Free Tool
PCI DSS 4.0.1 Readiness Checklist
The March 2025 enforcement deadline shifted PCI DSS from annual snapshots to continuous monitoring. Are you ready? Check your posture in 5 minutes — free.
⚠️ ENFORCEMENT ACTIVE — PCI DSS 4.0.1 is now mandatory
0% Met · 0 Met · 0 Not Met · 0 Unsure
HIGH RISK — Significant gaps identified. Immediate action required.
Section 1 — Network Security Controls
- Firewall/network security controls documented and configured
- Network segmentation between cardholder data environment and other networks
- Wireless access points inventoried and secured
- Network diagrams maintained and current
Section 2 — Secure Configurations
- Default passwords changed on all system components
- Unnecessary services and protocols disabled
- System configuration standards documented and applied
- Non-console admin access encrypted
Section 3 — Data Protection
- Cardholder data storage minimized and documented
- Primary Account Numbers (PAN) rendered unreadable in storage
- Data retention and disposal policy in place
- Sensitive authentication data not stored after authorization
Section 4 — Access Control
- Access to cardholder data restricted to business need-to-know
- Unique user IDs assigned to all users
- MFA implemented for all non-console admin access into CDE
- MFA implemented for all remote network access
- Physical access to cardholder data controlled and monitored
Section 5 — Monitoring and Testing
- All access to system components and cardholder data logged
- Logs reviewed at least daily (NEW in 4.0.1 — previously periodic)
- Intrusion detection/prevention system in place
- Vulnerability scans conducted quarterly
- Penetration testing conducted annually
Section 6 — Policy and Awareness
- Information security policy established, published, and reviewed annually
- Security awareness training completed by all personnel annually
- Incident response plan documented and tested
- Third-party service providers managing cardholder data contractually acknowledge their PCI DSS responsibilities
PCI DSS 4.0.1 requires continuous monitoring — not annual checkboxes.
Scarlet Intel monitors your cardholder data environment in real time, flags new vulnerabilities as they emerge, and keeps your evidence current between assessments. No consultant. No $15K platform.
This checklist is for self-assessment purposes only and does not constitute a formal PCI DSS audit or QSA assessment. Scarlet Intelligence is not a Qualified Security Assessor.
