Frameworks · Global standards
PCI DSS compliance, run as a living system
The Payment Card Industry Data Security Standard is the card brands' security mandate for any entity that stores, processes or transmits cardholder data, organised into twelve requirement groups.
Who it applies to
Merchants, payment processors, acquirers and service providers handling cardholder data, with validation levels by transaction volume.
What it demands
Network & data protection
Segmentation, encryption of cardholder data, secure configurations.
Access control
Unique IDs, least privilege, MFA for cardholder data environment access.
Testing & monitoring
Quarterly scans, penetration tests, logging and monitoring.
Policy & programme
Security policy, awareness and incident response specific to cardholder data.
How Compli-Once runs it
- 1
The twelve requirement groups modelled with owners and evidence per requirement.
- 2
Quarterly scans and annual reviews tracked with expiry dates and renewal tasks.
- 3
Crosswalk to ISO 27001 reuses your ISMS evidence across overlapping requirements.
What you already satisfy
PCI DSS overlaps with frameworks you may already run. The crosswalk quantifies existing coverage on day one, before you plan a single task.
Implement once, satisfy many
In a representative demonstration environment, 61% of a newly adopted regulatory framework was already satisfied by the existing ISO 27001 programme.
Illustrative, computed live per tenant in the platform.
Frequently asked questions
Which PCI DSS version is supported?
The library carries PCI DSS v4.0, with the transition guidance from v3.2.1 mapped for organisations completing migration.
How are quarterly scans tracked?
As time-bound evidence with expiry dates. A renewal task is raised before each quarter closes, so the scan schedule never silently lapses.
Can segmentation evidence be managed in Compli-Once?
Yes. Segmentation test results and network documentation live in the vault, linked to the requirements they prove, with validity tracked.
Does Compli-Once replace a QSA?
No. Compli-Once runs the programme; the QSA assesses it. The auditor portal gives the QSA scoped access to evidence requests, which shortens the assessment considerably.
