The 51 future-dated requirements of PCI DSS v4 stopped being future-dated on 31 March 2025. Multi-factor authentication for all access to the cardholder data environment, twelve-character passwords, payment page script integrity, anti-phishing controls — these are not roadmap items any more. They are assessed.

This assessment scopes your environment first, then scores all twelve requirements at sub-requirement level, flagging what changed in v4 as it goes. It is free, it saves as you go, and you can stop and come back to it.

What is a PCI DSS gap assessment?

A gap assessment compares what you do today against PCI DSS v4.0.1 and records the distance, before a QSA does it for a fee or before you sign a self-assessment questionnaire you cannot actually support.

The expensive failures are almost never technical. They are scope failures — a payment channel nobody remembered, cardholder data sitting in call recordings or support tickets, segmentation that was designed but never tested. That is why this assessment spends its first six questions on scope rather than controls.

What this assessment covers

73 assessable items: 6 on scope, all 63 second-level sub-requirements across the twelve requirements, and 4 on approach and risk analysis.

DomainItemsWhat it asks about
Scope and validation6Merchant or service provider level, payment channels, data discovery, CDE definition, segmentation testing, service providers
1 — Network security controls5Configuration, restricting traffic to and from the CDE, trusted and untrusted boundaries, remote devices
2 — Secure configuration3Hardening standards, vendor defaults, wireless
3 — Protecting stored account data7Minimising storage, sensitive authentication data, masking, rendering PAN unreadable, key protection and lifecycle
4 — Data in transit2Strong cryptography over open networks, the certificate inventory
5 — Malicious software4Anti-malware coverage, currency, removable media, anti-phishing
6 — Secure systems and software5Secure development, patching, web application protection, payment page scripts, change management
7 — Access by need to know3Least privilege, six-monthly reviews, default deny
8 — Identity and authentication6Unique IDs, password strength, MFA for the CDE, MFA configuration, system account credentials
9 — Physical access5Entry controls, visitors, media handling and destruction, card reader tamper checks
10 — Logging and monitoring7Log content, protection, automated review, retention, time sync, control failure detection
11 — Testing security6Wireless detection, vulnerability scanning, penetration testing, intrusion and change detection, payment page tamper detection
12 — Policies and programmes10Security policy, acceptable use, risk analyses, scope confirmation, awareness, screening, service providers, incident response
Approach and risk analysis4Defined or customized approach, both kinds of targeted risk analysis, evidence readiness

What actually changed in v4

Sixty-four requirements were new in v4. Thirteen applied immediately; the other fifty-one became mandatory on 31 March 2025. The ones that catch organisations out:

  • 8.4.2 — MFA for all access into the CDE. Not just administrators, not just remote. This is the biggest single change in the standard.
  • 6.4.3 and 11.6.1 — payment page scripts. An inventory of every script on the page, authorisation for each, integrity checking, and tamper detection. Aimed at digital skimming, and the requirement most organisations have not started.
  • 12.3.1 — targeted risk analyses. Wherever the standard lets you set your own frequency, you now owe a documented analysis justifying it, reviewed annually.
  • 7.2.4 — six-monthly access reviews, now extending to application and system accounts.
  • 5.4.1 — anti-phishing. A technical control, not a training slide.

v4.0.1, published June 2024, added no requirements and renumbered nothing — it was an errata and clarification release.

How the scoring works

StatusWeightMeans
Not started0%No policy, process or activity exists
Planned25%Agreed and scheduled, nothing in place yet
Partially implemented50%In place for part of the scope, or applied inconsistently
Implemented, not evidenced75%Operating as intended, but you could not prove it today
Implemented and evidenced100%Operating as intended, with records an assessor can sample
Not applicable—A justified exclusion, removed from the score

Free score, or the full report

The assessment and your overall score are free. The full report is a one-off $39 and gives you every sub-requirement with your status and notes, the score broken down by requirement, a prioritised gap list, and the Governance Docs documents that close each gap — PDF and working Excel.

How long does it take?

About 40 minutes. The scope section at the start is worth slowing down for; every later answer depends on it being right.

Gap assessment, SAQ, Report on Compliance

  • Gap assessment — you, measuring yourself, with no consequences for an honest answer. This.
  • Self-assessment questionnaire — the formal validation document for lower-volume merchants and some service providers. Which SAQ applies depends on your payment channels, which is why the assessment asks about them.
  • Report on Compliance — a QSA’s assessment, required at the higher levels, and priced accordingly.

What to do with your score

Below 40% — fix scope first. Run data discovery, draw the CDE, and look hard at whether you can take cardholder data out of scope entirely.

40–70% — work the March 2025 requirements as a block. MFA, password length, access reviews and payment page controls are where most of the remaining distance sits.

Above 70% — assemble evidence and confirm your validation route. Pulling evidence is what makes assessments overrun.

Frequently asked questions

Is this assessment really free?

Yes. Every sub-requirement, your section breakdown and your overall score cost nothing. The $39 full report is optional.

Does it assess v4.0 or v4.0.1?

v4.0.1, the current version. Since v4.0.1 added no requirements and renumbered nothing, the structure is identical to v4.0.

Why sub-requirement level rather than every individual control?

There are around 250 individual requirements in v4.0.1. Scoring each one would take well over an hour and most people would abandon it. Scoring the 63 sub-requirements gives you an accurate picture in 40 minutes and points precisely at where to look in the standard.

Does it cover the appendices?

Not A1, A2 or A3 — they apply to multi-tenant service providers, SSL/early TLS migration and designated entities respectively. If those apply to you, you are almost certainly working with a QSA already.

Is a high score the same as being PCI compliant?

No. Compliance is validated through an SAQ or a Report on Compliance. This tells you how that validation is likely to go.

Can I use this for a client?

Yes. Run one assessment per client organisation.

What happens to my answers?

They are stored against your account so you can come back to them, and they are never shared. Never enter cardholder data — the notes fields are for describing controls. You can delete your answers at any time.