Practitioner Track · Outline + Hands-on Labs

PCI DSS v4.0 — Payment Card Security Practitioner

From CDE scoping to QSA-ready evidence

The Payment Card Industry Data Security Standard v4.0 covered end-to-end for practitioners in India. Card ecosystem, scoping the Cardholder Data Environment, all 12 requirements, segmentation, SAQ selection, and evidence collection. Hands-on labs live in the 22-Day GRC Simulation.

5 chapters· ~10 hours reading· 5 matching hands-on labs

Course outline

Chapter 1

Card Ecosystem, CHD, and Scoping

Who's who in the card ecosystem (issuer, acquirer, brand, merchant, service provider), what counts as Cardholder Data (CHD) vs Sensitive Authentication Data (SAD), and how to identify the Cardholder Data Environment (CDE).

Key concepts

  • CHD: PAN, cardholder name, expiration date, service code
  • SAD: full magnetic stripe, CVV2/CID, PIN/PIN block (NEVER store post-authorisation)
  • CDE = any system that stores, processes, transmits, or is connected to CHD
  • Merchant levels 1-4 (based on transaction volume per brand)

Chapter 2

The 12 PCI DSS v4.0 Requirements in Depth

Detailed walkthrough of all 12 requirements: network controls (1), config (2), stored CHD protection (3), transmission encryption (4), malware (5), secure dev (6), access (7), identity (8), physical (9), logging (10), testing (11), and policy (12).

Key concepts

  • Req 3: Never store SAD; PAN storage requires rendering unreadable (encryption / tokenisation / truncation / hashing)
  • Req 4: TLS 1.2+ mandatory for CHD in transit
  • Req 8: Multi-factor authentication for ALL access into the CDE
  • Req 10: Log retention 12 months (3 months immediately available)
  • Req 11.3: External + internal pentests annually + after significant change
  • Customised approach (new in v4.0): risk-based alternative to defined approach

Chapter 3

Segmentation Strategy + Scope Reduction

Network segmentation as the single most-effective PCI cost-reduction lever. Techniques (VLANs, firewalls, separate VPCs, tokenisation), validation methods, and the segmentation pentest requirement.

Key concepts

  • Segmentation reduces PCI scope from 'entire enterprise' to a defined CDE
  • Validated segmentation requires annual pentest (semi-annual for service providers)
  • Tokenisation moves PAN out of your systems entirely = SAQ A eligibility
  • Common architectures: hosted payment page, iframe, direct-post, redirect

Chapter 4

SAQ Selection + Evidence Collection

Which Self-Assessment Questionnaire applies (A, A-EP, B, B-IP, C, C-VT, D, P2PE)? How to collect, organise, and version-control evidence for QSA review.

Key concepts

  • SAQ A: fully outsourced e-commerce (~24 questions)
  • SAQ A-EP: e-commerce with some page controls (~140 questions)
  • SAQ D: everyone else (~330 questions)
  • Evidence types: policy PDFs, screenshots, log samples, training records, scan results
  • QSA walkthrough: usually 3-5 days on-site or virtual

Chapter 5

Reporting — RoC, AoC, and Executive Summary

Report on Compliance (RoC), Attestation of Compliance (AoC), and how to communicate PCI status to the Board without over-claiming or under-selling.

Key concepts

  • RoC is the full evidence-backed report (QSA-authored)
  • AoC is the summary (goes to acquiring bank)
  • Compensating controls: valid when a requirement can't be met — must reference specific requirement
  • Board framing: contract loss + brand damage + regulatory action if non-compliant

Ready for the workshop?

The 22-Day GRC Practical Simulation is where you actually produce the deliverables — scope statements, SoAs, control tests, evidence packs. Full access is included with the 22-Day Program enrolment or Cohort 2026 candidature.