Compliance Scanning

PCI DSS 4.0
Compliance Scanning

PCI DSS 4.0 introduces new requirements for payment page script integrity, anti-phishing mechanisms, and enhanced encryption standards. ComplianceLayer maps external scan findings to the specific PCI DSS 4.0 requirements your QSA evaluates.

Control Mapping

PCI DSS 4.0 Requirements Mapped to Scan Modules

The following PCI DSS 4.0 requirements are verified through external scanning. Control IDs reference the PCI DSS v4.0 standard published by the PCI Security Standards Council.

RequirementDescriptionScan ModuleWhat We Check
1.2.1Restrict Inbound/Outbound TrafficOpen PortsConfigure network security controls to restrict inbound and outbound traffic. Detects exposed services beyond what is necessary.
1.3.1Restrict Inbound Traffic to CDEOpen PortsRestrict inbound traffic to the cardholder data environment. Identifies exposed RDP, database, and administrative ports.
2.2.4Configure System Security ParametersSecurity Headers / PortsConfigure system security parameters to prevent misuse. Validates security header configuration and service exposure.
2.2.5Enable Only Necessary ServicesOpen Ports / SSLEnable only necessary services, protocols, and ports. Detects unnecessary services and deprecated TLS versions.
4.1Strong Cryptography for TransmissionSSL/TLSUse strong cryptography and security protocols to safeguard cardholder data in transit. Validates TLS 1.2+, cipher strength, and certificate validity.
4.2.1Strong Cryptography ControlsSSL/TLS / EmailImplement strong cryptography whenever cardholder data is transmitted. Checks HTTPS enforcement, HSTS, SPF, DKIM, and DMARC.
5.1.1Anti-Phishing MechanismsEmailImplement anti-phishing mechanisms. Validates DMARC policy enforcement to prevent email domain spoofing.
6.4.3Payment Page Script IntegritySecurity HeadersManage all payment page scripts loaded and executed in the consumer browser. Validates Content-Security-Policy for script control.
6.5.4Insecure Direct Object ReferencesSecurity HeadersAddress common coding vulnerabilities including insecure direct object references. Validates HSTS and access control headers.
6.5.7Cross-Site Scripting (XSS)Security HeadersAddress XSS vulnerabilities. Validates CSP, X-Content-Type-Options, X-Frame-Options, and X-XSS-Protection headers.
6.5.10Broken Access ControlSecurity HeadersAddress broken access control vulnerabilities. Validates Referrer-Policy, Permissions-Policy, and X-Frame-Options.
8.2.1Unique User IDsOpen PortsAssign unique identification to each person with computer access. Identifies exposed database ports with potential shared access.
8.3.1MFA for Remote AccessOpen PortsImplement MFA for all remote network access. Flags exposed RDP and remote access services without apparent MFA protection.
11.3.1External Vulnerability ScansAll ModulesPerform external vulnerability scans at least quarterly. ComplianceLayer provides continuous external scanning across 16 modules.

PCI DSS applies to cardholder data environments. These are PCI DSS-relevant technical controls observable from external scanning. Scope applicability depends on your specific environment.

How It Works

PCI DSS Evidence Collection in 3 Steps

01

Enter your domain

Submit your e-commerce or payment-processing domain. ComplianceLayer scans the external attack surface across 16 modules.

02

Review PCI mapping

Each finding maps to specific PCI DSS 4.0 requirements with pass, fail, or partial status and remediation guidance.

03

Export for your QSA

Download the compliance report as supporting evidence for your PCI DSS assessment or self-assessment questionnaire.

FAQ

Common questions

Is ComplianceLayer a PCI Approved Scanning Vendor (ASV)?

No. ComplianceLayer is not a PCI Council-approved ASV. However, the external scan results map directly to PCI DSS 4.0 requirements and provide evidence that supports your PCI compliance program. For official ASV scans required by Requirement 11.3.2, you need a PCI-approved vendor.

Which PCI DSS requirements does ComplianceLayer cover?

ComplianceLayer maps to Requirements 1 (network security), 2 (secure configurations), 4 (encryption), 5 (anti-phishing), 6 (secure development), 8 (access control), and 11 (vulnerability management). These are the requirements with externally observable technical controls.

How does PCI DSS 4.0 differ from 3.2.1?

PCI DSS 4.0 introduces new requirements including 6.4.3 (payment page script integrity via CSP), 11.6.1 (change detection), and 5.1.1 (anti-phishing mechanisms via DMARC). ComplianceLayer checks all of these through security header and email authentication scanning.

Can ComplianceLayer help with PCI DSS 4.0 Requirement 6.4.3?

Yes. Requirement 6.4.3 requires managing payment page scripts to ensure integrity. ComplianceLayer validates your Content-Security-Policy header, which is the primary technical control for meeting this requirement. We check for script-src directives and unsafe-inline usage.

Other compliance frameworks

Get started

Start scanning your first
domain in 60 seconds.

No credit card. No sales call. No setup. Free tier is permanent.

10 free scans per month, foreverAPI key in 30 secondsCancel anytime

All scans are passive and external — we never access your servers, install agents, or require credentials. View our security practices, live system status, or browse domain reports.