PCI DSS v4.0.1 Compliance Checklist and Evidence Tracker
Prepare for a PCI DSS assessment with a working checklist covering all 12 requirement groups, evidence status, ownership, gaps, and remediation.
- 18-page PCI DSS v4.0.1 compliance checklist
- Editable evidence tracker
- Requirements 1–12 evidence checks
- Remediation and final readiness review
The control is there. The evidence is somewhere else.
Controls get implemented across security, IT, compliance, and vendors. Proving they work, on demand, is a different job.
What's inside the PCI DSS Compliance Checklist
PCI DSS scoping setup
Record your validation route, CDE, connected systems, third parties, segmentation, and owners.
Requirements 1–12 checklist
Review control readiness and expected evidence across all 12 PCI DSS requirement groups.
Editable evidence tracker
Track applicability, implementation, evidence status, owners, gaps, priorities, dates, and evidence links.
Validation materials tracker
Keep SAQ or ROC, AOC, ASV scans, penetration-test records, policies, and supporting evidence in view.
Readiness and remediation review
See which requirement groups are ready and where control or evidence gaps remain open.
Final assessment check
Run one last review before validation and confirm that evidence can actually be produced when requested.
PCI DSS readiness works better when evidence has an owner
Use the PDF checklist to review implementation and the editable tracker to maintain your own evidence record throughout the assessment cycle.
Download the PCI DSS Compliance ChecklistTwo different jobs, covered by two different resources
The PCI DSS Compliance Evidence Checklist covers readiness and evidence across all 12 requirement groups. The PCI DSS Penetration Testing Playbook focuses specifically on Requirement 11.4 and the penetration-testing engagement.
Go deeper than the requirement headings
Separate control status from evidence status
A technical control can be working while the evidence behind it is incomplete. Tracking the two separately makes those gaps visible earlier.
Prepare evidence across all 12 requirements
Use one structure across network controls, stored account data, access, authentication, logging, testing, policies, third parties, and the rest of the PCI DSS program.
Keep remediation visible
Record gaps, owners, priority, target dates, and closure evidence instead of rebuilding the remediation list before every assessment.
Keep evidence from depending on one person
Evidence should not disappear because the person who knows where it lives is unavailable that week.
Need more context before using the checklist? Start here.
Frequently asked questions
What is a PCI compliance checklist?
A PCI compliance checklist is a working document for reviewing applicable PCI DSS controls, implementation status, supporting evidence, ownership, gaps, and remediation before or during an assessment.
What does this PCI DSS compliance checklist cover?
It covers readiness and evidence across all 12 PCI DSS requirement groups, plus assessment scope, validation materials, remediation, and final assessment preparation.
Does this checklist replace an SAQ or ROC?
No. It supports assessment preparation and evidence management. It does not replace an official SAQ, ROC, AOC, ASV report, or other required PCI DSS validation documentation.
Is this a PCI compliance checklist PDF?
Yes. The resource includes a PDF checklist and an editable spreadsheet for maintaining your PCI DSS evidence tracker.
Can I use it for a PCI DSS assessment?
Yes. It is designed to help teams prepare evidence, identify gaps, assign ownership, and track remediation before and during assessment preparation.
What is the difference between this checklist and the PCI DSS Penetration Testing Playbook?
The checklist covers readiness across the full PCI DSS standard. The Penetration Testing Playbook focuses on Requirement 11.4 and the penetration-testing process.
A checklist can reveal missing controls and missing evidence
Q-Sec can review your PCI DSS scope, technical controls, evidence gaps, and remediation priorities.