Skip to main content
Free resource · PCI DSS v4.0.1

PCI DSS v4.0.1 Compliance Checklist and Evidence Tracker

Prepare for a PCI DSS assessment with a working checklist covering all 12 requirement groups, evidence status, ownership, gaps, and remediation.

  • 18-page PCI DSS v4.0.1 compliance checklist
  • Editable evidence tracker
  • Requirements 1–12 evidence checks
  • Remediation and final readiness review
— 01 · The challenge

The control is there. The evidence is somewhere else.

Controls get implemented across security, IT, compliance, and vendors. Proving they work, on demand, is a different job.

Common PCI DSS readiness problem
What the team needs
Controls are implemented, but supporting evidence is scattered
One place to track control and evidence status separately
PCI DSS ownership is split across security, IT, compliance, and vendors
Clear control and evidence owners
Evidence is collected only shortly before assessment
An ongoing evidence tracker
Remediation exists in tickets and separate spreadsheets
Gap, priority, target date, and closure tracking
Scope changes are not reflected quickly enough
A repeatable scoping and review process
— 02 · Inside the download

What's inside the PCI DSS Compliance Checklist

PCI DSS scoping setup

Record your validation route, CDE, connected systems, third parties, segmentation, and owners.

Requirements 1–12 checklist

Review control readiness and expected evidence across all 12 PCI DSS requirement groups.

Editable evidence tracker

Track applicability, implementation, evidence status, owners, gaps, priorities, dates, and evidence links.

Validation materials tracker

Keep SAQ or ROC, AOC, ASV scans, penetration-test records, policies, and supporting evidence in view.

Readiness and remediation review

See which requirement groups are ready and where control or evidence gaps remain open.

Final assessment check

Run one last review before validation and confirm that evidence can actually be produced when requested.

PCI DSS readiness works better when evidence has an owner

Use the PDF checklist to review implementation and the editable tracker to maintain your own evidence record throughout the assessment cycle.

Download the PCI DSS Compliance Checklist
— 03 · Full readiness or penetration testing?

Two different jobs, covered by two different resources

The PCI DSS Compliance Evidence Checklist covers readiness and evidence across all 12 requirement groups. The PCI DSS Penetration Testing Playbook focuses specifically on Requirement 11.4 and the penetration-testing engagement.

PCI DSS Compliance Checklist
PCI DSS Penetration Testing Playbook
Readiness and evidence across all 12 requirement groups
Scope, methodology, and evidence for Requirement 11.4 testing
Control status, ownership, and remediation tracking
Segmentation testing, retest cycles, and engagement readiness
— 04 · Why teams use this checklist

Go deeper than the requirement headings

Separate control status from evidence status

A technical control can be working while the evidence behind it is incomplete. Tracking the two separately makes those gaps visible earlier.

Prepare evidence across all 12 requirements

Use one structure across network controls, stored account data, access, authentication, logging, testing, policies, third parties, and the rest of the PCI DSS program.

Keep remediation visible

Record gaps, owners, priority, target dates, and closure evidence instead of rebuilding the remediation list before every assessment.

Keep evidence from depending on one person

Evidence should not disappear because the person who knows where it lives is unavailable that week.

— 05 · Refresh the PCI DSS essentials

Need more context before using the checklist? Start here.

PCI DSS Requirements

Review all 12 requirement groups and what each one covers.

Read the guide
PCI DSS Audit and Assessment

See how assessments work and what evidence to prepare.

Read the guide
Cardholder Data Environment

Clarify CDE scope, connected systems, and segmentation.

Read the guide
— 06 · FAQ

Frequently asked questions

What is a PCI compliance checklist?

A PCI compliance checklist is a working document for reviewing applicable PCI DSS controls, implementation status, supporting evidence, ownership, gaps, and remediation before or during an assessment.

What does this PCI DSS compliance checklist cover?

It covers readiness and evidence across all 12 PCI DSS requirement groups, plus assessment scope, validation materials, remediation, and final assessment preparation.

Does this checklist replace an SAQ or ROC?

No. It supports assessment preparation and evidence management. It does not replace an official SAQ, ROC, AOC, ASV report, or other required PCI DSS validation documentation.

Is this a PCI compliance checklist PDF?

Yes. The resource includes a PDF checklist and an editable spreadsheet for maintaining your PCI DSS evidence tracker.

Can I use it for a PCI DSS assessment?

Yes. It is designed to help teams prepare evidence, identify gaps, assign ownership, and track remediation before and during assessment preparation.

What is the difference between this checklist and the PCI DSS Penetration Testing Playbook?

The checklist covers readiness across the full PCI DSS standard. The Penetration Testing Playbook focuses on Requirement 11.4 and the penetration-testing process.

— Looking beyond the checklist?

A checklist can reveal missing controls and missing evidence

Q-Sec can review your PCI DSS scope, technical controls, evidence gaps, and remediation priorities.

Talk to Q-Sec