The Short Answer
PCI DSS has 12 core requirements, organized under 6 goals. This structure has stayed the same across PCI DSS v3.2.1 and the current v4.0, only the depth and detail underneath each requirement has changed. See our PCI DSS compliance guide for the fundamentals, or our PCI DSS compliance cost breakdown by merchant level.
The 12 Requirements by Goal
| Goal | Requirements | Covers |
|---|---|---|
| 1. Build and Maintain a Secure Network and Systems | 1 – 2 | Network security controls, secure system configurations |
| 2. Protect Account Data | 3 – 4 | Stored data protection, encryption in transit |
| 3. Maintain a Vulnerability Management Program | 5 – 6 | Anti-malware, secure software development |
| 4. Implement Strong Access Control Measures | 7 – 9 | Need-to-know access, authentication, physical access restriction |
| 5. Regularly Monitor and Test Networks | 10 – 11 | Logging and monitoring, regular security testing |
| 6. Maintain an Information Security Policy | 12 | Policy, risk assessment, incident response, awareness training |
Goal 4 covers three requirements, the most of any goal; every other goal covers one or two. That weighting reflects how much of PCI DSS is genuinely about controlling who can reach cardholder data, not just protecting the data itself.
What Each Requirement Actually Covers
- Install and maintain network security controls — firewalls and network segmentation isolating the cardholder data environment.
- Apply secure configurations to all system components — hardened baselines, no default passwords or unnecessary services.
- Protect stored account data — encryption, truncation, or tokenization of stored cardholder data.
- Protect cardholder data with strong cryptography during transmission — TLS or equivalent for data in transit over open networks.
- Protect all systems and networks from malicious software — anti-malware deployed and kept current.
- Develop and maintain secure systems and software — secure development practices, patching, change control.
- Restrict access to system components and cardholder data by business need to know — least-privilege access control.
- Identify users and authenticate access to system components — unique IDs, multi-factor authentication for relevant access.
- Restrict physical access to cardholder data — physical security controls for systems and media.
- Log and monitor all access to system components and cardholder data — audit trails, log review, retention.
- Test security of systems and networks regularly — quarterly ASV scans, periodic penetration testing.
- Support information security with organizational policies and programs — policy, risk assessment, incident response, training.
v4.0 Kept the Structure, Added Depth
PCI DSS v4.0 did not change the number of requirements or goals. What it added is more prescriptive detail underneath them, expanded authentication requirements, more explicit encryption standards, and new emphasis on continuous monitoring, along with some reworded requirement titles to better reflect intent. If you're budgeting or planning around v4.0, the increase is in sub-requirement depth, not in requirement count.
Not sure which requirements actually apply to your scope?
Your SAQ type determines how many sub-requirements you attest to. We'll confirm yours before you start.
Get a Free QuoteRequirements vs Scope: Why the Count Doesn't Predict Your Workload
All 12 requirements exist regardless of merchant level, but how much work each one represents depends entirely on scope. A merchant routing card data through a fully tokenized processor has drastically fewer systems subject to requirements 1 through 11, since those systems never touch cardholder data. The requirement count is fixed; the number of systems you have to evidence against them isn't. See our guide to PCI DSS compliance cost for how scope reduction changes the budget.
Ready to map these requirements to your environment?
We've guided merchants across 40+ markets through PCI DSS scoping and remediation.
Talk to an Avantcert ExpertFrequently asked questions about PCI DSS requirements
Did PCI DSS v4.0 change the number of requirements?
No. v4.0 keeps the same 12 requirements under the same 6 goals as v3.2.1. What changed is the detail underneath them, new sub-requirements around authentication, encryption, and continuous monitoring, and some requirement titles were reworded, but the top-level structure of 12 requirements is unchanged.
Which PCI DSS requirement group has the most individual requirements?
Goal 4, Implement Strong Access Control Measures, with three: restricting access by business need to know, identifying and authenticating users, and restricting physical access to cardholder data. Every other goal covers one or two requirements.
Do all 12 requirements apply to every merchant regardless of level?
The requirements themselves apply universally, but the SAQ type determines how many sub-requirements you actually attest to. A merchant using a fully outsourced, tokenized payment flow completes a much shorter SAQ than one handling cardholder data directly, even though both are technically operating under the same 12-requirement standard.
Which requirement is most commonly missed by first-time merchants?
Requirement 11, regular security testing, particularly quarterly ASV scanning and periodic penetration testing. It's easy to implement the preventive controls in requirements 1 through 9 and overlook the ongoing testing obligation that requirement 11 imposes.
Is Requirement 12 just paperwork, or does it matter operationally?
It matters operationally. Requirement 12 covers the information security policy, risk assessment process, incident response plan, and security awareness training, the organizational scaffolding that makes the other 11 requirements sustainable rather than a one-time technical checklist.
How do the 12 requirements relate to reducing PCI scope?
Scope reduction, routing card data through a tokenized processor, doesn't remove any of the 12 requirements from existence, but it can remove entire systems from being in scope for them. Fewer in-scope systems means fewer requirements you have to evidence, which is why tokenization is the biggest lever for shrinking a PCI project.
About Avantcert. Avantcert is a compliance consultancy that has guided 3,000+ organisations across 40+ markets through PCI DSS scoping, remediation, and QSA-coordinated assessment. See our PCI DSS compliance service or request a free quote.