PCI DSS v4.0 Compliance Checklist for SaaS & Fintech Companies (2026)

PCI DSS v4.0 Compliance Checklist for SaaS & Fintech Companies

PCI DSS compliance checklist

Getting PCI DSS compliance checklist isn’t a single event — it’s a sequence of well-defined steps, each building on the last, that ends with your organization proving it can handle cardholder data safely, wherever it lives in your systems. This guide walks through the full checklist: what you’ll build, what assessors look for, and how the pieces fit together for SaaS and fintech teams handling payment data.

Quick idea:  PCI DSS v4.0 is the global security standard for any business that stores, processes, or transmits cardholder data. Compliance is built around 6 goals and 12 core requirements, validated through a mix of self-assessment, scanning, and — for higher-volume merchants — a formal audit by a Qualified Security Assessor (QSA).

Data protection:  Encrypt, restrict, and monitor access to cardholder data across every system that touches it.

Customer trust:  Compliance signals to customers, partners, and payment brands that you take card security seriously.

Continuous validation:  Quarterly scans, annual assessments, and ongoing monitoring keep your compliance status current, not just a one-time checkbox.

Important context:  B4Q Assurance works with SaaS and fintech clients across the PCI DSS journey — from scoping the cardholder data environment through SAQ completion or QSA-led assessment — and this checklist reflects the patterns we see across those engagements.

PCI DSS compliance checklist Requirements at a Glance

Before working through the checklist itself, it helps to see the shape of the standard you’re complying with. PCI DSS compliance checklist organizes its requirements into 6 broad goals, which break down into 12 specific requirements that assessors test against.

PCI DSS Goals and Requirements
Goal Requirements
Building and maintaining secure networks 1. Install and maintain a firewall configuration to protect cardholder data
2. Do not use vendor-supplied defaults for system passwords and other security parameters
Protecting cardholder data 3. Protect stored cardholder data
4. Encrypt transmission of cardholder data across open, public networks
Managing vulnerabilities 5. Use and regularly update anti-virus software or programs
6. Develop and maintain secure systems and applications
Implementing strong access controls 7. Restrict access to cardholder data by business need-to-know
8. Assign a unique ID to each person with computer access
9. Restrict physical access to cardholder data
Monitoring and testing networks 10. Track and monitor all access to network resources and cardholder data
11. Regularly test security systems and processes
Establishing information security policies 12. Maintain a policy that addresses information security for all personnel

The 6 Steps to Get PCI DSS Compliant

At a high level, every compliance journey compresses into six recognizable steps. The checklist further down expands on each of these for SaaS and fintech environments specifically.

PCI DSS Compliance Checklist
  • Determine your merchant or service provider level
  • Map your cardholder data environment
  • Reduce scope where you can
  • Perform a gap assessment
  • Implement controls and document everything
  • Validate and maintain compliance

The PCI DSS Compliance Checklist, Step by Step

Zooming in, most SaaS and fintech teams move through these practical steps from kickoff to validated compliance — and then into the ongoing cycle that keeps that status current.

Step 1: Determine Your Level

Your PCI DSS obligations scale with transaction volume. Merchant levels (1–4) and service provider levels (1–2) each carry different validation requirements — from a Self-Assessment Questionnaire (SAQ) at the low end to a full Report on Compliance (RoC) from a QSA at the high end. Get this right first; it determines everything else about scope and effort.

Step 2: Map Your Cardholder Data Environment (CDE)

Identify every system, application, and network segment that stores, processes, or transmits cardholder data — and everything connected to those systems. For SaaS platforms, this usually means tracing data flows through APIs, third-party payment processors, logging pipelines, and backup systems that teams sometimes forget are in scope.

PCI DSS Compliance Checklist

Step 3: Reduce Scope Where You Can

The smaller your CDE, the smaller your compliance burden. Network segmentation, tokenization, and routing card data through a PCI-validated payment processor instead of touching raw card numbers directly are the most common ways SaaS and fintech companies shrink scope before doing anything else.

Step 4: Perform a Gap Assessment

Compare your current controls against the 12 PCI DSS requirements and identify what’s missing. This step produces the remediation plan that drives the rest of the project, and it’s where most teams first discover how much of the standard is already covered by existing security work.

Step 5: Implement Controls and Document Everything

Close the gaps identified above: firewall rules, encryption in transit and at rest, access controls, vulnerability management, and logging. Documentation matters as much as the controls themselves — assessors and QSAs need evidence that policies are written down and being followed, not just implemented informally.

Step 6: Complete Your SAQ or Assessment

Depending on your level, this means completing the appropriate Self-Assessment Questionnaire, running required quarterly vulnerability scans through an Approved Scanning Vendor (ASV), and — for Level 1 merchants and service providers — undergoing a formal on-site or remote assessment with a QSA.

Step 7: Submit Your Attestation of Compliance (AoC)

Once validation is complete, submit your AoC to your acquiring bank or the payment brands, along with your SAQ or RoC. This is the formal record that confirms your compliance status for the year.

Step 8: Maintain Continuous Compliance

Compliance isn’t the finish line. Quarterly ASV scans, annual penetration testing, ongoing log monitoring, and re-validation each year keep your status current between assessments.

PCI DSS Compliance Checklist

What Are the Consequences of Non-Compliance?

Skipping or delaying PCI DSS compliance checklist carries real business risk, not just an audit finding.

PCI DSS Compliance Checklist
Consequences of Non-Compliance
Consequence What It Looks Like
Financial penalties Payment brands and acquiring banks can levy fines, often escalating the longer non-compliance continues
Fraud losses Uncontrolled cardholder data increases breach risk, and fraud losses can stack up fast once an incident occurs
Loss of customer trust Customers and partners expect card data to be handled safely; a breach or known gap erodes that confidence quickly
Harder to scale Enterprise customers, payment processors, and partners increasingly require proof of compliance before signing

Why PCI DSS compliance checklist Matters for Your Business

PCI DSS Compliance Checklist

Beyond avoiding penalties, PCI DSS compliance protects customers from data breaches, boosts customer confidence in your business, and gives your security program a proven baseline to build on — one that’s already mapped to what payment brands and acquiring banks expect to see.

Common Mistakes During PCI DSS compliance checklist

  • Assuming a third-party payment processor removes all PCI scope, without confirming exactly what’s still in the CDE.
  • Treating the SAQ as a one-time form instead of an accurate, current picture of your environment.
  • Skipping quarterly ASV scans between annual assessments, which is exactly where drift tends to show up first.
  • Under-scoping network segmentation, leaving far more systems in scope than necessary.
  • Losing track of compliance once the AoC is submitted, instead of maintaining controls year-round.

How B4Q Assurance Helps

PCI DSS Compliance Checklist

B4Q Assurance works with SaaS and fintech organizations preparing for PCI DSS v4.0 compliance — scoping the cardholder data environment, running gap assessments, and getting teams ready for SAQ completion or QSA-led assessment.

Resources

PCI Security Standards Council — PCI DSS v4.0: the official standard reference.

PCI SSC — Self-Assessment Questionnaire (SAQ) instructions and guidelines.

PCI SSC — Approved Scanning Vendors (ASV) list for required quarterly scans.

 

FAQs

How long does PCI DSS v4.0 compliance take?

Most SaaS and fintech companies take 2–4 months from scoping to a completed SAQ, or longer for Level 1 merchants and service providers requiring a full QSA assessment, depending on how much of the cardholder data environment already has controls in place.

Only merchants and service providers at the highest transaction levels are required to use a QSA for a formal Report on Compliance. Lower levels typically self-assess using the appropriate SAQ, though many teams still bring in outside help to scope correctly the first time.

There’s no automatic penalty for a first finding. You’re given time to remediate identified gaps, and compliance is confirmed once those fixes are verified through re-scanning or re-assessment.

Annually, along with quarterly vulnerability scans through an ASV and ongoing monitoring in between.

It can significantly reduce scope if implemented correctly — for example, by tokenizing card data or redirecting payment collection entirely to the processor — but it rarely eliminates PCI obligations altogether, since the surrounding systems are usually still part of the CDE.

What do you think?