PCI DSS v4.0.1 · ALL SAQ TYPES

PCI DSS v4.0.1 Compliance
Cardholder Data Security

PCI DSS v4.0.1 applies to any organization that stores, processes, or transmits payment card data. ThreeShield delivers scoping analysis, SAQ type determination, and continuous Lavawall® CDE monitoring for merchants and service providers across all SAQ types.

Credit card (PCI DSS) compliance: who we focus on

ThreeShield works with merchants that process fewer than 1 million transactions per card brand per year and service providers under 300,000 per year. These are the organizations that validate PCI DSS with a Self-Assessment Questionnaire (SAQ) rather than a formal on-site report signed by an outside assessor.

For them we handle the whole SAQ path: scoping, choosing the right SAQ type, closing the gaps, and coordinating the quarterly scans. If your volumes are higher and you need a formal on-site assessment, we get you ready for it and bring in the assessor.

PCI DSS SAQ Type Determination

The SAQ your organization must complete depends entirely on how you accept and process card payments. Incorrect SAQ selection is a common compliance gap - and a source of liability.

SAQ A - Fully Outsourced

Card-not-present merchants using fully outsourced payment pages. No electronic storage, processing, or transmission of cardholder data. 22 requirements.

SAQ A-EP - E-Commerce, Outsourced

E-commerce merchants using a third-party processor but with scripts on their own page that could affect payment security. 191 requirements.

SAQ B/B-IP - Standalone Terminals

Merchants using standalone dial-up or IP-connected terminals. Not electronic storage of cardholder data on any computer system. 41-83 requirements.

SAQ C / C-VT - Payment Application Systems

Merchants with payment application systems connected to internet, or virtual terminals via internet browser. 160-249 requirements.

SAQ D - Full PCI DSS

All merchants not meeting criteria for other SAQ types, and all service providers. 329 requirements. Includes all 12 PCI DSS requirement domains.

Lavawall® CDE Monitoring

Continuous monitoring of cardholder data environment systems against PCI DSS Requirements 6 (patch management), 10 (logging and monitoring), and 11 (testing). Automated evidence for quarterly scan requirements.

PCI DSS Non-Compliance Consequences

Card brands (Visa, Mastercard) can impose fines of $5,000-$100,000 per month for non-compliance. Following a breach, non-compliant merchants face forensic investigation costs, chargeback liability, and potential loss of the ability to accept card payments. Healthcare organizations that process card payments are subject to both PCI DSS and their healthcare privacy obligations simultaneously.

What Changed in PCI DSS v4.0 (the big rewrite)

Version 4.0 was the major overhaul of the standard, replacing v3.2.1. These are the changes that reshaped what compliance actually requires.

Customized Approach

v4.0 introduced a "Customized Approach" option allowing organizations to meet the intent of a requirement through alternative controls, backed by a documented risk analysis - instead of only the prescribed method.

Targeted Risk Analysis

Organizations must perform targeted risk analyses for any requirement where the standard leaves the frequency up to the entity. Documented risk analysis is now formally required.

Multi-Factor Authentication Expansion

MFA is now required for all access into the cardholder data environment - not just remote access. This is a significant scope expansion for many organizations.

Password Requirements

Minimum password length increased to 12 characters, complexity requirements were updated, and password management solutions are now formally recognized.

What Changed in PCI DSS v4.0.1 (the current version)

In plain language: v4.0.1 (June 2024) did not add new rules - it corrected errors and clarified confusing wording in v4.0. It is now the only active version; v4.0 has been retired.

A clarification, not a rewrite

No new requirements were added. v4.0.1 fixed typos, tightened wording, and adjusted a few applicability notes so the intent of v4.0 is clearer. If you are compliant with v4.0, you are on track for v4.0.1.

The "best practice until 2025" grace period is over

Many of v4.0's new requirements were optional ("best practice") until March 31, 2025. That date has passed - those requirements are now mandatory and assessed like any other.

Payment-page script monitoring is now required

Even fully outsourced e-commerce sites must now manage and tamper-monitor the scripts on their payment pages (Requirements 6.4.3 and 11.6.1) to catch digital skimming - a change that surprised many small merchants.

Documented, defensible frequencies

Where you set your own scan or review frequency, v4.0.1 expects that decision to be backed by a written risk analysis - not just "quarterly because someone said so."

Do You Need Quarterly ASV Scans? It Depends How You Take Payments

An ASV scan is an external vulnerability scan run by a PCI Approved Scanning Vendor. Whether you need one - and how often - comes down to how card data flows through your website. In plain language:

Fully outsourced checkout (usually SAQ A)

Your payment page is an iframe or redirect to your processor. Typically no ASV scan of the payment path is required - but since 2025 you must still monitor the scripts on that page for tampering.

E-commerce with your own scripts (SAQ A-EP)

Your site touches the payment flow, so a passing external ASV scan every quarter is required, along with the payment-page script rules.

Terminals (SAQ B / B-IP)

Dial-up standalone terminals (B) generally need no external scan. Internet-connected terminals (B-IP) usually do require quarterly ASV scanning of the connected devices.

Payment apps & virtual terminals (SAQ C / C-VT)

Payment applications connected to the internet (C) require quarterly ASV scans. A single isolated virtual terminal (C-VT) usually does not - but the environment decides.

Everyone else & all service providers (SAQ D)

Quarterly external ASV scans and quarterly internal scans are required, and every scan must pass (or be re-scanned until it does).

The bottom line

"Passing" means a clean quarterly ASV scan with no high-risk findings. ThreeShield determines exactly which scans your scope requires - and makes sure you pass them.

The scanning and testing behind PCI live in two related services: our vulnerability assessments cover the quarterly internal and external scans, and our penetration testing covers the annual and segmentation testing PCI DSS Requirement 11.4 asks for.

Frequently Asked Questions

We focus on merchants that process fewer than 1 million transactions per card brand per year and service providers under 300,000 per year. These organizations validate PCI DSS through a Self-Assessment Questionnaire (SAQ) rather than a formal on-site report signed by an external assessor. We handle scoping, SAQ type determination, gap assessment, remediation, and ASV scan coordination. If you are above those volumes and need a formal on-site assessment, we get you ready for it and coordinate the assessor.

Using Stripe, Square, or similar processors reduces your PCI scope significantly - but doesn't eliminate it. You're still responsible for your own systems, the security of your website (for card-not-present), and ensuring your payment page integration doesn't introduce vulnerabilities. Most merchants using hosted payment pages qualify for SAQ A or SAQ A-EP, which have significantly fewer requirements than SAQ D.

Yes. A clinic or hospital that accepts Visa or Mastercard is a PCI merchant regardless of its primary regulatory framework. PCI DSS requirements apply to your payment processing environment; Alberta HIA or HIPAA apply to your health information environment. These are separate compliance obligations that must both be met.

Annual validation - a Self-Assessment Questionnaire (SAQ) or Report on Compliance, plus an Attestation of Compliance (AOC) - is required for most merchants. On top of that, you need internal vulnerability scans every quarter, and for the SAQ types with internet-facing systems in scope (A-EP, C, D, and usually B-IP) a passing quarterly external scan from a PCI Approved Scanning Vendor (ASV).

ThreeShield tracks all of it for you in Lavawall®: we arrange your SAQs, AOCs, and the official ASV scans, and between those official scans we run our own more frequent internal and external scans with Lavawall® and other tools. That way problems get found and fixed before the official ASV scan - so you pass the first time instead of scrambling after a failed one. Lavawall® also monitors continuously, so your quarterly evidence accumulates automatically rather than being gathered in a panic at scan time.

Three Ways to Engage - DIY to Done-for-You

ThreeShield meets you at your current security maturity. Every level includes Lavawall®.

Self-Serve

DIY via Lavawall®

For lean IT departments and cost-conscious organizations with internal security capacity

  • Lavawall® GRC with PCI DSS control mapping
  • Continuous automated evidence collection
  • Live compliance dashboard and score
  • Policy template library
  • AI-generated compliance status reports
Start with Lavawall®
Recommended for MSPs & Lean IT

Supported

Expert guidance alongside your team - ideal for MSPs and organizations with some internal IT capacity

  • Everything in DIY tier
  • CISSP/CISA gap assessment
  • Prioritized remediation roadmap
  • Policy and procedure development
  • Quarterly compliance review calls
  • MSP white-label available
Get Supported Engagement
Fully Managed

Done-for-You

Full compliance delivery - ThreeShield manages the entire program end to end

  • Everything in Supported tier
  • Full compliance program management
  • CISSP/CISA-executed formal assessment
  • findings methodology (typically 200+ findings)
  • Complete documentation package
  • Annual reassessment included
Book Done-for-You

Ready to Get Compliant?

Choose your engagement model: DIY via Lavawall®, supported by ThreeShield's CISSP/CISA team, or fully done-for-you. Every model includes continuous monitoring so you stay compliant year-round.

Book a Scoping Call

DIY · Supported · Done-for-You · Available globally