PCI DSS v4.0.1
Compliance Scanning
PCI DSS v4.0.1 introduces new requirements for payment page script integrity, anti-phishing mechanisms, and enhanced encryption standards. ComplianceLayer maps external scan findings to the specific PCI DSS v4.0.1 requirements your QSA evaluates.
PCI DSS v4.0.1 Requirements Mapped to Scan Modules
The following PCI DSS v4.0.1 requirements are assessed through external scanning. Control IDs reference the PCI DSS v4.0.1 standard published by the PCI Security Standards Council. ComplianceLayer is not affiliated with or endorsed by the PCI Security Standards Council.
| Requirement | Description | Scan Module | What We Check |
|---|---|---|---|
| 1.2.1 | Restrict Inbound/Outbound Traffic | Open Ports | Configure network security controls to restrict inbound and outbound traffic. Detects exposed services beyond what is necessary. |
| 1.3.1 | Restrict Inbound Traffic to CDE | Open Ports | Restrict inbound traffic to the cardholder data environment. Identifies exposed RDP, database, and administrative ports. |
| 2.2.4 | Configure System Security Parameters | Security Headers / Ports | Configure system security parameters to prevent misuse. Validates security header configuration and service exposure. |
| 2.2.5 | Enable Only Necessary Services | Open Ports / SSL | Enable only necessary services, protocols, and ports. Detects unnecessary services and deprecated TLS versions. |
| 4.2.1 | Strong Cryptography for Transmission | SSL/TLS / Email | Implement strong cryptography to safeguard cardholder data transmitted over open, public networks. Validates TLS 1.2+, cipher strength, certificate validity, HTTPS enforcement, HSTS, SPF, DKIM, and DMARC. |
| 5.4.1 | Anti-Phishing Mechanisms | Detect and protect personnel against phishing attacks. Validates DMARC policy enforcement to prevent email domain spoofing. | |
| 6.4.3 | Payment Page Script Integrity | Security Headers | Manage all payment page scripts loaded and executed in the consumer browser. Validates Content-Security-Policy for script control. |
| 6.2.4 | Common Software Attack Prevention | Security Headers | Software engineering techniques prevent common software attacks including XSS and access-control bypass. Validates CSP, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, and Permissions-Policy headers. |
| 8.2.1 | Unique User IDs | Open Ports | Assign unique identification to each person with computer access. Identifies exposed database ports with potential shared access. |
| 8.4.3 | MFA for Remote Access | Open Ports | Implement MFA for all remote network access originating from outside the network. Flags exposed RDP and remote access services without apparent MFA protection. |
| 11.3.2 | External Vulnerability Scans | All Modules | Perform external vulnerability scans at least once every three months. ComplianceLayer provides continuous external scanning across 15 scan modules. Note: the quarterly scans this requirement mandates must be performed by a PCI-approved scanning vendor (ASV), which ComplianceLayer is not. |
PCI DSS applies to cardholder data environments. These are PCI DSS-relevant technical controls observable from external scanning. Scope applicability depends on your specific environment. ComplianceLayer is not a PCI SSC Approved Scanning Vendor (ASV); official ASV scans require an approved vendor.
PCI DSS Evidence Collection in 3 Steps
Enter your domain
Submit your e-commerce or payment-processing domain. ComplianceLayer scans the external attack surface across 15 scan modules.
Review PCI mapping
Each finding maps to specific PCI DSS v4.0.1 requirements with pass, fail, or partial status and remediation guidance.
Export for your QSA
Download the compliance report as supporting evidence for your PCI DSS assessment or self-assessment questionnaire.
Common questions
Is ComplianceLayer a PCI Approved Scanning Vendor (ASV)?
No. ComplianceLayer is not a PCI Council-approved ASV. However, the external scan results map directly to PCI DSS v4.0.1 requirements and provide evidence that supports your PCI compliance program. For official ASV scans required by Requirement 11.3.2, you need a PCI-approved vendor.
Which PCI DSS requirements does ComplianceLayer cover?
ComplianceLayer maps to Requirements 1 (network security), 2 (secure configurations), 4 (encryption), 5 (anti-phishing), 6 (secure development), 8 (access control), and 11 (vulnerability management). These are the requirements with externally observable technical controls.
How does PCI DSS v4.0.1 differ from 3.2.1?
PCI DSS v4.0.1 introduces new requirements including 6.4.3 (payment page script integrity via CSP) and 5.4.1 (anti-phishing mechanisms, supported by DMARC). ComplianceLayer checks the externally observable parts of these through security header and email authentication scanning. Requirement 11.6.1 (payment page change detection) needs client-side tooling that an external scan cannot fully verify.
Can ComplianceLayer help with PCI DSS v4.0.1 Requirement 6.4.3?
It helps. Requirement 6.4.3 requires managing payment page scripts to ensure integrity. ComplianceLayer validates your Content-Security-Policy header, one of the technical controls relevant to this requirement. We check for script-src directives and unsafe-inline usage. Your assessor determines whether the requirement is met.
Start scanning your first
domain in 60 seconds.
No credit card. No sales call. No setup. The free tier is here to stay.
All scans are external and non-exploitative — we never access your servers, install agents, or require credentials. View our security practices, or live system status.