarter
- Commission quarterly external scans through a PCI SSC-Approved Scanning Vendor (ASV); CyRAACS provides VAPT and security assessment services aligned to these requirements
- Complete your annual SAQ or commission a Qualified Security Assessor (QSA) for Level 1 validation
- Conduct annual penetration testing covering the CDE perimeter and all internal network segmentation
- Test segmentation controls every six months and after any infrastructure change
- Verify every third-party service provider’s PCI DSS compliance status annually and keep the records
- File your Attestation of Compliance (AOC), the formal sign-off confirming your assessment results, with your acquiring bank before your validation deadline
What Should PCI DSS Compliance Software Do for Your Team?
PCI DSS compliance software provides your team with continuous, real-time visibility into all 12 requirements, so your auditor never waits for evidence to be compiled. The right platform tracks live control status, not just stores documents.
| Feature | What It Automates | Why It Matters for Indian BFSI Teams |
| Unified control mapping | Maps one control to PCI DSS compliance, RBI, and ISO 27001 simultaneously | Removes the need to run three separate audit programmes in parallel |
| Continuous evidence collection | Pulls scan results, access logs, and policy acknowledgements automatically | Closes the gap between quarterly scans and annual audit submission |
| TRA documentation | Generates Targeted Risk Analysis records per control frequency | Req. 12 now mandates this; manual spreadsheet tracking fails at scale |
| Third-party vendor tracking | Monitors vendor compliance status with automated renewal alerts | RBI mandates annual vendor PCI DSS compliance verification |
| Audit-ready dashboards | Shows real-time compliance posture across all 12 requirements | QSAs and internal auditors review live evidence without waiting for reports |
CyRAACS: PCI DSS Compliance Consulting for Indian BFSI and Fintech
CyRAACS is a CERT-In-empaneled cybersecurity consulting firm. Over 750 client engagements across BFSI, fintech, and IT/ITES. Offices in Bengaluru, Mumbai, and Dubai. Clients include leading banks and small finance banks, among others. The team holds CISSP, CISA, and CISM certifications. It covers every stage of PCI DSS compliance: CDE scoping, gap assessment, technical controls, and continuous monitoring through COMPASS. Ready to close your compliance gaps before your next assessment window? Talk to the CyRAACS team.
Conclusion
Scope is where most PCI DSS compliance programs quietly go wrong. Teams document the controls, file the SAQ, and think the job is done. Then a vendor gets added mid-year, and nobody updates the CDE boundary. Which part of your current programme would not survive a QSA asking to see twelve months of live evidence tomorrow?
Explore CyRAACS’s COMPASS compliance management platform before your next validation window opens.
Start Your PCI DSS Compliance Assessment Today
CyRAACS delivers structured PCI DSS compliance readiness assessments for Indian BFSI and fintech organisations. Every requirement covered. Every control evidenced. Contact CyRAACS to book your assessment.
Frequently Asked Questions
Who needs PCI DSS compliance in India?
Who needs PCI DSS compliance in India includes every merchant, payment aggregator, fintech platform, and third-party service provider that handles card payment data. The RBI Master Direction on Cyber Resilience (July 2024) adds a direct regulatory obligation for non-bank Payment System Operators, separate from the PCI SSC contractual requirement your acquiring bank enforces. Both apply at the same time.
What does PCI DSS compliance software do?
PCI DSS compliance software tracks live evidence across all 12 requirements, automates log review, monitors third-party vendor status, and generates Targeted Risk Analysis documentation your assessor needs on the day. Platforms like COMPASS by CyRAACS go further by mapping PCI DSS controls alongside RBI and ISO 27001 in one place, so your team runs one programme instead of three.
How long does it take to implement PCI DSS compliance?
How to implement PCI DSS compliance from a standing start takes four to eight weeks for a Level 4 merchant with a clean scope. A Level 1 enterprise with significant gaps typically needs six to twelve months. The timeline is almost entirely determined by how well-scoped the Cardholder Data Environment is on day one.
What changed in PCI DSS v4.0.1 compared to v3.2.1?
PCI DSS compliance under v4.0.1 now covers 64 new or updated requirements versus v3.2.1. Thirteen became mandatory in April 2024. The remaining 51 became mandatory on 31 March 2025. The biggest operational shifts are: MFA required for all CDE access (not just admin accounts); client-side script monitoring per Requirements 6.4.3 and 11.6.1; Targeted Risk Analysis documentation per control frequency; and formal annual CDE rescoping. Every 2026 assessment must reflect all 64 changes.
What are the fines for failing PCI DSS compliance?
Monthly penalties start at $5,000 to $10,000 for the first three months. By months four to six, they rise to $25,000 to $50,000. Beyond six months, fines reach $100,000 per month, per industry data from Scrut.io (2025). Your acquiring bank can also suspend card-processing privileges until compliance is restored. If your program has gaps today, CyRAACS can assess and close them before a regulator does.




