ZETLAN TECHNOLOGIES
Course Categories 172+
Cloud & Infrastructure 7
Networking 8
Virtualisation 5
IT Security 10
CyberSecurity & Mgmt 14
Software Development 16
Web Dev & Database 27
Data Science & AI 14
Mobile, Testing & Games 22
Design & Creative 49
Navigation
Home Business About Us Contact Us All Courses FAQ & Help
Contact Us
+91 8680961847 +91 8680961847 (WhatsApp) info@zetlantechnologies.com
Browse by Domain
Cloud & Infrastructure 7
Networking 8
Virtualisation 5
IT Security 10
CyberSecurity & Mgmt 14
Software Development 16
Web Dev & Database 27
Data Science & AI 14
Mobile, Testing & Games 22
Design & Creative 49
2000+ Courses · 15+ Technology Domains
Microsoft Cisco AWS EC-Council View All Courses
Home  /  ITSM Certifications  /  PCI DSS Certification
Payment Security Standard · PCI DSS v4.0

PCI DSS Certification
Payment Card Industry Security

The global payment card security standard governing how organisations protect cardholder data — covering all 12 requirements of PCI DSS v4.0 across network security, cardholder data protection, vulnerability management, access control, monitoring, and information security policy. Essential for any organisation that stores, processes, or transmits payment card data.

PCI DSS Payment Security Cardholder Data PCI SSC QSA ASV PCI DSS v4.0 Cryptography Tokenisation PCIP
Enroll Now
PCI DSS Certification
Payment Card Industry Security Standard
Standard VersionPCI DSS v4.0 (2022)
Governing BodyPCI Security Standards Council (PCI SSC)
Individual CertPCIP (PCI Professional) — Online
12 RequirementsAcross 6 Security Goals
Applies ToAll Visa / MC / Amex / Discover / JCB Merchants
StatusActive
6
Modules
12
Requirements
v4.0
Current
Global
Mandate
Certification Overview

What This Certification Validates

The Payment Card Industry Data Security Standard (PCI DSS) was established in 2004 by Visa, Mastercard, American Express, Discover, and JCB through the PCI Security Standards Council. PCI DSS v4.0 — released in 2022 and fully effective since March 2024 — defines 12 technical and operational requirements that all organisations must meet to protect cardholder data environments (CDEs), prevent payment card fraud, and maintain card brand compliance.

PCI DSS compliance is not optional — it is contractually mandated by card brands and acquiring banks for any merchant or service provider that stores, processes, or transmits cardholder data. With card payment fraud exceeding $33 billion globally and regulators tightening fintech oversight, PCI DSS expertise is essential for security professionals, compliance managers, and IT architects in banking, fintech, e-commerce, retail, hospitality, and healthcare.

What You Will Learn

Skills Covered

Design and implement secure network controls — firewalls, network segmentation, secure system configurations, and cardholder data environment (CDE) scoping

Protect stored cardholder data — apply data retention policies, masking, truncation, tokenisation, and strong cryptography for PAN and sensitive authentication data

Manage vulnerabilities and secure development — deploy anti-malware, apply secure coding practices, manage patches, and implement vulnerability scanning with ASVs

Implement access control — enforce least-privilege access, unique user IDs, multi-factor authentication (MFA), and restrict physical access to cardholder data

Monitor and log all access — implement centralised logging, intrusion detection systems (IDS/IPS), file integrity monitoring (FIM), and conduct regular penetration tests

Maintain an information security policy — document and communicate PCI DSS policies, manage security awareness training, and control third-party service provider compliance

Target Audience

Who Should Take This Course

Security analysts, information security managers, and CISOs at merchants, payment processors, and financial institutions who must achieve and maintain PCI DSS compliance

Network engineers, system administrators, and IT architects responsible for designing and maintaining CDE infrastructure that meets PCI DSS v4.0 technical requirements

Compliance officers, internal auditors, and risk managers in banking, fintech, e-commerce, retail, hospitality, or healthcare that handle payment card transactions

QSAs (Qualified Security Assessors) and ISAs (Internal Security Assessors) who assess and validate PCI DSS compliance on behalf of organisations or card brands

Certification Details
StandardPCI DSS v4.0 (2022)
Governing BodyPCI Security Standards Council
Individual CertPCIP — Online Proctored Exam
Requirements12 Requirements / 6 Goals
Applies ToMerchants, Processors, Service Providers
ComplianceAnnual — AOC / SAQ / ROC
Effectivev4.0 Fully Effective March 2024

Zetlan Technologies delivers PCI DSS training covering all 6 modules — across all 12 requirements of PCI DSS v4.0 — through live expert instruction with real-world payment security scenarios and full PCIP exam preparation support.

Course Curriculum

PCI DSS v4.0 — 6 Core Modules

Click any module to explore all topics covered — mapped to all 12 PCI DSS v4.0 requirements across the 6 security goals.

1
Build and Maintain a Secure Network and Systems
7 Topics
Requirement 1: Install and Maintain Network Security Controls — Firewalls, Routers, and Network Segmentation
Defining the Cardholder Data Environment (CDE) — Scoping, Network Diagrams, and Data Flows
Firewall Configuration Standards — Inbound/Outbound Rules, DMZ Design, and Review Procedures
Requirement 2: Apply Secure Configurations to All System Components
Eliminating Vendor-Supplied Default Passwords and Security Parameters
Hardening Standards — CIS Benchmarks and PCI DSS System Configuration Baselines
Managing System Components — Inventory, Configuration Management, and Secure Protocols Only
2
Protect Account Data
7 Topics
Requirement 3: Protect Stored Account Data — Data Retention, Purging, and Masking of PAN
What Must Not Be Stored — Full Track Data, CVV/CVC, PIN Blocks
Rendering PAN Unreadable — Tokenisation, Truncation, Hashing, and Strong Cryptography
Cryptographic Key Management — Key Generation, Distribution, Storage, Retirement, and Destruction
Requirement 4: Protect Cardholder Data with Strong Cryptography During Transmission
TLS Requirements — Accepted Protocol Versions and Cipher Suites for Data-in-Transit
Identifying and Inventorying All Locations Where PAN is Transmitted Across Open, Public Networks
3
Maintain a Vulnerability Management Programme
9 Topics
Requirement 5: Protect All Systems and Networks from Malicious Software
Anti-Malware Deployment — Scope, Configuration, Update Frequency, and Periodic Evaluation
Phishing and Social Engineering Awareness — PCI DSS v4.0 New Anti-Phishing Requirements
Requirement 6: Develop and Maintain Secure Systems and Software
Vulnerability Management Process — Security Patches, Risk Ranking, and Critical Patch Timelines
Secure Software Development Lifecycle (SSDLC) — Secure Coding Practices and Code Reviews
Web Application Security — WAF Requirements, OWASP Top 10, and Public-Facing Application Scanning
Software Change Management — Change Control and Testing Procedures
Bespoke and Custom Software Security Testing
4
Implement Strong Access Control Measures
10 Topics
Requirement 7: Restrict Access to System Components and Cardholder Data by Business Need to Know
Access Control Policy — Least Privilege, Default Deny-All, and Role-Based Access Control (RBAC)
Requirement 8: Identify Users and Authenticate Access to System Components
Unique User IDs — Prohibiting Shared and Generic Credentials in CDE
Password/Passphrase Requirements — Length, Complexity, History, and Lockout Policies
Multi-Factor Authentication (MFA) — Where Required Under PCI DSS v4.0 (All CDE Admin Access)
Service Account Management and Privileged Access Controls
Requirement 9: Restrict Physical Access to Cardholder Data
Physical Security Controls — Badge Access, CCTV, Visitor Logs, and Media Controls
Protecting Point of Interaction (POI) Devices — Inspection Procedures to Detect Tampering
5
Regularly Monitor and Test Networks
9 Topics
Requirement 10: Log and Monitor All Access to System Components and Cardholder Data
Centralised Audit Logging — What Events Must Be Logged and Retained for 12 Months
Log Management Systems — SIEM Integration, Log Integrity, and Review Procedures
Requirement 11: Test Security of Systems and Networks Regularly
Internal and External Vulnerability Scanning — ASV Requirements and Remediation Timelines
Penetration Testing — Scope, Methodology (NIST/PTES), Frequency, and Segmentation Testing
Intrusion Detection and Prevention Systems (IDS/IPS) — Deployment and Tuning
File Integrity Monitoring (FIM) — Critical File Change Detection
PCI DSS v4.0 — Authenticated Scanning and Expanded Penetration Test Requirements
6
Maintain an Information Security Policy
8 Topics
Requirement 12: Support Information Security with Organisational Policies and Programmes
Comprehensive Information Security Policy — Content Requirements, Annual Review, and Communication
Risk Assessment Process — Identifying and Managing Information Security Risks Annually
Security Awareness Training — Hiring, On-Boarding, Annual Training, and Specific Role-Based Training
Incident Response Plan — Roles, Responsibilities, Communication Tree, and Annual Testing
Managing Third-Party Service Providers (TPSPs) — Agreements, TPSP Lists, and Compliance Monitoring
Maintaining a List of Hardware and Software Technologies with Support End-Dates
PCI DSS Compliance Validation — SAQ Types, AOC, ROC, and QSA Engagement Guidance
FAQs

Frequently Asked Questions

What is PCI DSS and who must comply?
PCI DSS (Payment Card Industry Data Security Standard) is the mandatory security framework for any organisation that stores, processes, or transmits payment card data — including merchants, payment processors, acquirers, issuers, and service providers. It is governed by the PCI SSC and compliance is contractually enforced by card brands (Visa, Mastercard, Amex, Discover, JCB). Non-compliance can result in fines of $5,000–$100,000 per month, card brand penalties, and termination of payment acceptance.
What changed in PCI DSS v4.0 vs v3.2.1?
PCI DSS v4.0 (2022) introduced over 60 new requirements — now all fully mandatory since March 2024. Key changes include: customised implementation approach (risk-based alternative to prescriptive controls), mandatory MFA for all CDE administrative access, expanded anti-phishing requirements, authenticated vulnerability scanning, enhanced e-commerce skimming protections, and stronger password/passphrase requirements. It also introduced 12-character minimum passwords and expanded TPP monitoring requirements.
What individual certifications exist for PCI DSS?
The PCI SSC offers the PCIP (Payment Card Industry Professional) — an online proctored exam that validates individual knowledge of PCI DSS requirements. For assessors, the QSA (Qualified Security Assessor) credential is for consultants who assess compliance on behalf of organisations, and the ISA (Internal Security Assessor) is for employed security professionals who conduct internal assessments. Zetlan Technologies prepares students for the PCIP and ISA examinations.
What is the difference between SAQ, AOC, and ROC?
SAQ (Self-Assessment Questionnaire) — used by smaller merchants to self-validate compliance; 9 SAQ types based on how cards are processed. ROC (Report on Compliance) — completed by a QSA for large merchants (Level 1) and service providers; the most rigorous validation. AOC (Attestation of Compliance) — summary document signed by the assessed entity and (for ROC) the QSA confirming PCI DSS compliance status. All merchants must submit an AOC annually to their acquiring bank.
What does Zetlan Technologies offer for PCI DSS training?
Zetlan Technologies delivers PCI DSS training covering all 6 modules — mapped to all 12 PCI DSS v4.0 requirements across network security, cardholder data protection, vulnerability management, access control, monitoring and testing, and security policy — through live expert-led sessions with real-world payment security scenarios and full PCIP exam preparation support.
Get Started

Get PCI DSS Certified — Secure Every Payment, Every Transaction

From CDE scoping and firewall design to cryptography, MFA, penetration testing, and incident response — master all 12 PCI DSS v4.0 requirements with Zetlan Technologies.

Enroll Now Call Us
Zetlan Technologies
Online — Replies in minutes
👋 Hi! Welcome to Zetlan Technologies.

Interested in PCI DSS Payment Card Industry Data Security Standard Certification? Ask us anything!
Just now
Course Fee? Batch Timings? Exam Details
Open WhatsApp Chat
Your info is safe with us
💬 Chat with us!