PCI DSS v4.0.1 applies to any organization that stores, processes, or transmits payment card data. ThreeShield delivers scoping analysis, SAQ type determination, and continuous Lavawall® CDE monitoring for merchants and service providers across all SAQ types.
ThreeShield works with merchants that process fewer than 1 million transactions per card brand per year and service providers under 300,000 per year. These are the organizations that validate PCI DSS with a Self-Assessment Questionnaire (SAQ) rather than a formal on-site report signed by an outside assessor.
For them we handle the whole SAQ path: scoping, choosing the right SAQ type, closing the gaps, and coordinating the quarterly scans. If your volumes are higher and you need a formal on-site assessment, we get you ready for it and bring in the assessor.
The SAQ your organization must complete depends entirely on how you accept and process card payments. Incorrect SAQ selection is a common compliance gap - and a source of liability.
Card-not-present merchants using fully outsourced payment pages. No electronic storage, processing, or transmission of cardholder data. 22 requirements.
E-commerce merchants using a third-party processor but with scripts on their own page that could affect payment security. 191 requirements.
Merchants using standalone dial-up or IP-connected terminals. Not electronic storage of cardholder data on any computer system. 41-83 requirements.
Merchants with payment application systems connected to internet, or virtual terminals via internet browser. 160-249 requirements.
All merchants not meeting criteria for other SAQ types, and all service providers. 329 requirements. Includes all 12 PCI DSS requirement domains.
Continuous monitoring of cardholder data environment systems against PCI DSS Requirements 6 (patch management), 10 (logging and monitoring), and 11 (testing). Automated evidence for quarterly scan requirements.
Card brands (Visa, Mastercard) can impose fines of $5,000-$100,000 per month for non-compliance. Following a breach, non-compliant merchants face forensic investigation costs, chargeback liability, and potential loss of the ability to accept card payments. Healthcare organizations that process card payments are subject to both PCI DSS and their healthcare privacy obligations simultaneously.
Version 4.0 was the major overhaul of the standard, replacing v3.2.1. These are the changes that reshaped what compliance actually requires.
v4.0 introduced a "Customized Approach" option allowing organizations to meet the intent of a requirement through alternative controls, backed by a documented risk analysis - instead of only the prescribed method.
Organizations must perform targeted risk analyses for any requirement where the standard leaves the frequency up to the entity. Documented risk analysis is now formally required.
MFA is now required for all access into the cardholder data environment - not just remote access. This is a significant scope expansion for many organizations.
Minimum password length increased to 12 characters, complexity requirements were updated, and password management solutions are now formally recognized.
In plain language: v4.0.1 (June 2024) did not add new rules - it corrected errors and clarified confusing wording in v4.0. It is now the only active version; v4.0 has been retired.
No new requirements were added. v4.0.1 fixed typos, tightened wording, and adjusted a few applicability notes so the intent of v4.0 is clearer. If you are compliant with v4.0, you are on track for v4.0.1.
Many of v4.0's new requirements were optional ("best practice") until March 31, 2025. That date has passed - those requirements are now mandatory and assessed like any other.
Even fully outsourced e-commerce sites must now manage and tamper-monitor the scripts on their payment pages (Requirements 6.4.3 and 11.6.1) to catch digital skimming - a change that surprised many small merchants.
Where you set your own scan or review frequency, v4.0.1 expects that decision to be backed by a written risk analysis - not just "quarterly because someone said so."
An ASV scan is an external vulnerability scan run by a PCI Approved Scanning Vendor. Whether you need one - and how often - comes down to how card data flows through your website. In plain language:
Your payment page is an iframe or redirect to your processor. Typically no ASV scan of the payment path is required - but since 2025 you must still monitor the scripts on that page for tampering.
Your site touches the payment flow, so a passing external ASV scan every quarter is required, along with the payment-page script rules.
Dial-up standalone terminals (B) generally need no external scan. Internet-connected terminals (B-IP) usually do require quarterly ASV scanning of the connected devices.
Payment applications connected to the internet (C) require quarterly ASV scans. A single isolated virtual terminal (C-VT) usually does not - but the environment decides.
Quarterly external ASV scans and quarterly internal scans are required, and every scan must pass (or be re-scanned until it does).
"Passing" means a clean quarterly ASV scan with no high-risk findings. ThreeShield determines exactly which scans your scope requires - and makes sure you pass them.
The scanning and testing behind PCI live in two related services: our vulnerability assessments cover the quarterly internal and external scans, and our penetration testing covers the annual and segmentation testing PCI DSS Requirement 11.4 asks for.
We focus on merchants that process fewer than 1 million transactions per card brand per year and service providers under 300,000 per year. These organizations validate PCI DSS through a Self-Assessment Questionnaire (SAQ) rather than a formal on-site report signed by an external assessor. We handle scoping, SAQ type determination, gap assessment, remediation, and ASV scan coordination. If you are above those volumes and need a formal on-site assessment, we get you ready for it and coordinate the assessor.
Using Stripe, Square, or similar processors reduces your PCI scope significantly - but doesn't eliminate it. You're still responsible for your own systems, the security of your website (for card-not-present), and ensuring your payment page integration doesn't introduce vulnerabilities. Most merchants using hosted payment pages qualify for SAQ A or SAQ A-EP, which have significantly fewer requirements than SAQ D.
Yes. A clinic or hospital that accepts Visa or Mastercard is a PCI merchant regardless of its primary regulatory framework. PCI DSS requirements apply to your payment processing environment; Alberta HIA or HIPAA apply to your health information environment. These are separate compliance obligations that must both be met.
Annual validation - a Self-Assessment Questionnaire (SAQ) or Report on Compliance, plus an Attestation of Compliance (AOC) - is required for most merchants. On top of that, you need internal vulnerability scans every quarter, and for the SAQ types with internet-facing systems in scope (A-EP, C, D, and usually B-IP) a passing quarterly external scan from a PCI Approved Scanning Vendor (ASV).
ThreeShield tracks all of it for you in Lavawall®: we arrange your SAQs, AOCs, and the official ASV scans, and between those official scans we run our own more frequent internal and external scans with Lavawall® and other tools. That way problems get found and fixed before the official ASV scan - so you pass the first time instead of scrambling after a failed one. Lavawall® also monitors continuously, so your quarterly evidence accumulates automatically rather than being gathered in a panic at scan time.
ThreeShield meets you at your current security maturity. Every level includes Lavawall®.
For lean IT departments and cost-conscious organizations with internal security capacity
Expert guidance alongside your team - ideal for MSPs and organizations with some internal IT capacity
Full compliance delivery - ThreeShield manages the entire program end to end
Choose your engagement model: DIY via Lavawall®, supported by ThreeShield's CISSP/CISA team, or fully done-for-you. Every model includes continuous monitoring so you stay compliant year-round.
Book a Scoping CallDIY · Supported · Done-for-You · Available globally