CookbookWork and teamsNo. 36
PCI DSS readinesstwelve requirements, the evidence and the road to assessment
See it in know.sh
PCI DSS 2027No. 1
Tidewater TicketsPCI DSS v4.0.1 readiness
6 sections, 1,720 words, about 7 minutes, filed 6 July, revised 25 September, 2 highlights.
Our acquirer wants a Report on Compliance, so a QSA assesses us against PCI DSS v4.0.1 on site from 8 to 10 February 2027. It is our first assessment since the requirements that were future-dated in v4.0 became mandatory on 31 March 2025. Each requirement has its own document on this shelf.
Controls in place by requirement, per cent, May to September
| Requirement | May | Jun | Jul | Aug | Sep |
|---|---|---|---|---|---|
| 1 Network security controls | 40 | 55 | 70 | 85 | 90 |
| 2 Secure configurations | 30 | 45 | 60 | 70 | 80 |
| 3 Protect stored account data | 60 | 80 | 95 | 100 | 100 |
| 4 Cryptography in transit | 70 | 80 | 90 | 100 | 100 |
| 5 Malicious software | 50 | 60 | 75 | 80 | 85 |
| 6 Secure systems and software | 20 | 30 | 45 | 55 | 65 |
| 7 Access by need to know | 45 | 55 | 65 | 75 | 85 |
| 8 Identify and authenticate | 25 | 40 | 50 | 60 | 70 |
| 9 Physical access | 80 | 85 | 90 | 95 | 100 |
| 10 Log and monitor | 20 | 30 | 40 | 55 | 60 |
| 11 Test security regularly | 15 | 25 | 35 | 45 | 55 |
| 12 Policies and programmes | 35 | 45 | 60 | 70 | 80 |
Share of each requirement’s applicable controls marked In place in its document, at month end.
Controls in place by requirement, per cent, May to September
| Requirement | May | Jun | Jul | Aug | Sep |
|---|---|---|---|---|---|
| 1 Network security controls | 40 | 55 | 70 | 85 | 90 |
| 2 Secure configurations | 30 | 45 | 60 | 70 | 80 |
| 3 Protect stored account data | 60 | 80 | 95 | 100 | 100 |
| 4 Cryptography in transit | 70 | 80 | 90 | 100 | 100 |
| 5 Malicious software | 50 | 60 | 75 | 80 | 85 |
| 6 Secure systems and software | 20 | 30 | 45 | 55 | 65 |
| 7 Access by need to know | 45 | 55 | 65 | 75 | 85 |
| 8 Identify and authenticate | 25 | 40 | 50 | 60 | 70 |
| 9 Physical access | 80 | 85 | 90 | 95 | 100 |
| 10 Log and monitor | 20 | 30 | 40 | 55 | 60 |
| 11 Test security regularly | 15 | 25 | 35 | 45 | 55 |
| 12 Policies and programmes | 35 | 45 | 60 | 70 | 80 |
Columns: Month
Units: %
Shaded in five steps: 0–20%, 20–40%, 40–60%, 60–80% and 80%+.
Highest: 3 Protect stored account data, Aug, 100%. Lowest: 11 Test security regularly, May, 15%.
Source: Share of each requirement’s applicable controls marked In place in its document, at month end.
```element heatmap
{
"caption": "Controls in place by requirement, per cent, May to September",
"rowTitle": "Requirement",
"columnTitle": "Month",
"columns": [
{
"label": "May"
},
{
"label": "Jun"
},
{
"label": "Jul"
},
{
"label": "Aug"
},
{
"label": "Sep"
}
],
"rows": [
{
"label": "1 Network security controls",
"values": "40, 55, 70, 85, 90"
},
{
"label": "2 Secure configurations",
"values": "30, 45, 60, 70, 80"
},
{
"label": "3 Protect stored account data",
"values": "60, 80, 95, 100, 100"
},
{
"label": "4 Cryptography in transit",
"values": "70, 80, 90, 100, 100"
},
{
"label": "5 Malicious software",
"values": "50, 60, 75, 80, 85"
},
{
"label": "6 Secure systems and software",
"values": "20, 30, 45, 55, 65"
},
{
"label": "7 Access by need to know",
"values": "45, 55, 65, 75, 85"
},
{
"label": "8 Identify and authenticate",
"values": "25, 40, 50, 60, 70"
},
{
"label": "9 Physical access",
"values": "80, 85, 90, 95, 100"
},
{
"label": "10 Log and monitor",
"values": "20, 30, 40, 55, 60"
},
{
"label": "11 Test security regularly",
"values": "15, 25, 35, 45, 55"
},
{
"label": "12 Policies and programmes",
"values": "35, 45, 60, 70, 80"
}
],
"units": "%",
"steps": 5,
"range": "zero",
"source": "Share of each requirement’s applicable controls marked *In place* in its document, at month end."
}
```Requirement 3 reached 100 per cent in August, when card numbers left the order database for good. Requirements 6, 10 and 11 are the long pole.
From remediation to the assessor’s visit
Scope was confirmed on 7 September. Multi-factor authentication into the cardholder data environment runs six weeks from 21 September and is critical. The payment-page script inventory runs five weeks from 14 September; log alerting five weeks from 5 October; the kiosk compensating control three weeks from 12 October. Evidence collection runs from 1 October to 15 January. Penetration tests run two weeks from 16 November, the readiness review with the QSA is the week of 7 December, and the on-site assessment is 8 to 10 February 2027, critical.
| Task | Section | Starts | Ends | Status |
|---|---|---|---|---|
| Scope confirmed | Remediation | 2026-09-07 | 0 days | Done, milestone |
| MFA into the CDE | Remediation | 2026-09-21 | 6 weeks | Active, critical |
| Payment-page scripts | Remediation | 2026-09-14 | 5 weeks | Active |
| Log alerting | Remediation | 2026-10-05 | 5 weeks | |
| Kiosk isolation | Remediation | 2026-10-12 | 3 weeks | |
| Collect evidence | Evidence | 2026-10-01 | 2027-01-15 | |
| Penetration tests | Evidence | 2026-11-16 | 2 weeks | |
| Readiness review | Assessment | 2026-12-07 | 1 week | |
| QSA on site | Assessment | 2027-02-08 | 3 days |
Weeks start on Monday.
```element gantt
{
"caption": "From remediation to the assessor’s visit",
"description": "Scope was confirmed on 7 September. Multi-factor authentication into the cardholder data environment runs six weeks from 21 September and is critical. The payment-page script inventory runs five weeks from 14 September; log alerting five weeks from 5 October; the kiosk compensating control three weeks from 12 October. Evidence collection runs from 1 October to 15 January. Penetration tests run two weeks from 16 November, the readiness review with the QSA is the week of 7 December, and the on-site assessment is 8 to 10 February 2027, critical.",
"width": "wide",
"dateFormat": "YYYY-MM-DD",
"sections": [
{
"id": "fix",
"label": "Remediation"
},
{
"id": "prove",
"label": "Evidence"
},
{
"id": "assess",
"label": "Assessment"
}
],
"tasks": [
{
"id": "scope",
"label": "Scope confirmed",
"section": "fix",
"shape": "milestone",
"start": "2026-09-07",
"duration": "0d",
"status": "done"
},
{
"id": "mfa",
"label": "MFA into the CDE",
"section": "fix",
"shape": "bar",
"start": "2026-09-21",
"duration": "6w",
"status": "active",
"critical": true
},
{
"id": "scripts",
"label": "Payment-page scripts",
"section": "fix",
"shape": "bar",
"start": "2026-09-14",
"duration": "5w",
"status": "active"
},
{
"id": "logs",
"label": "Log alerting",
"section": "fix",
"shape": "bar",
"start": "2026-10-05",
"duration": "5w"
},
{
"id": "kiosk",
"label": "Kiosk isolation",
"section": "fix",
"shape": "bar",
"start": "2026-10-12",
"duration": "3w"
},
{
"id": "evidence",
"label": "Collect evidence",
"section": "prove",
"shape": "bar",
"start": "2026-10-01",
"end": "2027-01-15"
},
{
"id": "pentest",
"label": "Penetration tests",
"section": "prove",
"shape": "bar",
"start": "2026-11-16",
"duration": "2w"
},
{
"id": "ready",
"label": "Readiness review",
"section": "assess",
"shape": "bar",
"start": "2026-12-07",
"duration": "1w"
},
{
"id": "onsite",
"label": "QSA on site",
"section": "assess",
"shape": "bar",
"start": "2027-02-08",
"duration": "3d"
}
],
"axisFormat": "%b",
"tickInterval": "1month",
"weekStart": "monday",
"weekend": "saturday",
"today": "shown"
}
```Sections
- 1Scope: what is in the cardholder data environmentDecision, keyThe checkout, the payment-page servers, the box-office terminals and the jump host. The order database is out.
- 2Owners by roleObservationHead of engineering, IT lead, box office manager and finance director; the compliance lead holds the register.
- 3Decisions: scope and compensating controlsDecision, key
and 3 more sections
PCI DSS 2027Requirement 8
1of 7
Status and evidence, September
Observation, key section, 1 note, 340 words
Owner: the IT lead, with the head of engineering on 8.4.2. Two gaps left, both on the plan.
Requirement 8, the controls we track
| Requirement | Status | Owner |
|---|---|---|
| 8.2.1 A unique ID for every user | In place | IT lead |
| 8.2.2 Shared accounts only by documented exception | In place | IT lead |
| 8.2.6 Inactive accounts removed or disabled within 90 days | In place | IT lead |
| 8.3.6 Passwords of at least 12 characters | Partial | IT lead |
| 8.4.2 MFA for all access into the CDE | Gap | Engineering |
| 8.4.3 MFA for remote network access | In place | IT lead |
| 8.6.1 Interactive use of system accounts controlled | Gap | Engineering |
8.3.6, 8.4.2 and 8.6.1 were future-dated in v4.0 and have applied since 31 March 2025.
Requirement 8, the controls we track
| Requirement | Status | Owner |
|---|---|---|
| 8.2.1 A unique ID for every user | In place | IT lead |
| 8.2.2 Shared accounts only by documented exception | In place | IT lead |
| 8.2.6 Inactive accounts removed or disabled within 90 days | In place | IT lead |
| 8.3.6 Passwords of at least 12 characters | Partial | IT lead |
| 8.4.2 MFA for all access into the CDE | Gap | Engineering |
| 8.4.3 MFA for remote network access | In place | IT lead |
| 8.6.1 Interactive use of system accounts controlled | Gap | Engineering |
8.3.6, 8.4.2 and 8.6.1 were future-dated in v4.0 and have applied since 31 March 2025.
```element table
{
"caption": "Requirement 8, the controls we track",
"columns": [
{
"label": "Requirement",
"align": "left"
},
{
"label": "Status",
"align": "left"
},
{
"label": "Owner",
"align": "left"
}
],
"rows": [
[
"8.2.1 A unique ID for every user",
"In place",
"IT lead"
],
[
"8.2.2 Shared accounts only by documented exception",
"In place",
"IT lead"
],
[
"8.2.6 Inactive accounts removed or disabled within 90 days",
"In place",
"IT lead"
],
[
"8.3.6 Passwords of at least 12 characters",
"Partial",
"IT lead"
],
[
"8.4.2 MFA for all access into the CDE",
"Gap",
"Engineering"
],
[
"8.4.3 MFA for remote network access",
"In place",
"IT lead"
],
[
"8.6.1 Interactive use of system accounts controlled",
"Gap",
"Engineering"
]
],
"notes": "8.3.6, 8.4.2 and 8.6.1 were future-dated in v4.0 and have applied since 31 March 2025."
}
```Requirement 8 evidence, week of 21 September
To collect: jump host MFA settings for 8.4.2, high priority; the system account inventory for 8.6.1; the box-office password settings for 8.3.6. Collected: the user list for CDE systems, 8.2.1; the leavers report against access removals, 8.2.5. Reviewed: the VPN MFA settings, 8.4.3, and the inactive-account job log, 8.2.6.
- To collect
- Jump host MFA settings, assigned to Engineering, ticket 8.4.2, high priority
- System account inventory, assigned to Engineering, ticket 8.6.1
- Box-office password settings, assigned to IT lead, ticket 8.3.6
- Collected
- User list, CDE systems, assigned to IT lead, ticket 8.2.1
- Leavers against removals, assigned to IT lead, ticket 8.2.5
- Reviewed
- VPN MFA settings, assigned to IT lead, ticket 8.4.3
- Inactive-account job log, assigned to IT lead, ticket 8.2.6
```element kanban
{
"caption": "Requirement 8 evidence, week of 21 September",
"description": "To collect: jump host MFA settings for 8.4.2, high priority; the system account inventory for 8.6.1; the box-office password settings for 8.3.6. Collected: the user list for CDE systems, 8.2.1; the leavers report against access removals, 8.2.5. Reviewed: the VPN MFA settings, 8.4.3, and the inactive-account job log, 8.2.6.",
"columns": [
{
"label": "To collect",
"cards": [
{
"label": "Jump host MFA settings",
"ticket": "8.4.2",
"assigned": "Engineering",
"priority": "high"
},
{
"label": "System account inventory",
"ticket": "8.6.1",
"assigned": "Engineering"
},
{
"label": "Box-office password settings",
"ticket": "8.3.6",
"assigned": "IT lead"
}
]
},
{
"label": "Collected",
"cards": [
{
"label": "User list, CDE systems",
"ticket": "8.2.1",
"assigned": "IT lead"
},
{
"label": "Leavers against removals",
"ticket": "8.2.5",
"assigned": "IT lead"
}
]
},
{
"label": "Reviewed",
"cards": [
{
"label": "VPN MFA settings",
"ticket": "8.4.3",
"assigned": "IT lead"
},
{
"label": "Inactive-account job log",
"ticket": "8.2.6",
"assigned": "IT lead"
}
]
}
]
}
```Scope decisions and compensating controls
Card numbers in the order database
Store the processor’s tokens only; purge every stored card number
Takes the order database and its backups out of the cardholder data environment, and most of Requirement 3 with it.
Also considered Keep them, encrypted at rest
Phone bookings
Keypad entry masked by the telephony provider
Agents never hear or key a card number, so their desktops and the call recordings stay out of scope.
Also considered Agents key cards into a virtual terminal
Box-office kiosks past vendor support
A compensating control for 6.3.3 until replacement in May 2027
Replacements have a 16-week lead time. Kiosks move to their own network segment with application allow-listing and daily file-integrity checks, written up in the Appendix C worksheet.
Also considered Replace them before the assessment
Customized approach
The defined approach for every requirement
Our first assessment under v4.0.1; a customized control needs its own targeted risk analysis and more of the assessor’s time.
Payment-page scripts, 6.4.3 and 11.6.1
A script-monitoring service on the checkout page
Decide after the readiness review in December.
Also considered A strict Content Security Policy with reporting
Scope decisions and compensating controls
Card numbers in the order database
✓ Decided 14 July
Choice: Store the processor’s tokens only; purge every stored card number
Reason: Takes the order database and its backups out of the cardholder data environment, and most of Requirement 3 with it.
Also considered: Keep them, encrypted at rest
Phone bookings
✓ Decided 3 August
Choice: Keypad entry masked by the telephony provider
Reason: Agents never hear or key a card number, so their desktops and the call recordings stay out of scope.
Also considered: Agents key cards into a virtual terminal
Box-office kiosks past vendor support
✓ Decided 7 September
Choice: A compensating control for 6.3.3 until replacement in May 2027
Reason: Replacements have a 16-week lead time. Kiosks move to their own network segment with application allow-listing and daily file-integrity checks, written up in the Appendix C worksheet.
Also considered: Replace them before the assessment
Customized approach
✓ Decided 14 July
Choice: The defined approach for every requirement
Reason: Our first assessment under v4.0.1; a customized control needs its own targeted risk analysis and more of the assessor’s time.
Payment-page scripts, 6.4.3 and 11.6.1
○ Open
Choice: A script-monitoring service on the checkout page
Reason: Decide after the readiness review in December.
Also considered: A strict Content Security Policy with reporting
```element decisions
{
"caption": "Scope decisions and compensating controls",
"decisions": [
{
"title": "Card numbers in the order database",
"status": "decided",
"date": "2026-07-14",
"choice": "Store the processor’s tokens only; purge every stored card number",
"reason": "Takes the order database and its backups out of the cardholder data environment, and most of Requirement 3 with it.",
"alternatives": [
{
"option": "Keep them, encrypted at rest"
}
]
},
{
"title": "Phone bookings",
"status": "decided",
"date": "2026-08-03",
"choice": "Keypad entry masked by the telephony provider",
"reason": "Agents never hear or key a card number, so their desktops and the call recordings stay out of scope.",
"alternatives": [
{
"option": "Agents key cards into a virtual terminal"
}
]
},
{
"title": "Box-office kiosks past vendor support",
"status": "decided",
"date": "2026-09-07",
"choice": "A compensating control for 6.3.3 until replacement in May 2027",
"reason": "Replacements have a 16-week lead time. Kiosks move to their own network segment with application allow-listing and daily file-integrity checks, written up in the Appendix C worksheet.",
"alternatives": [
{
"option": "Replace them before the assessment"
}
]
},
{
"title": "Customized approach",
"status": "decided",
"date": "2026-07-14",
"choice": "The defined approach for every requirement",
"reason": "Our first assessment under v4.0.1; a customized control needs its own targeted risk analysis and more of the assessor’s time."
},
{
"title": "Payment-page scripts, 6.4.3 and 11.6.1",
"status": "open",
"choice": "A script-monitoring service on the checkout page",
"reason": "Decide after the readiness review in December.",
"alternatives": [
{
"option": "A strict Content Security Policy with reporting"
}
]
}
]
}
```How it works
Walk into the assessment with the answers filed: a document per requirement with its controls, status and owner by role, evidence moving from requested to reviewed, a Gantt chart to the assessor’s visit, and every scope decision and compensating control written down with its reason.