The 12 PCI DSS Requirements

PCI DSS v4.0 is built on 12 requirements grouped under six goals. Each requirement below opens a full breakdown: sub-requirements, how to meet them, tips, a worked example, and the evidence to keep.

PCI DSS cardholder data flow showing checkout, gateway, token, logs and cardholder data environment boundary.
PCI cardholder flow / 12 KB WebP

Get the documents in our PCI DSS templates (data-flow inventory, scope, SAQ guide, and more).

Audit-ready next steps

PCI DSS documents, evidence, and software path

Cardholder data flow, scope, SAQ, TPSP responsibility, access, logging, crypto, and incident records.