PCI DSS 4.0
Compliance Scanning
PCI DSS 4.0 introduces new requirements for payment page script integrity, anti-phishing mechanisms, and enhanced encryption standards. ComplianceLayer maps external scan findings to the specific PCI DSS 4.0 requirements your QSA evaluates.
PCI DSS 4.0 Requirements Mapped to Scan Modules
The following PCI DSS 4.0 requirements are verified through external scanning. Control IDs reference the PCI DSS v4.0 standard published by the PCI Security Standards Council.
| Requirement | Description | Scan Module | What We Check |
|---|---|---|---|
| 1.2.1 | Restrict Inbound/Outbound Traffic | Open Ports | Configure network security controls to restrict inbound and outbound traffic. Detects exposed services beyond what is necessary. |
| 1.3.1 | Restrict Inbound Traffic to CDE | Open Ports | Restrict inbound traffic to the cardholder data environment. Identifies exposed RDP, database, and administrative ports. |
| 2.2.4 | Configure System Security Parameters | Security Headers / Ports | Configure system security parameters to prevent misuse. Validates security header configuration and service exposure. |
| 2.2.5 | Enable Only Necessary Services | Open Ports / SSL | Enable only necessary services, protocols, and ports. Detects unnecessary services and deprecated TLS versions. |
| 4.1 | Strong Cryptography for Transmission | SSL/TLS | Use strong cryptography and security protocols to safeguard cardholder data in transit. Validates TLS 1.2+, cipher strength, and certificate validity. |
| 4.2.1 | Strong Cryptography Controls | SSL/TLS / Email | Implement strong cryptography whenever cardholder data is transmitted. Checks HTTPS enforcement, HSTS, SPF, DKIM, and DMARC. |
| 5.1.1 | Anti-Phishing Mechanisms | Implement anti-phishing mechanisms. Validates DMARC policy enforcement to prevent email domain spoofing. | |
| 6.4.3 | Payment Page Script Integrity | Security Headers | Manage all payment page scripts loaded and executed in the consumer browser. Validates Content-Security-Policy for script control. |
| 6.5.4 | Insecure Direct Object References | Security Headers | Address common coding vulnerabilities including insecure direct object references. Validates HSTS and access control headers. |
| 6.5.7 | Cross-Site Scripting (XSS) | Security Headers | Address XSS vulnerabilities. Validates CSP, X-Content-Type-Options, X-Frame-Options, and X-XSS-Protection headers. |
| 6.5.10 | Broken Access Control | Security Headers | Address broken access control vulnerabilities. Validates Referrer-Policy, Permissions-Policy, and X-Frame-Options. |
| 8.2.1 | Unique User IDs | Open Ports | Assign unique identification to each person with computer access. Identifies exposed database ports with potential shared access. |
| 8.3.1 | MFA for Remote Access | Open Ports | Implement MFA for all remote network access. Flags exposed RDP and remote access services without apparent MFA protection. |
| 11.3.1 | External Vulnerability Scans | All Modules | Perform external vulnerability scans at least quarterly. ComplianceLayer provides continuous external scanning across 16 modules. |
PCI DSS applies to cardholder data environments. These are PCI DSS-relevant technical controls observable from external scanning. Scope applicability depends on your specific environment.
PCI DSS Evidence Collection in 3 Steps
Enter your domain
Submit your e-commerce or payment-processing domain. ComplianceLayer scans the external attack surface across 16 modules.
Review PCI mapping
Each finding maps to specific PCI DSS 4.0 requirements with pass, fail, or partial status and remediation guidance.
Export for your QSA
Download the compliance report as supporting evidence for your PCI DSS assessment or self-assessment questionnaire.
Common questions
Is ComplianceLayer a PCI Approved Scanning Vendor (ASV)?
No. ComplianceLayer is not a PCI Council-approved ASV. However, the external scan results map directly to PCI DSS 4.0 requirements and provide evidence that supports your PCI compliance program. For official ASV scans required by Requirement 11.3.2, you need a PCI-approved vendor.
Which PCI DSS requirements does ComplianceLayer cover?
ComplianceLayer maps to Requirements 1 (network security), 2 (secure configurations), 4 (encryption), 5 (anti-phishing), 6 (secure development), 8 (access control), and 11 (vulnerability management). These are the requirements with externally observable technical controls.
How does PCI DSS 4.0 differ from 3.2.1?
PCI DSS 4.0 introduces new requirements including 6.4.3 (payment page script integrity via CSP), 11.6.1 (change detection), and 5.1.1 (anti-phishing mechanisms via DMARC). ComplianceLayer checks all of these through security header and email authentication scanning.
Can ComplianceLayer help with PCI DSS 4.0 Requirement 6.4.3?
Yes. Requirement 6.4.3 requires managing payment page scripts to ensure integrity. ComplianceLayer validates your Content-Security-Policy header, which is the primary technical control for meeting this requirement. We check for script-src directives and unsafe-inline usage.
Start scanning your first
domain in 60 seconds.
No credit card. No sales call. No setup. Free tier is permanent.
All scans are passive and external — we never access your servers, install agents, or require credentials. View our security practices, live system status, or browse domain reports.