PCI Compliance Checklist, in the order that reduces risk fastest
Most teams start a PCI DSS programme at Requirement 1 and work down the list. That is the wrong order. This pre-audit checklist follows the six risk-based milestones the PCI Security Standards Council uses in its Prioritized Approach, so the controls that close off the worst outcomes come first. Answer honestly and you will finish with a ranked view of what to fix before an assessor walks in.
Answer as an assessor would read it
For each item, ask whether you could put evidence in front of someone today. Not whether you believe it is happening, and not whether it is written in a policy somewhere. A control you cannot evidence is a finding waiting to be written. Mark Partial where something exists but is incomplete, inconsistent across the environment, or undocumented.
Milestone 1. Stop holding what you cannot defend
Critical riskSensitive authentication data, retention limits and knowing your true scope. The cheapest breach is the one where there was nothing worth taking.
Milestone 2. Protect the systems and networks around the data
Very high riskThe largest milestone by far, and where most assessment findings land. These are the controls that stop an attacker reaching the environment in the first place.
Milestone 3. Secure the applications that touch payments
High riskApplication weaknesses are the most reliable route into an otherwise well-defended environment. This milestone is narrow but unforgiving.
Milestone 4. Know who did what, and when
Medium riskAccess control and logging. This is what turns an incident from an unknown into something you can reconstruct, scope and defend.
Milestone 5. Protect the data you have decided to keep
Medium-low riskFor everything that survived Milestone 1. Storage protection and key management is where the standard is least forgiving of good intentions.
Milestone 6. Close the loop and make it hold
Low riskPolicy, governance, people and third parties. Historically treated as paperwork, and now among the most commonly failed areas at assessment.
Answer the questions above to see where you stand
Your score updates as you go. Nothing you enter leaves your browser.
Fix these first
Gaps will be listed here in priority order, earliest milestone first.
Frequently asked questions about the PCI compliance checklist
Is this checklist suitable for all PCI merchant levels?
How often should I review this checklist?
What is the difference between this checklist and the SAQ?
What are the most commonly failed checklist items?
Can a QSA help me work through this checklist?
Continue your PCI journey
All PCI servicesWhat is PCI Compliance?
The complete business guide to PCI DSS: what it is, what is required, and how to get there.
Read the guidePCI Compliance Assistance
QSA-led, end-to-end PCI compliance assistance, from gap assessment to certified AOC.
View serviceSAQ Selector
Find the right SAQ for your business in under 60 seconds. Nine outcomes, no signup.
Open the selectorPre-Audit Maturity Assessment
Rate 24 practices across 8 domains and see whether your compliance will hold between assessments.
Start the assessmentHave a QSA check your answers
Thirty minutes with a practising Qualified Security Assessor who will tell you which of your gaps actually matter for your validation route, and what an assessor will ask for.
About this checklist. The six-milestone risk ordering is the structure published by the PCI Security Standards Council in The Prioritized Approach to Pursue PCI DSS Compliance for PCI DSS v4.0.1. The requirement numbers cited are references to that standard. All question wording on this page is Cianaa’s own, written as evidence questions rather than restatements of the standard, and no text from PCI SSC documents is reproduced here.
PCI DSS and the Prioritized Approach are published by the PCI Security Standards Council LLC, which is not affiliated with Cianaa Technologies and does not endorse this checklist. Always work from the current standard, including its Applicability Notes, which change how individual requirements are interpreted.
Cianaa Technologies is an independent certification and assessment body headquartered in Auckland. We have been a PCI Qualified Security Assessor on the PCI Security Standards Council register since 2014 and are a PCI 3DS Assessor.
