The global payment card security standard governing how organisations protect cardholder data — covering all 12 requirements of PCI DSS v4.0 across network security, cardholder data protection, vulnerability management, access control, monitoring, and information security policy. Essential for any organisation that stores, processes, or transmits payment card data.
The Payment Card Industry Data Security Standard (PCI DSS) was established in 2004 by Visa, Mastercard, American Express, Discover, and JCB through the PCI Security Standards Council. PCI DSS v4.0 — released in 2022 and fully effective since March 2024 — defines 12 technical and operational requirements that all organisations must meet to protect cardholder data environments (CDEs), prevent payment card fraud, and maintain card brand compliance.
PCI DSS compliance is not optional — it is contractually mandated by card brands and acquiring banks for any merchant or service provider that stores, processes, or transmits cardholder data. With card payment fraud exceeding $33 billion globally and regulators tightening fintech oversight, PCI DSS expertise is essential for security professionals, compliance managers, and IT architects in banking, fintech, e-commerce, retail, hospitality, and healthcare.
Design and implement secure network controls — firewalls, network segmentation, secure system configurations, and cardholder data environment (CDE) scoping
Protect stored cardholder data — apply data retention policies, masking, truncation, tokenisation, and strong cryptography for PAN and sensitive authentication data
Manage vulnerabilities and secure development — deploy anti-malware, apply secure coding practices, manage patches, and implement vulnerability scanning with ASVs
Implement access control — enforce least-privilege access, unique user IDs, multi-factor authentication (MFA), and restrict physical access to cardholder data
Monitor and log all access — implement centralised logging, intrusion detection systems (IDS/IPS), file integrity monitoring (FIM), and conduct regular penetration tests
Maintain an information security policy — document and communicate PCI DSS policies, manage security awareness training, and control third-party service provider compliance
Security analysts, information security managers, and CISOs at merchants, payment processors, and financial institutions who must achieve and maintain PCI DSS compliance
Network engineers, system administrators, and IT architects responsible for designing and maintaining CDE infrastructure that meets PCI DSS v4.0 technical requirements
Compliance officers, internal auditors, and risk managers in banking, fintech, e-commerce, retail, hospitality, or healthcare that handle payment card transactions
QSAs (Qualified Security Assessors) and ISAs (Internal Security Assessors) who assess and validate PCI DSS compliance on behalf of organisations or card brands
Zetlan Technologies delivers PCI DSS training covering all 6 modules — across all 12 requirements of PCI DSS v4.0 — through live expert instruction with real-world payment security scenarios and full PCIP exam preparation support.
Click any module to explore all topics covered — mapped to all 12 PCI DSS v4.0 requirements across the 6 security goals.
From CDE scoping and firewall design to cryptography, MFA, penetration testing, and incident response — master all 12 PCI DSS v4.0 requirements with Zetlan Technologies.