PCI DSS v4.0.1
PCI DSS, mapped to controls you actually run
The Payment Card Industry Data Security Standard, modelled as an internal self-assessment and readiness tool. 78 sub-requirements across the 12 PCI requirements are instantiated per workspace, a SAQ questionnaire derives its answers straight from your control state, and an Attestation of Compliance plus a cardholder-data-environment scope page keep the whole picture in one place.
78
sub-requirements
12
PCI requirements
SAQ + AoC
self-assessment
- The 12 requirements, instantiated
- SAQ questionnaire
- Attestation of Compliance
- CDE scope + AI readiness
What’s in the module
The 12 requirements, instantiated — not a checklist
78 sub-requirements across all twelve PCI requirements become first-class controls you implement and evidence, with the self-assessment derived from that work.
- 01
The 12 requirements, instantiated
78 sub-requirements across all twelve PCI requirements, each becoming a first-class control you implement and evidence — not a checklist bolted on the side.
- 02
SAQ questionnaire
The self-assessment questionnaire derives In-place / CCW / N-A / Not-in-place from your control state — a single source of truth, not a second spreadsheet to keep in sync.
- 03
Attestation of Compliance
Track SAQ type, merchant level and the AoC verdict with its counts, so you know exactly where you stand before a QSA is involved.
- 04
CDE scope + AI readiness
Define the cardholder-data environment and segmentation, mark out-of-scope requirements with justification, and let the AI readiness analyser verdict each requirement.
Self-assessment & attestation
From control state to a defensible SAQ
SAQ questionnaire
The self-assessment questionnaire derives In-place / CCW / N-A / Not-in-place directly from your control state — one source of truth, so your SAQ can’t drift from the work you’ve actually done.
Attestation of Compliance
Track SAQ type, merchant level and the AoC verdict with its counts, so you know precisely where you stand before a QSA-led Report on Compliance is on the table.
Cardholder-data-environment scope
Define the CDE and your segmentation, and mark out-of-scope requirements with justification — readiness then scores over the applicable requirements only.
AI readiness analyser
Per-requirement verdicts with cited evidence across all twelve requirements, persisted as snapshots so progress is visible over time.
Obligara is your internal self-assessment and readiness workspace. A Level-1 entity still needs a QSA-led Report on Compliance — this gets you there prepared, not surprised.
See your PCI DSS readiness
Scope your cardholder-data environment and watch the SAQ and readiness scorecard populate from your controls — live.