Build your future with us.

Enable continuous compliance with a unified, intelligent platform

Let's Discuss

The Ultimate PCI DSS Compliance Checklist for 2026

Your security lead is three weeks from a PCI audit. A vendor just turned up in scope that nobody tracked all year. The network diagram is eight months old and three infrastructure changes behind. The Verizon 2024 Payment Security Report found that only 14% of organisations maintain full PCI DSS compliance at any point in time. The other 86% carry gaps that cost them in fines, failed audits, and suspended card-processing accounts. This checklist tells you exactly what PCI DSS v4.0.1 requires, what your auditor needs to see, and where Indian BFSI and fintech teams get caught out. Start with CyRAACS’s GRC and compliance readiness services before your next validation window opens.

A PCI DSS compliance checklist covers the 12 core PCI DSS requirements that any organisation storing, processing, or transmitting payment card data must meet. PCI DSS v4.0.1 is the only active standard in 2026. Controls must be proven through continuous, documented evidence throughout the year, not captured once in a policy document before an audit.

Key Takeaways

  • PCI DSS compliance is mandatory for every Indian organisation handling card payments. PCI SSC enforces it through your acquiring bank. The RBI Master Direction on Cyber Resilience (30 July 2024) adds a second independent obligation for non-bank payment operators.
  • PCI DSS v4.0.1 introduced 64 new or updated requirements versus v3.2.1. Thirteen became mandatory in April 2024. The remaining 51 became mandatory on 31 March 2025. Any assessment in 2026 must reflect all 64.
  • This PCI DSS compliance checklist covers 12 requirements across six control objectives: network security, data protection, vulnerability management, access control, monitoring, and security policy. Every one applies unless your SAQ type specifically excludes it.
  • Scoping your Cardholder Data Environment (CDE), the boundary of all systems that store, process, or touch card data, is the first step in how to implement PCI DSS compliance. Every control you build after that is only as reliable as your scope.
  • Selecting the wrong SAQ (Self-Assessment Questionnaire) type is the most expensive and most avoidable compliance mistake Indian fintech and BFSI teams make. One conversation with your acquiring bank before you start prevents it.

Who Needs PCI DSS Compliance?

Who needs PCI DSS compliance is straightforward: if your systems store, process, or transmit payment card data in any form, you are in scope. That includes:

  • Merchants accepting card payments online or in-store
  • Payment aggregators and fintech platforms
  • NBFCs processing card transactions
  • Third-party service providers whose systems can affect cardholder data security, even without directly handling card numbers

Do I need PCI DSS compliance if payments run through a gateway? Yes. Your checkout page, your integration, and any script loading on that page still put you in scope.

In India, two obligations apply independently:

ObligationEnforced ByApplies To
PCI DSS compliancePCI SSC via your acquiring bankAll entities handling card data
RBI Master Direction on Cyber Resilience (30 July 2024)Reserve Bank of IndiaNon-bank Payment System Operators including aggregators and gateways

Both apply at the same time. Meeting one does not satisfy the other.

Your compliance level sets how you validate each year and what it costs:

LevelAnnual Card TransactionsValidation MethodApprox. India Cost
Level 1Over 6 millionOn-site QSA audit plus Report on Compliance₹10 lakh to ₹30 lakh
Level 21 million to 6 millionAnnual SAQ plus quarterly ASV scans₹3 lakh to ₹8 lakh
Level 320,000 to 1 million (e-commerce)SAQ plus quarterly ASV scans₹1 lakh to ₹5 lakh
Level 4Under 20,000 (e-commerce)SAQ recommended₹50,000 to ₹3 lakh

India cost estimates per IncorpX India PCI DSS Compliance Guide, 2026. Costs vary by scope and assessor.

What Does the PCI DSS Compliance Checklist Cover Across All 12 Requirements?

The PCI DSS compliance checklist maps 12 requirements to six control objectives. The evidence column is what most teams underestimate. Documenting a control is not the same as proving it works. Your assessor wants to see operational records, not a written policy.

Req.Control ObjectiveWhat to ImplementEvidence Your Auditor NeedsKey v4.0.1 Change
1Network SecurityFirewall and network security controls restricting all CDE trafficNetwork diagrams, rule review records every 6 monthsControls are now technology-neutral, not firewall-specific
2Network SecurityRemove all vendor-supplied defaults before any system goes liveHardening standards, system inventory with assigned ownersTargeted Risk Analysis (TRA) now required per system component
3Data ProtectionEncrypt or tokenise all stored cardholder dataData retention policy, encryption key management recordsDisk-level encryption alone no longer satisfies this requirement
4Data ProtectionEncrypt card data in transit over public networksTLS configuration evidence, certificate recordsTLS 1.2 minimum; TLS 1.3 strongly recommended
5Vulnerability ManagementAnti-malware on all in-scope systemsScan logs, update frequency recordsAnti-phishing controls now explicitly required
6Vulnerability ManagementSecure development practices plus payment page script inventoryChange control records, authorised script inventoryReq. 6.4.3: every payment page script must be authorised and integrity-checked (SAQ A-EP and SAQ D only)
7Access ControlRole-based access to the CDE by business need onlyAccess matrix, documented review scheduleFormal access review frequency must now be documented
8Access ControlMFA for all CDE access, unique IDs per userMFA configuration evidence, user account auditMFA now required for all CDE access, not admin accounts only
9Access ControlPhysical access controls on all CDE hardwareVisitor logs, media destruction records, chain of custodyPhysical media tracking requires a documented chain of custody
10MonitoringLog all access to CDE systems and card dataLog retention records, 12 months minimum, plus review evidenceAutomated log review permitted; the mechanism must be documented
11TestingQuarterly internal and external scans plus annual penetration testASV scan reports, pen test report, segmentation test evidenceReq. 11.6.1: HTTP header and payment page tamper detection mandatory for SAQ A-EP and SAQ D merchants
12Security PolicyDocumented information security policy covering all personnelSigned policy acknowledgements, annual review recordsTRA documents required per control frequency decision

Which SAQ Mistake Is Costing Indian Teams the Most?

Indian fintech and e-commerce merchants lose more audit time and money to wrong SAQ selection than to any technical control gap.

Raksha runs payments for a mid-size D2C brand. A gateway handles checkout. She files SAQ A, around 30 questions, because the payment page is outsourced. The QSA visits. Google Tag Manager is firing on the checkout URL. A live chat widget loads from the brand’s own domain. Neither was flagged internally. SAQ A no longer applies. She needed SAQ A-EP, which runs to roughly 190 questions. The reassessment adds four more, and, per the IncorpX India PCI DSS Compliance Guide 2026, wrong selections can cost Indian merchants up to ₹5 lakh in unnecessary audit work. This is how the SAQ types map to your architecture:

SAQ TypeWho It Applies ToQuestionsThe Trap
SAQ AFully outsourced card-not-present payments, no scripts from your domain on checkout~30Any JS from your domain on the payment page disqualifies you
SAQ A-EPE-commerce with third-party payment page but your domain scripts load on checkout~190GTM, analytics tags, or chat widgets on checkout trigger this
SAQ BCard-present only, standalone terminals, no electronic card data storage~45Terminals on your network move you to SAQ C
SAQ CPayment apps connected to the internet, no card data stored~160Legacy POS systems with network connectivity fall here
SAQ DAll merchants storing, processing, or transmitting card data directly~350Partial outsourcing does not reduce your scope to SAQ A

Confirm your SAQ type with your acquiring bank and payment gateway before you start. Review your PCI DSS certification readiness approach before filing anything with your assessor.

How Do You Check and Maintain PCI DSS Compliance All Year?

How to check PCI DSS compliance is a year-round discipline, not a pre-audit sprint. These actions keep your controls evidenced and your assessor satisfied across all 12 months:

  • Run internal vulnerability scans on all in-scope systems every quarter
  • Commission quarterly external scans through a PCI SSC-Approved Scanning Vendor (ASV); CyRAACS provides VAPT and security assessment services aligned to these requirements
  • Complete your annual SAQ or commission a Qualified Security Assessor (QSA) for Level 1 validation
  • Conduct annual penetration testing covering the CDE perimeter and all internal network segmentation
  • Test segmentation controls every six months and after any infrastructure change
  • Verify every third-party service provider’s PCI DSS compliance status annually and keep the records
  • File your Attestation of Compliance (AOC), the formal sign-off confirming your assessment results, with your acquiring bank before your validation deadline

What Should PCI DSS Compliance Software Do for Your Team?

PCI DSS compliance software provides your team with continuous, real-time visibility into all 12 requirements, so your auditor never waits for evidence to be compiled. The right platform tracks live control status, not just stores documents.

FeatureWhat It AutomatesWhy It Matters for Indian BFSI Teams
Unified control mappingMaps one control to PCI DSS compliance, RBI, and ISO 27001 simultaneouslyRemoves the need to run three separate audit programmes in parallel
Continuous evidence collectionPulls scan results, access logs, and policy acknowledgements automaticallyCloses the gap between quarterly scans and annual audit submission
TRA documentationGenerates Targeted Risk Analysis records per control frequencyReq. 12 now mandates this; manual spreadsheet tracking fails at scale
Third-party vendor trackingMonitors vendor compliance status with automated renewal alertsRBI mandates annual vendor PCI DSS compliance verification
Audit-ready dashboardsShows real-time compliance posture across all 12 requirementsQSAs and internal auditors review live evidence without waiting for reports

CyRAACS: PCI DSS Compliance Consulting for Indian BFSI and Fintech

CyRAACS is a CERT-In-empaneled cybersecurity consulting firm. Over 750 client engagements across BFSI, fintech, and IT/ITES. Offices in Bengaluru, Mumbai, and Dubai. Clients include leading banks and small finance banks, among others. The team holds CISSP, CISA, and CISM certifications. It covers every stage of PCI DSS compliance: CDE scoping, gap assessment, technical controls, and continuous monitoring through COMPASS. Ready to close your compliance gaps before your next assessment window? Talk to the CyRAACS team.

Conclusion

Scope is where most PCI DSS compliance programs quietly go wrong. Teams document the controls, file the SAQ, and think the job is done. Then a vendor gets added mid-year, and nobody updates the CDE boundary. Which part of your current programme would not survive a QSA asking to see twelve months of live evidence tomorrow?

Explore CyRAACS’s COMPASS compliance management platform before your next validation window opens.

Start Your PCI DSS Compliance Assessment Today

CyRAACS delivers structured PCI DSS compliance readiness assessments for Indian BFSI and fintech organisations. Every requirement covered. Every control evidenced. Contact CyRAACS to book your assessment.

Frequently Asked Questions

Who needs PCI DSS compliance in India?

Who needs PCI DSS compliance in India includes every merchant, payment aggregator, fintech platform, and third-party service provider that handles card payment data. The RBI Master Direction on Cyber Resilience (July 2024) adds a direct regulatory obligation for non-bank Payment System Operators, separate from the PCI SSC contractual requirement your acquiring bank enforces. Both apply at the same time.

What does PCI DSS compliance software do?

PCI DSS compliance software tracks live evidence across all 12 requirements, automates log review, monitors third-party vendor status, and generates Targeted Risk Analysis documentation your assessor needs on the day. Platforms like COMPASS by CyRAACS go further by mapping PCI DSS controls alongside RBI and ISO 27001 in one place, so your team runs one programme instead of three.

How long does it take to implement PCI DSS compliance?

How to implement PCI DSS compliance from a standing start takes four to eight weeks for a Level 4 merchant with a clean scope. A Level 1 enterprise with significant gaps typically needs six to twelve months. The timeline is almost entirely determined by how well-scoped the Cardholder Data Environment is on day one.

What changed in PCI DSS v4.0.1 compared to v3.2.1?

PCI DSS compliance under v4.0.1 now covers 64 new or updated requirements versus v3.2.1. Thirteen became mandatory in April 2024. The remaining 51 became mandatory on 31 March 2025. The biggest operational shifts are: MFA required for all CDE access (not just admin accounts); client-side script monitoring per Requirements 6.4.3 and 11.6.1; Targeted Risk Analysis documentation per control frequency; and formal annual CDE rescoping. Every 2026 assessment must reflect all 64 changes.

What are the fines for failing PCI DSS compliance?

Monthly penalties start at $5,000 to $10,000 for the first three months. By months four to six, they rise to $25,000 to $50,000. Beyond six months, fines reach $100,000 per month, per industry data from Scrut.io (2025). Your acquiring bank can also suspend card-processing privileges until compliance is restored. If your program has gaps today, CyRAACS can assess and close them before a regulator does.

Let us help you

By clicking on this button, you can connect with us. Let’s make your brand secure.

you may also like