Know where PAN exists
PAN and any associated cardholder name, expiration date, or service code must be mapped, minimized, protected, retained only as needed, and securely deleted.
Bring current PCI DSS requirements into continuous managed operation across a correctly scoped cardholder data environment.
View the control mappingWhere we contribute
PCI DSS applies to the people, processes, technologies, facilities, payment channels, providers, and evidence involved in storing, processing, or transmitting account data, as well as those affecting the security of the cardholder data environment. Network Box can operate substantial technical controls, but it does not certify compliance or replace a QSA, ISA, ASV, or the entity that accepts the client's validation.
Current standard status
Reviewed September 2, 2026PCI SSC published v4.0.1 as a limited revision in June 2024. PCI DSS v4.0 retired on December 31, 2024, and the future-dated v4.x requirements became effective on March 31, 2025.
Read PCI SSC's v4.0.1 announcement ↗Scope and applicability
A defensible PCI program begins by locating account data and identifying every person, process, technology, facility, service, and connection that can store, process, transmit, or affect it.
PAN and any associated cardholder name, expiration date, or service code must be mapped, minimized, protected, retained only as needed, and securely deleted.
Full track data, card verification codes or values, and PIN/PIN-block data generally may not be stored after authorization, even when encrypted.
Identity, security, administration, logging, virtualization, cloud control planes, software delivery, and connected systems may be in scope even without directly storing card data.
The applicable payment brand, acquirer, or compliance-accepting entity determines the required SAQ, AOC, ROC, ASV evidence, assessor involvement, and submission schedule.
Control mapping
The twelve requirement families below distinguish continuous managed-security contributions from the merchant or service provider responsibilities that remain necessary for assessment and validation.
| Framework area | Network Box contribution | Relevant services | Coverage |
|---|---|---|---|
| Managed boundaries, segmentation, secure connectivity, rule changes, inspection, and monitoring restrict traffic within scope. | Strong | ||
Detailed mapping2 mapping notes Define, configure, maintain, review, and document network security controls that restrict connections and traffic between trusted and untrusted networks and within the CDE. Network Box contributionStrongNetwork Box manages firewalls, SD-WAN, VPN, segmentation, traffic policy, IDS/IPS, controlled changes, configuration records, and continuous monitoring for subscribed systems. Assessed entity responsibilityClient responsibilityIdentify the complete CDE and connected systems, maintain current network and data-flow diagrams, approve business justifications, control all inbound and outbound traffic, review rule sets at least every six months, and validate controls outside scope. | |||
| Secure configurations, restricted administration, updates, change records, and monitoring protect managed services. | Partial | ||
Detailed mapping2 mapping notes Develop, apply, and maintain secure configuration standards for all system components and eliminate unnecessary functions, accounts, services, and insecure defaults. Network Box contributionPartialNetwork Box applies controlled configurations to subscribed services, restricts administration, manages supported updates, disables unnecessary managed functions, records changes, and monitors relevant conditions. Assessed entity responsibilityClient responsibilitySecurely configure and inventory every server, endpoint, payment device, network device, cloud resource, application, database, virtual platform, container, wireless system, and administrative tool outside Network Box management. | |||
| Segmentation, access restrictions, monitoring, and detection reduce exposure but do not replace storage minimization or cryptography. | Supporting | ||
Detailed mapping2 mapping notes Minimize account-data storage, prohibit retention of sensitive authentication data after authorization, render stored PAN unreadable, mask displays, and govern retention, deletion, cryptography, and keys. Network Box contributionSupportingNetwork Box can restrict access paths, segment storage environments, monitor connected systems, protect applications, and detect suspicious activity while reducing PAN exposure in managed telemetry. Assessed entity responsibilityClient responsibilityLocate every account-data store, eliminate prohibited data, minimize retention, encrypt or otherwise render PAN unreadable, mask displays, protect backups, prevent leakage into logs, securely delete records, and manage cryptographic keys. | |||
| Managed encrypted connectivity and gateway controls protect covered public-network paths and reveal unexpected communications. | Strong | ||
Detailed mapping2 mapping notes Use strong cryptography and secure protocols to protect cardholder data transmitted across open, public networks and prevent unprotected PAN transmission through end-user messaging technologies. Network Box contributionStrongNetwork Box provides VPN, encrypted site connectivity, secure remote-access paths, gateway policy, traffic inspection, and monitoring for configured managed paths. Assessed entity responsibilityClient responsibilityInventory every browser, application, API, wireless, email, messaging, file-transfer, remote-access, and third-party path; manage certificates and keys; prohibit insecure fallback; and validate end-to-end protection beyond managed tunnels. | |||
| Layered network, email, web, endpoint, intelligence, and SOC controls prevent and respond to malware. | Strong | ||
Detailed mapping2 mapping notes Deploy active, current, monitored anti-malware mechanisms on systems at risk and periodically evaluate systems considered not at risk. Network Box contributionStrongNetwork Box detects and blocks malicious files, content, traffic, and behavior, maintains managed protections, investigates alerts, and supports containment within the subscribed scope. Assessed entity responsibilityClient responsibilityEnsure every applicable in-scope system is covered, evaluate exclusions, prevent unauthorized disabling, retain logs, address removable media and unmanaged assets, and remediate affected systems. | |||
| Vulnerability findings, WAF, threat response, advisories, and controlled managed-service changes support secure operation. | Partial | ||
Detailed mapping2 mapping notes Identify and remediate vulnerabilities, securely develop and change software, protect public-facing applications, and control browser-executed payment-page scripts. Network Box contributionPartialNetwork Box identifies weaknesses, helps prioritize remediation, detects or blocks exploitation, can provide automated WAF protection, monitors production activity, and documents changes to its managed services. Assessed entity responsibilityClient responsibilityPatch critical vulnerabilities within required timelines, own secure development and code review, protect delivery pipelines, manage dependencies, inventory and validate payment-page scripts, cover every applicable application, and confirm the exact 6.4.2 and 6.4.3 implementations. | |||
| Network policy, segmentation, managed roles, secure remote access, and telemetry support least-privilege enforcement. | Partial | ||
Detailed mapping2 mapping notes Limit access to system components and cardholder data according to job function and least privilege, using systems that deny access unless expressly allowed. Network Box contributionPartialNetwork Box firewalls, segmentation, VPN policy, managed administrative roles, supported identity integration, and logging restrict network and service access within scope. Assessed entity responsibilityClient responsibilityDefine job roles, approve and periodically review access, manage privileged and service accounts, enforce application, database, operating-system, cloud, and data-layer permissions, and revoke access promptly. | |||
| Unique managed-service accounts, secure administration, supported MFA, directory integration, and logging protect managed access. | Partial | ||
Detailed mapping2 mapping notes Uniquely identify users, protect credentials, govern account lifecycle, and use MFA for access into the CDE and other scenarios required by PCI DSS. Network Box contributionPartialNetwork Box supports unique administrative accounts, secure remote administration, compatible MFA and directory integration, authentication records, monitoring, and alerting. Assessed entity responsibilityClient responsibilityImplement joiner-mover-leaver controls, strong authentication, complete CDE MFA coverage, credential protection, dormant-account review, permitted shared-account exceptions, and governance of application and service accounts across every in-scope technology. | |||
| Service and assurance information can support review of facilities used for Network Box-managed services. | Supporting | ||
Detailed mapping2 mapping notes Restrict physical access to cardholder data, systems, media, devices, sensitive areas, and point-of-interaction equipment and maintain the required records and inspections. Network Box contributionSupportingNetwork Box can provide available service and assurance information, while monitoring and segmentation may reduce some consequences of unauthorized physical access. Assessed entity responsibilityClient responsibilityControl facilities, visitors, wiring areas, media, backups, workstations, and payment devices; inspect terminals for tampering or substitution; authorize access; retain records; securely destroy media; and evaluate provider facilities. | |||
| Connected telemetry, correlation, continuous analyst review, alerting, investigations, dashboards, and reports support auditability. | Strong | ||
Detailed mapping2 mapping notes Record and examine activity in systems and account data, protect logs, review security events at required frequencies, investigate anomalies, synchronize time, and retain sufficient audit history. Network Box contributionStrongNetwork Box collects connected logs, monitors managed services, correlates events, investigates alerts, tracks silent sources, provides time-synchronized security telemetry, and produces dashboards and reports. Assessed entity responsibilityClient responsibilityEnable required records on every in-scope system, preserve user and event context, protect logs from alteration, investigate exceptions, continuously verify source coverage, retain at least 12 months with the most recent three months immediately available, and document recurring reviews. | |||
| Vulnerability assessment, monitoring, attack detection, change telemetry, WAF, and SOC investigations support recurring testing. | Partial | ||
Detailed mapping2 mapping notes Regularly scan, test, and validate security systems, applications, wireless exposure, intrusion detection, change detection, payment pages, and segmentation using required methods and qualified independence. Network Box contributionPartialNetwork Box can perform agreed vulnerability assessment, support authenticated scanning where included, monitor attacks and changes, supply boundary evidence, track findings, and assist with remediation and rescans. Assessed entity responsibilityClient responsibilityArrange required internal and external ASV scans, scans after significant changes, penetration and segmentation tests, wireless detection, payment-page tamper controls, qualified independence, passing results, remediation, and retesting across the complete PCI scope. | |||
| Responsibilities, reporting, intelligence, response support, awareness training, and operational records support the entity's program. | Partial | ||
Detailed mapping2 mapping notes Maintain governance, policies, risk analyses, scope confirmation, security awareness, incident response, service-provider oversight, and documented responsibility for protecting account data. Network Box contributionPartialNetwork Box can document its contracted responsibilities, provide threat and risk information, report security operations, train users when subscribed, support incident exercises, and furnish evidence and provider-status information. Assessed entity responsibilityClient responsibilityOwn policy and governance, annual scope confirmation, targeted risk analyses, role assignment, acceptable use, annual response testing, workforce training, TPSP inventory and monitoring, responsibility matrices, compliance submissions, and executive accountability. | |||
These mappings are illustrative and depend on deployment, configuration, service scope, the client environment, and evidence requirements. Strong, Partial, and Supporting describe Network Box's potential contribution, not a compliance conclusion.
Segmentation and scope
Network Box firewalls, routing, VLAN controls, SD-WAN policy, access restrictions, and monitoring can establish a strong segmentation foundation. The assessed entity must still map every account-data flow and security-impacting dependency, apply documented least-access paths, test segmentation at required frequencies and after applicable changes, and have the assessor confirm whether isolation is effective for PCI DSS scope reduction.
Architecture-specific validation
Several active v4.0.1 requirements depend on exact technical scope, implementation, cadence, independence, and testing evidence. General product capability is not enough.
An appropriately scoped, current, monitored, and actively blocking WAF can strongly support the required automated protection, but every applicable application and response process must be covered.
The entity must authorize browser-executed scripts, assure their integrity, and maintain a justified inventory. A traditional WAF alone does not establish these outcomes.
The mechanism must evaluate payment-page headers and content as received by the consumer's browser. Server-side monitoring alone may not satisfy the requirement.
Confirm complete in-scope coverage, required authenticated scanning, qualified independence, passing criteria, rescans, and scans after applicable significant changes.
A standard vulnerability report is not automatically an ASV scan. Required external compliance scans must use a PCI SSC Approved Scanning Vendor and achieve the required passing result.
Vulnerability scanning does not replace penetration testing. Required tests need compliant scope, methodology, independence, cadence, remediation, and retesting evidence.
Assessment evidence
Available evidence depends on deployed services, configured log sources, agreed scope, format, and retention period.
Coverage key
Network Box can directly deliver and operate a substantial part of this technical outcome when the relevant services are in scope.
Network Box contributes meaningful controls, but the requirement also depends on the client's systems, configuration, people, or processes.
Network Box provides useful security operations or evidence, but does not satisfy the requirement by itself.
This area primarily remains with the MSP and client, their assessors, or other qualified parties.
Shared responsibility
The merchant or service provider owns PCI applicability, payment channels and account-data flows, annual scope confirmation, stored-data protection, enterprise identity and physical controls, secure development, remediation, required scanning and penetration testing, third-party governance, incident obligations, evidence completeness, and accurate SAQ, AOC, ROC, or other validation submissions.
PCI DSS v4.0.1 FAQ
Bring current PCI DSS requirements into continuous managed operation across a correctly scoped cardholder data environment.
Network Box USA can operate managed technical safeguards, monitor the subscribed environment, investigate and escalate security activity, maintain managed configurations, and produce service evidence that may support applicable PCI DSS v4.0.1 requirements.
No. A managed security service can contribute controls, operations, and evidence, but it cannot guarantee compliance or replace the organization's governance, complete scope, legal interpretation, assessment, or formal certification and attestation work.
Use the mapping as a scoping and evidence-planning aid. Each row explains the requirement, the potential Network Box contribution, available evidence, the coverage level, and the work that remains with the organization.
Depending on the deployed services and agreed retention, evidence may include managed configurations, logs, alerts, incident records, vulnerability findings, change records, service reports, and recurring operational reviews. The assessor determines whether evidence is sufficient.
The merchant or service provider owns PCI applicability, payment channels and account-data flows, annual scope confirmation, stored-data protection, enterprise identity and physical controls, secure development, remediation, required scanning and penetration testing, third-party governance, incident obligations, evidence completeness, and accurate SAQ, AOC, ROC, or other validation submissions.
The information in this Compliance Center is provided for general informational purposes and does not constitute legal, regulatory, audit, or certification advice. Requirements vary by organization, jurisdiction, contract, data, and system scope. Network Box services can support selected technical and operational safeguards but do not by themselves establish compliance, certification, or attestation. Each organization remains responsible for determining its obligations, defining scope, implementing governance and non-technical controls, and obtaining advice or assessment from qualified legal, compliance, audit, or certification professionals.
Security stack review