PCI DSS Requirements
The twelve requirements of PCI DSS v4.0, sequenced by prioritized-approach milestone.
Requirements
9
9
Implemented
1
1
In progress
4
4
Not started
4
4
All requirements
| Requirement | Description | Milestone | Owner | Status | Tested | Evidence | Actions |
|---|---|---|---|---|---|---|---|
| Req 1 | Install and maintain network security controls | 1 | Daniel Chen | In progress | — | 2 | |
| Req 2 | Apply secure configurations | 2 | Daniel Chen | Not started | — | 0 | |
| Req 3 | Protect stored account data | 1 | Arjun Rao | In progress | — | 1 | |
| Req 4 | Protect cardholder data with strong cryptography in transit | 1 | Arjun Rao | Implemented | Jun 30, 2026 | 3 | |
| Req 6 | Develop and maintain secure systems and software | 3 | Arjun Rao | Not started | — | 0 | |
| Req 8 | Identify users and authenticate access | 2 | Arjun Rao | In progress | — | 2 | |
| Req 10 | Log and monitor all access | 3 | Daniel Chen | Not started | — | 0 | |
| Req 11 | Test security of systems and networks regularly | 4 | Arjun Rao | Not started | — | 0 | |
| Req 12 | Support information security with policies and programs | 5 | Priya Menon | In progress | — | 1 |