SCARLET RISK

Free Tool

PCI DSS 4.0.1 Readiness Checklist

The March 2025 enforcement deadline shifted PCI DSS from annual snapshots to continuous monitoring. Are you ready? Check your posture in 5 minutes — free.

⚠️ ENFORCEMENT ACTIVE — PCI DSS 4.0.1 is now mandatory
0% Met · 0 Met · 0 Not Met · 0 Unsure
HIGH RISK — Significant gaps identified. Immediate action required.

Section 1Network Security Controls

  • Firewall/network security controls documented and configured
  • Network segmentation between cardholder data environment and other networks
  • Wireless access points inventoried and secured
  • Network diagrams maintained and current

Section 2Secure Configurations

  • Default passwords changed on all system components
  • Unnecessary services and protocols disabled
  • System configuration standards documented and applied
  • Non-console admin access encrypted

Section 3Data Protection

  • Cardholder data storage minimized and documented
  • Primary Account Numbers (PAN) rendered unreadable in storage
  • Data retention and disposal policy in place
  • Sensitive authentication data not stored after authorization

Section 4Access Control

  • Access to cardholder data restricted to business need-to-know
  • Unique user IDs assigned to all users
  • MFA implemented for all non-console admin access into CDE
  • MFA implemented for all remote network access
  • Physical access to cardholder data controlled and monitored

Section 5Monitoring and Testing

  • All access to system components and cardholder data logged
  • Logs reviewed at least daily (NEW in 4.0.1 — previously periodic)
  • Intrusion detection/prevention system in place
  • Vulnerability scans conducted quarterly
  • Penetration testing conducted annually

Section 6Policy and Awareness

  • Information security policy established, published, and reviewed annually
  • Security awareness training completed by all personnel annually
  • Incident response plan documented and tested
  • Third-party service providers managing cardholder data contractually acknowledge their PCI DSS responsibilities

PCI DSS 4.0.1 requires continuous monitoring — not annual checkboxes.

Scarlet Intel monitors your cardholder data environment in real time, flags new vulnerabilities as they emerge, and keeps your evidence current between assessments. No consultant. No $15K platform.

This checklist is for self-assessment purposes only and does not constitute a formal PCI DSS audit or QSA assessment. Scarlet Intelligence is not a Qualified Security Assessor.