Skip to content
ASIRI

Frameworks · PCI DSS v4.0.1 · managed

Everything inside this line is your problem.

Anything that stores, processes or transmits card data is in scope — and so is anything connected to it. Which means the cheapest way to pass is to move the line, not to harden what is behind it.

Tokenise card dataCard data held in your own vault. Twelve systems in scope.

Systems assessed

1224

Quarterly scan targets

917

Staff needing training

84212
Cardholder data environment
Checkout service
Card vault
Payment gateway
Fraud scoring
Analytics warehouse
Marketing platform
Tokenisation proxy
Settlement job
Refund service
Chargeback tool
Support desk
CRM
Reporting API
Ledger sync
Batch export
Reconciliation
Data warehouse
BI dashboards
HR system
Payroll
Wiki
Issue tracker
Email
Chat

Read from your systems register, so the scope statement matches what is deployed rather than what was true at the last assessment.

Eight digits you may never keep

The middle of the number is not yours

First six, last four. Everything between them must be truncated or rendered unreadable, and three things may never be stored after authorisation under any circumstance — not encrypted, not briefly, not in a log.

Asiri scans what your systems actually retain and raises it as a finding when a log line carries more of the number than the rule allows. This is the failure that ends assessments.

Permitted, if you need it

First 6 digitsLast 4 digitsCardholder nameExpiry dateService code
Stored representation
539962••••••4271

First 6 and last 4 retained · 8 digits truncated at rest

Cardholder

A. OBIORA

Expires

08 / 29

CVV / CVC

Never retained after authorisation. Not once.

PIN or PIN block

Encryption does not make this permissible.

Full track or chip data

Including anything a debug log captured on the way past.

Four levels

Your level is decided by your card volume, not your ambition

Move the slider. It changes whether you fill in a form yourself or a Qualified Security Assessor spends a week in your building — and the jump between the two is the largest cost step on this framework.

Card transactions a year

146,780

Level 4

SAQ

Level 3

SAQ

Level 2

SAQ + scan

Level 1

QSA audit

Level 3 · 20,000 to 1m e-commerce

SAQ, plus quarterly external scans

Still self-assessed, but the scan evidence is expected on a schedule rather than when somebody remembers.

Thresholds are set by the card brands, and each publishes its own. Where they disagree, your acquirer's reading binds you — Asiri records which one you were assessed against.

Twelve requirements

Six of them you have already evidenced for the Act

The overlap is on protection: access, encryption, logging, vulnerability management. What PCI adds is prescription — it tells you how, where the Act only tells you that you must.

01

Network security controls

Read from your firewall configuration, not from a diagram.

02

Secure configurations

No vendor defaults. Asiri flags the ones still in place.

03

Protect stored account data

The requirement tokenisation removes entirely.

04

Encrypt in transit

Already evidenced for the Act on organisational measures.

05

Protect against malware

Endpoint coverage counted against your real asset list.

06

Secure systems and software

Change management and patch windows, with dates.

07

Restrict access by need to know

Your access register, reused whole.

08

Identify and authenticate users

MFA state read from the identity provider.

09

Restrict physical access

The one requirement a cloud-only company scopes out with a shared responsibility matrix.

10

Log and monitor

Retention of twelve months, three of them immediately available.

11

Test security regularly

Quarterly scans and annual penetration testing, on a calendar.

12

Support with policies

Your policy register, plus the targeted risk analyses v4.0 introduced.

v4.0 · the part people miss

A passing scan in March proves nothing in June

Version 4.0 moved the standard toward continuous evidence: targeted risk analyses, defined frequencies, and controls you must show operating rather than merely existing. That is a calendar problem, and it is the one Asiri solves.

New

Targeted risk analysis

For any control where you choose your own frequency, you must document why that frequency is enough. A blank here is a finding.

New

Customised approach

You may meet an objective differently from the prescribed method — but only with the analysis and testing to defend it.

Harder

Continuous evidence

Controls must be shown operating across the period. Point-in-time screenshots stop being sufficient.

Draw the scope line before you buy the assessment

Asiri reads your systems register, marks what touches card data, and shows what tokenisation would remove from the assessment entirely.