WATCHUR6 // PCI DSS // AUDIT READINESS

The deadline already passed.
The only question is whether your scope holds.

PCI DSS v4.x is fully in effect — the 51 future-dated requirements went live March 31, 2025, with no grace period. If you take card payments, you're now either compliant or you're not, and your cardholder data environment scope decides how hard that is. We scope it tight and prove it.

Book a PCI DSS Strategy Call
PCI DSS v4.x 4 MERCHANT LEVELS SCOPE-FIRST VETERAN-LED

// WHY PCI DSS, WHY NOW

The bar moved in 2025. "Catching up" isn't a defense anymore.

MAR 2025

51 requirements went live

The future-dated v4.x controls — MFA on all CDE access, targeted risk analysis, payment-page script monitoring — became mandatory with no transition period after them.

LEVEL 1

Where a breach lands you

Any merchant that suffers a cardholder-data breach is bumped to Level 1 regardless of volume — a permanent step up to QSA-led validation. The cost of a gap isn't just a fine.

SCOPE

Decides the whole effort

Your cardholder data environment sets which SAQ applies, how many requirements are in play, and total cost. The most expensive PCI mistakes are scoping mistakes.

// A PROCESSOR ISN'T A PASS

Our processor handles the cards, so we're covered.
You still validate — scope is what changes, not the obligation.

Outsourcing payments shrinks your burden; it doesn't erase it. If you accept cards, you still validate — typically a Self-Assessment Questionnaire scoped to how you accept them — and you're responsible for the service providers in your flow. For e-commerce, the v4.x payment-page requirements apply to the page that hands the customer to payment even when the form is hosted elsewhere. "We use a processor" is a reason to scope carefully, not a reason to assume PCI doesn't apply.

// THE MERCHANT LEVEL PYRAMID

Four levels. One you never want to reach by accident.

Your transaction volume sets your level, and your level sets how you validate. Level 1 is the top tier — QSA-led, the most demanding — and a single breach lands any merchant there regardless of volume.

Level 1 >6M txns/yr · OR any breached merchant

The most demanding tier: an annual QSA-led Report on Compliance plus quarterly ASV scans. The part most merchants miss — a single cardholder-data breach promotes you to Level 1 regardless of volume, a permanent step up in validation burden. The three levels below validate more lightly, by volume.

// LEVEL 2

1–6M txns

SAQ or RoC at acquirer discretion, plus quarterly ASV scans.

// LEVEL 3

20k–1M e-comm

Mid-market online band — where the SAQ A vs A-EP choice matters most.

// LEVEL 4

<20k e-comm

Largest level by count — self-assess via SAQ plus quarterly ASV scans.

Volume sets your level — but scope sets your effort.

v4.x · v4.0 + v4.0.1, IN EFFECT Card Brands · ENFORCED VIA ACQUIRERS CDE Scope · DRIVES SAQ & COST

// THE PATH

From scope to sustained attestation.

PCI DSS is an annual cycle that starts with scope, not controls. The amber stages are where outside parties enter — the quarterly ASV scans and the formal validation (SAQ or QSA-led RoC).

Scope

CDE & Level

WK 1–3

Gap

Gap Assessment

WK 3–7

Remediate

Control Buildout

MO 2–5

ASV Scans

Quarterly Scans

QUARTERLY

Validate

SAQ / RoC

ANNUAL

Maintain

Annual Cycle

CONTINUOUS

Amber stages are where outside parties enter — the Approved Scanning Vendor's quarterly scans and your annual validation (SAQ or a QSA-led Report on Compliance). PCI is a yearly cycle, not a one-time pass.

// IS THIS YOU?

Three signs you have a PCI gap right now.

// 01 // STALE SAQ

Your last validation predates 2025

If your SAQ or RoC was completed before the March 2025 changes took effect, it doesn't reflect the controls now required — MFA on all CDE access, script monitoring, and the rest.

// 02 // SPRAWLING SCOPE

Card data flows through your network

If cardholder data touches general-purpose systems instead of a tightly segmented environment, your scope — and your cost and risk — is far bigger than it needs to be.

// 03 // E-COMMERCE

You take payments online

The v4.x payment-page rules hit e-commerce hardest. If you haven't addressed script monitoring and change detection on your checkout flow, that's an open gap today.

// WHAT WE DO

Scope it tight, close the gaps, and attest with confidence.

// Phase 01 · Scope

CDE Scoping & Level

We draw the cardholder data environment boundary and confirm your level and SAQ eligibility — the decision that drives effort and cost more than any control.

  • CDE boundary mapping and data-flow analysis
  • Segmentation strategy to minimize scope
  • Merchant level and SAQ-vs-RoC determination

// Phase 02 · Remediate

Gap Closure & v4.x Controls

We close the gaps against v4.x — including the requirements that tripped up most merchants in 2025 — with evidence an assessor will accept.

  • v4.0.1 gap assessment and remediation plan
  • MFA, targeted risk analysis, script monitoring
  • Quarterly ASV scan setup and management

// Phase 03 · Validate

Attestation & the Annual Cycle

We carry you through SAQ submission or QSA-led RoC and keep the program live, so each year's attestation is maintenance — not a fresh scramble.

  • SAQ completion or QSA / RoC coordination
  • Service provider and third-party management
  • Annual attestation maintenance and evidence

// A BREACH BUMPS YOU TO LEVEL 1

The cost of a PCI gap isn't a fine. It's a permanent step up.

Book a PCI DSS Strategy Call

// FREQUENTLY ASKED

The PCI DSS questions teams keep asking.

Which PCI DSS version applies now, and didn't a big deadline already pass?

The active standard is v4.x — versions 4.0 and 4.0.1. v3.2.1 retired March 31, 2024, and v4.0.1 (June 2024) was a clarifying revision with no new requirements. The deadline that matters has passed: of the 64 new requirements in v4.0, 51 became mandatory on March 31, 2025, with no transition period after.

So in 2026 the framing isn't "we still have time to prepare" — it's "are we actually compliant, and can we prove it?" If your controls or last validation predate the March 2025 changes (MFA on all CDE access, targeted risk analysis, payment-page script monitoring), you're likely carrying gaps right now.

What are the merchant levels, and how is my level decided?

Your level is set by annual transaction volume and decides how you validate. Level 1 is over 6 million transactions — and any merchant that suffers a cardholder-data breach is assigned Level 1 regardless of volume. It requires an annual QSA-led Report on Compliance plus quarterly ASV scans. Level 2 is ~1–6M; Level 3 ~20k–1M e-commerce; Level 4 under 20k e-commerce.

Levels 2 through 4 generally self-assess via the appropriate SAQ plus quarterly ASV scans, though an acquirer can require more at its discretion. The part most miss: a single breach promotes you to the most demanding tier permanently — so getting scoping and controls wrong costs more than a fine.

Why does scope matter so much for PCI DSS?

Scope is the single biggest lever, because PCI DSS applies to your Cardholder Data Environment (CDE) — systems that store, process, or transmit card data, plus anything connected to them. That environment's size decides which SAQ you're eligible for, how many requirements apply, and the total cost.

A tightly scoped merchant that fully outsources payment handling can qualify for the shortest SAQ; one where card data flows through general-purpose systems drags the whole network into scope. The most expensive PCI mistakes are scoping mistakes — under-scope and your validation is invalid; over-scope and you're securing systems that never needed to touch card data. Getting the CDE boundary right is where a good engagement earns its keep.

We outsource payments to a processor. Are we still on the hook?

Almost always yes — though outsourcing can dramatically reduce your burden. If you accept cards, you have PCI obligations even when a third party handles the data: you still validate (typically a SAQ scoped to how you accept payments) and you manage the service providers in your flow.

For e-commerce specifically, the v4.x payment-page requirements (script monitoring, change detection) apply to the page that hands the customer to payment even when the form is hosted by a processor — which surprised many merchants. Outsourcing well, with validated providers and redirect/iframe approaches, is one of the best ways to shrink scope — but "we use a processor" is a reason to scope carefully, not to assume PCI doesn't apply.

// THE NEXT MOVE

Find out where you really stand against v4.x.

Book a 30-minute PCI DSS strategy call with a WatchUr6 advisor. Bring how you accept payments, your rough transaction volume, your processor or gateway, and your last SAQ or RoC if you have one. You'll walk away with a clear read on your level, a tighter scope, and an honest list of the gaps the 2025 changes opened — whether you hire us or not.

Book a PCI DSS Strategy Call

SDVOSB · DVBE · SBE · CMAS #3-25-06-1018 · CAGE 9CQZ9 · VETERAN-LED