PCI DSS compliance checklist
Jun 01, 2026
1 min read
Organizations that store, process or transmit cardholder data must comply with the Payment Card Industry Data Security Standard (PCIDSS). This checklist outlines core PCI DSS requirements to help you evaluate your compliance posture.
PCI DSS compliance requirements
- Install and maintain network security controls
Ensure firewalls and network controls are configured to protect cardholder data environments. - Apply secure configurations to all system components
Harden systems and remove default passwords and unnecessary services. - Protect stored cardholder data
Encrypt or otherwise secure stored payment data. - Encrypt transmission of cardholder data
Use strong cryptography when transmitting sensitive data over open networks. - Protect systems from malware
Deploy and maintain antimalware solutions where applicable. - Develop and maintain secure systems and applications
Apply patches, fix vulnerabilities and follow secure development practices. - Restrict access to cardholder data
Limit access based on business need to know. - Identify and authenticate access to system components
Use strong authentication methods, including multifactor authentication where required. - Restrict physical access to cardholder data
Control and monitor physical access to systems and environments. - Log and monitor all access to system components
Track and review logs to detect suspicious activity. - Test security systems and processes regularly
Conduct vulnerability scans, penetration testing and ongoing security testing. - Maintain a security policy
Establish, maintain and enforce a security policy that addresses PCI DSS requirements.
How to use this checklist
Use this checklist as a starting point to assess whether your organization meets core PCI DSS requirements. A full assessment may require deeper analysis depending on your environment, transaction volume and scope.
Need help with PCI DSS compliance?
Wipfli helps organizations assess and strengthen their PCI DSS compliance programs, from readiness assessments to ongoing monitoring and advisory support. Contact us to evaluate your compliance posture.
View as a PDF