Compliance matrix
Payment Card Industry Data Security Standard 4.0
Global (card brand mandate) · Updated 2026-07-19
Applies to: Any organization that stores, processes, or transmits cardholder data, or can affect its security.
Vendor certification snapshot
PCI DSS status across the 48 vendors we track, read live from each profile.
9
Certified
1
Partial
38
Not stated
Certified / supported
Partial
Status is one signal, not a guarantee. Always confirm current certification scope directly with the vendor.
Requirements mapped to CIAM
Restrict access by need-to-know (Req. 7)
Access to cardholder data and CDE systems must be limited to the least privilege required.
CIAM controls
- Role-based access with default-deny
- Documented least-privilege roles
Evidence
- Role definitions
- Access review records
Ask the vendor
- Do you support default-deny, least-privilege RBAC for admin access?
Identify users and authenticate (Req. 8)
Every user needs a unique ID, and MFA is required for all access into the CDE, with phishing-resistant factors increasingly expected for administrative access.
CIAM controls
- Unique IDs, no shared or generic accounts
- MFA for all CDE access
- Strong / phishing-resistant authentication for admins
Evidence
- MFA enforcement configuration
- Account inventory showing unique IDs
Ask the vendor
- Can MFA be enforced for all users, and is WebAuthn/passkey supported?
- How are shared or system accounts prevented or controlled?
Manage application and system accounts (Req. 8.6)
Non-human accounts used by applications and services must be tightly controlled and their credentials protected.
CIAM controls
- Scoped, rotatable machine credentials
- No interactive login for service accounts
Evidence
- Credential rotation records
- Machine-account inventory
Ask the vendor
- How are application/service credentials scoped, rotated, and audited?
Log and monitor all access (Req. 10)
Access to the CDE and to identity systems must be logged, time-synchronized, and reviewed.
CIAM controls
- Audit logs of authentication and access events
- Log export to monitoring / SIEM
Evidence
- Audit log samples
- Log retention and review records
Ask the vendor
- What authentication events are logged, and can they stream to our SIEM?
Take this into procurement
Turn these requirements into vendor questions.
The vendor questions above map directly into an RFP or an evaluation checklist you can share with security and procurement.
Go deeper
FAQ
- Is my CIAM platform in PCI DSS scope?
- Only if it stores, processes, or transmits cardholder data, or can affect the security of the CDE. Most CIAM deployments keep card data out of the identity system, but the login path into CDE-adjacent admin tools still inherits Requirement 8's MFA and unique-ID obligations.
- What changed for authentication in PCI DSS 4.0?
- 4.0 expanded MFA to all access into the CDE (not just remote and admin), strengthened password requirements, and added explicit controls for application and system accounts. Phishing-resistant MFA for administrative access is the direction of travel.
Source
PCI DSS v4.0 (PCI Security Standards Council)
This matrix is practitioner guidance, not legal advice, and does not establish an attorney-client relationship. Confirm your obligations with qualified counsel. See our disclaimer.