Frameworks · PCI DSS v4.0.1 · managed
Everything inside this line is your problem.
Anything that stores, processes or transmits card data is in scope — and so is anything connected to it. Which means the cheapest way to pass is to move the line, not to harden what is behind it.
Systems assessed
Quarterly scan targets
Staff needing training
Read from your systems register, so the scope statement matches what is deployed rather than what was true at the last assessment.
Eight digits you may never keep
The middle of the number is not yours
First six, last four. Everything between them must be truncated or rendered unreadable, and three things may never be stored after authorisation under any circumstance — not encrypted, not briefly, not in a log.
Asiri scans what your systems actually retain and raises it as a finding when a log line carries more of the number than the rule allows. This is the failure that ends assessments.
Permitted, if you need it
First 6 and last 4 retained · 8 digits truncated at rest
Cardholder
A. OBIORA
Expires
08 / 29
CVV / CVC
Never retained after authorisation. Not once.
PIN or PIN block
Encryption does not make this permissible.
Full track or chip data
Including anything a debug log captured on the way past.
Four levels
Your level is decided by your card volume, not your ambition
Move the slider. It changes whether you fill in a form yourself or a Qualified Security Assessor spends a week in your building — and the jump between the two is the largest cost step on this framework.
Card transactions a year
146,780Level 4
SAQ
Level 3
SAQ
Level 2
SAQ + scan
Level 1
QSA audit
Level 3 · 20,000 to 1m e-commerce
SAQ, plus quarterly external scans
Still self-assessed, but the scan evidence is expected on a schedule rather than when somebody remembers.
Thresholds are set by the card brands, and each publishes its own. Where they disagree, your acquirer's reading binds you — Asiri records which one you were assessed against.
Twelve requirements
Six of them you have already evidenced for the Act
The overlap is on protection: access, encryption, logging, vulnerability management. What PCI adds is prescription — it tells you how, where the Act only tells you that you must.
Network security controls
Read from your firewall configuration, not from a diagram.
Secure configurations
No vendor defaults. Asiri flags the ones still in place.
Protect stored account data
The requirement tokenisation removes entirely.
Encrypt in transit
Already evidenced for the Act on organisational measures.
Protect against malware
Endpoint coverage counted against your real asset list.
Secure systems and software
Change management and patch windows, with dates.
Restrict access by need to know
Your access register, reused whole.
Identify and authenticate users
MFA state read from the identity provider.
Restrict physical access
The one requirement a cloud-only company scopes out with a shared responsibility matrix.
Log and monitor
Retention of twelve months, three of them immediately available.
Test security regularly
Quarterly scans and annual penetration testing, on a calendar.
Support with policies
Your policy register, plus the targeted risk analyses v4.0 introduced.
v4.0 · the part people miss
A passing scan in March proves nothing in June
Version 4.0 moved the standard toward continuous evidence: targeted risk analyses, defined frequencies, and controls you must show operating rather than merely existing. That is a calendar problem, and it is the one Asiri solves.
New
Targeted risk analysis
For any control where you choose your own frequency, you must document why that frequency is enough. A blank here is a finding.
New
Customised approach
You may meet an objective differently from the prescribed method — but only with the analysis and testing to defend it.
Harder
Continuous evidence
Controls must be shown operating across the period. Point-in-time screenshots stop being sufficient.
Draw the scope line before you buy the assessment
Asiri reads your systems register, marks what touches card data, and shows what tokenisation would remove from the assessment entirely.