know.

CookbookWork and teamsNo. 36

PCI DSS readinesstwelve requirements, the evidence and the road to assessment

Recipe No. 36 · Work and teams

For: A compliance lead getting a small company ready for PCI DSS

You get: A document per requirement, evidence on a board, a plan to the QSA

Time: A day to set up, an hour a week

See it in know.sh

The readiness document: the twelve requirements shaded month by month as controls go in, and the plan back from the assessor’s February visit.

PCI DSS 2027No. 1

Tidewater TicketsPCI DSS v4.0.1 readiness

6 sections, 1,720 words, about 7 minutes, filed 6 July, revised 25 September, 2 highlights.

Our acquirer wants a Report on Compliance, so a QSA assesses us against PCI DSS v4.0.1 on site from 8 to 10 February 2027. It is our first assessment since the requirements that were future-dated in v4.0 became mandatory on 31 March 2025. Each requirement has its own document on this shelf.

Requirement 3 reached 100 per cent in August, when card numbers left the order database for good. Requirements 6, 10 and 11 are the long pole.

Sections

  1. 1Scope: what is in the cardholder data environmentDecision, keyThe checkout, the payment-page servers, the box-office terminals and the jump host. The order database is out.
  2. 2Owners by roleObservationHead of engineering, IT lead, box office manager and finance director; the compliance lead holds the register.
  3. 3Decisions: scope and compensating controlsDecision, key

and 3 more sections

Requirement 8 in its own document: each control with status and owner by role, and its evidence moving from to collect to reviewed.

PCI DSS 2027Requirement 8

1of 7

Status and evidence, September

Observation, key section, 1 note, 340 words

Owner: the IT lead, with the head of engineering on 8.4.2. Two gaps left, both on the plan.

The register the assessor will read: three scope decisions, a compensating control with its worksheet, and the payment-page scripts still open.

How it works

Walk into the assessment with the answers filed: a document per requirement with its controls, status and owner by role, evidence moving from requested to reviewed, a Gantt chart to the assessor’s visit, and every scope decision and compensating control written down with its reason.

  1. A document per requirement

    Ask your assistant for a shelf with one document per PCI DSS v4.0.1 requirement, one section per control you must meet, each with its owner by role and status.

  2. Track evidence on a board

    In each document, ask for a table element of the controls and a kanban element of evidence: to collect, collected, reviewed. Never paste card data or live secrets.

  3. Plan back from the assessment

    Give the assessor’s dates and ask for a Gantt chart: remediation, evidence, the penetration test and the readiness review, with the fixed dates marked critical.

  4. Record every scope decision

    Each time you shrink scope or rely on a compensating control, ask for a decisions entry with the reason. Your QSA reads the same register.

Try this prompt

Your assistant, connected to know.sh (Claude, ChatGPT or a local model):

On my know.sh shelf PCI DSS 2027, make one document per PCI DSS v4.0.1 principal requirement, titled with its number and name. In each, add a status section with a table element (requirement number, control, status, owner by role) and a kanban element of evidence: to collect, collected, reviewed. Use roles, never names, and file anything you are unsure applies to us as a Question.

Your assistant, connected to know.sh (Claude, ChatGPT or a local model):

Add a decisions entry to the scope register in my readiness document: box-office kiosks past vendor support, a compensating control for 6.3.3 until May 2027, with the controls I listed and the replacement as the alternative. Then mark kiosk isolation on the Gantt chart.

Made with

ShelfDocumentSectionElementsYour AI assistantRevisions