Skip to main content

Blog/Security

PCI DSS 4.0: what merchants should finish before the next audit

A practical sequence for SAQ, segmentation, and evidence so the next PCI assessment is a review, not a scramble.

DDevolity·Feb 18, 2026·2 min read
On this page

PCI DSS 4.0 did not invent new checkout software. It asks merchants to show that cardholder data is scoped, protected, and watched all year, not only the week an assessor arrives.

Most gaps we see are operational. The questionnaire is current, the network diagram is not. Logging exists, nobody reviews it. A service provider changed, and the responsibility matrix was never updated.

Start with scope

Draw where card data can exist: payment page, gateway, tokens, backups, and support tools. If a system can see a PAN, it is in scope until you prove otherwise. Tokenization and a hosted payment page shrink that drawing. They do not remove the need for access control on the systems that remain.

Segmentation only counts when you can demonstrate it. A firewall rule with no test is a hope. Run the test, keep the result, and date it.

Evidence you can hand over

Keep a single folder for the assessment period:

  • Network diagram and data-flow diagram, both dated
  • ASV scan results and the tickets that closed the failures
  • Access reviews for anyone who can reach the cardholder environment
  • The service-provider list, with which requirement each vendor covers

Assign an owner for each item. A shared drive with no owner becomes stale before the audit window opens.

What to do in the 90 days before fieldwork

  1. Reconfirm scope with the people who actually deploy changes.
  2. Close or formally risk-accept every failing scan item.
  3. Walk one incident from alert to ticket to closure, and write down the path.
  4. Brief the assessor on what changed since last year before they ask.

Devolity runs this as a programme with the same team that operates the environment, from SAQ through AOC. If you want that scope written down for your stack, talk to us.

PCI DSS 4.0: what merchants should finish before the next audit | Devolity