Payment Security

PCI DSS v4 Readiness Checklist for SaaS and Fintech Teams

Published September 2026

Most SaaS and fintech teams meet PCI DSS the same way: a customer, acquirer, or partner asks for evidence, and the deadline arrives before the scope is understood. This checklist covers the readiness work that happens before a formal assessment begins, so the assessment itself is shorter and far less disruptive.

Readiness is not an assessment. Readiness identifies gaps and prepares evidence. Official validation, attestations, and certifications are performed by independent qualified assessors under the rules published by the PCI Security Standards Council.

1. Confirm which requirements apply

Start with your validation path rather than the control list. Whether you complete a self-assessment questionnaire or a Report on Compliance depends on your role in the payment flow, your transaction volume, and what your acquirer or payment brand requires. Ask your acquirer or partner directly, in writing, which validation type they expect and by when. The authoritative source for the standard itself, the SAQ types, and supporting guidance is the PCI SSC Document Library at pcisecuritystandards.org.

2. Map account data flows end to end

Scope follows data. Before reviewing a single control, document every path account data takes through your product and operations:

  • Where card data enters: checkout, hosted fields, APIs, file uploads, phone, support tooling.
  • Where it is transmitted, processed, or stored, including queues, logs, and backups.
  • Which third parties receive it, and which of them are PCI validated.
  • Which internal systems can reach those flows, including admin tooling and CI/CD.
  • Where sensitive authentication data could be captured accidentally, such as debug logs.

Teams that skip this step usually over-scope, then spend remediation budget on systems that never needed to be in scope at all.

3. Reduce scope before remediating

Scope reduction is the highest-leverage action available. Common moves include shifting to a hosted payment page or tokenized fields so raw card data never touches your servers, removing storage that exists only for convenience, segmenting the cardholder data environment from corporate and general production networks, and eliminating card data from support workflows and log pipelines. Every system removed from scope is a system you never have to evidence again.

4. Work through the control areas

PCI DSS v4 is organized into twelve requirements grouped under control objectives. A practical readiness pass covers:

  • Network and cloud security controls, including inbound and outbound restrictions.
  • Removal of vendor defaults and hardening of system components.
  • Protection of stored account data and encryption of data in transit over open networks.
  • Malware protection and secure software development practices.
  • Access control by business need to know, with unique IDs and strong authentication.
  • Physical access controls where they still apply to your environment.
  • Logging, monitoring, and the ability to reconstruct events.
  • Vulnerability scanning and penetration testing.
  • Security policy, risk analysis, and personnel practices.

For each one, the readiness question is not "do we do this" but "what artifact proves we did this, for the whole period, across every in-scope system."

5. Plan for the v4 changes that need lead time

Several v4 items are harder to retrofit than they look, so they belong early in the plan rather than in the final weeks:

  • Targeted risk analyses that justify the frequency of activities you set yourself.
  • Stronger authentication expectations, including multi-factor coverage into the environment.
  • Formalized roles and responsibilities documented per requirement.
  • Additional attention to payment page scripts and client-side integrity for e-commerce flows.
  • The customized approach option, which requires more documentation and assessor involvement than the defined approach.

Confirm the current text and any applicable dates against the standard published by the PCI SSC rather than secondhand summaries, including this one.

6. Build the evidence set as you go

Evidence is where readiness projects usually stall. For each in-scope requirement, collect the configuration exports, screenshots with dates, ticket records, scan and test reports, policy documents with review dates, and training records that support it. Keep one index that maps requirement to artifact to owner. An assessor who receives that index spends their time assessing rather than chasing files.

7. Manage third parties deliberately

Payment processors, hosting providers, and managed service vendors carry part of your obligations. Collect their current validation documentation, confirm exactly which requirements they cover on your behalf, and record which ones remain yours. A responsibility matrix agreed in advance prevents the common late discovery that neither side owns a control.

8. Rehearse the assessment

Before engaging an assessor, run an internal walkthrough of the highest-risk requirements: pull the evidence, have the owner explain it, and note anything that would not survive a follow-up question. Fixing those items ahead of time is considerably cheaper than fixing them during billed assessment hours.

A short pre-assessment checklist

  • Validation path confirmed in writing with the acquirer or partner.
  • Account data flows documented and reviewed by engineering.
  • Scope boundary defined, with segmentation verified.
  • Gap register complete, with an owner per gap.
  • Remediation sequenced by risk and contractual pressure.
  • Evidence index built and populated.
  • Third-party responsibilities documented.
  • Scans and penetration testing scheduled or complete.
  • Internal walkthrough finished and findings closed.

Where readiness ends

ControlSolid provides readiness, gap assessment, remediation support, and evidence preparation. Independent qualified assessors perform official attestations and certifications. Keeping that line clear protects the integrity of your validation and avoids surprises late in the process.

If a deadline is already in play, the fastest route is a scoped readiness review: request a PCI readiness review or read the full PCI readiness service overview.