Home/Documentation/Regulation-specific sets

Policies & Standards — PCI DSS v4.0.1

Policies and standards for all 12 PCI DSS requirements, with the targeted risk analysis templates the v4 standard introduced and SAQ-specific scoping guidance.

What this set does

PCI DSS v4 asks for documented policies and procedures under every requirement, plus targeted risk analyses for the customised-approach and frequency-based controls. This set covers all twelve requirements and includes an applicability matrix so you keep only what your SAQ type needs.

What's inside

  • Policies and standards for Requirements 1–12
  • SAQ applicability matrix (A, A-EP, B, B-IP, C, C-VT, D Merchant, D Service Provider)
  • Cardholder data environment scoping and data-flow template
  • Targeted risk analysis templates (Requirement 12.3.1 and 12.3.2)
  • Roles and responsibilities acknowledgement (Requirement 12.4)
  • Quarterly and annual PCI task calendar

Who it is for

Merchants and service providers completing a SAQ or preparing for a QSA assessment.

How the documents are structured

Every document opens with its purpose, scope and owner, then the substantive content, then a control cross-reference showing which framework requirements it satisfies. Standards state requirements in testable language ("must", with the parameter). Procedures follow one format: trigger, roles, steps, frequency, records produced. Placeholders are limited to things only you can know: organisation name (which we fill in), system names, role titles, tool names and timelines. There are no "[insert policy here]" sections.

Tailoring effort

Expect to spend a few hours on a policies-and-standards set and longer on procedures, because procedures describe how your team actually works. The document register in each set lists every file with a suggested owner so you can split the work.

Licence

One purchase covers one organisation for internal use, with unlimited users and unlimited edits. Consultancies and MSPs tailoring documents for clients need the multi-client licence; see the terms or ask us.

Related products

Vulnerability & Patch Management Programme

A vulnerability management policy, SLA-driven remediation standard, scanning and patching procedures, and secure baseline configuration standards for common platforms.

£345 · 16 documents