Skip to content
Obligara

PCI DSS v4.0.1

PCI DSS, mapped to controls you actually run

The Payment Card Industry Data Security Standard, modelled as an internal self-assessment and readiness tool. 78 sub-requirements across the 12 PCI requirements are instantiated per workspace, a SAQ questionnaire derives its answers straight from your control state, and an Attestation of Compliance plus a cardholder-data-environment scope page keep the whole picture in one place.

PCI DSS · modulePCI DSS

78

sub-requirements

12

PCI requirements

SAQ + AoC

self-assessment

  • The 12 requirements, instantiated
  • SAQ questionnaire
  • Attestation of Compliance
  • CDE scope + AI readiness

What’s in the module

The 12 requirements, instantiated — not a checklist

78 sub-requirements across all twelve PCI requirements become first-class controls you implement and evidence, with the self-assessment derived from that work.

  • 01

    The 12 requirements, instantiated

    78 sub-requirements across all twelve PCI requirements, each becoming a first-class control you implement and evidence — not a checklist bolted on the side.

  • 02

    SAQ questionnaire

    The self-assessment questionnaire derives In-place / CCW / N-A / Not-in-place from your control state — a single source of truth, not a second spreadsheet to keep in sync.

  • 03

    Attestation of Compliance

    Track SAQ type, merchant level and the AoC verdict with its counts, so you know exactly where you stand before a QSA is involved.

  • 04

    CDE scope + AI readiness

    Define the cardholder-data environment and segmentation, mark out-of-scope requirements with justification, and let the AI readiness analyser verdict each requirement.

Self-assessment & attestation

From control state to a defensible SAQ

SAQ questionnaire

The self-assessment questionnaire derives In-place / CCW / N-A / Not-in-place directly from your control state — one source of truth, so your SAQ can’t drift from the work you’ve actually done.

Attestation of Compliance

Track SAQ type, merchant level and the AoC verdict with its counts, so you know precisely where you stand before a QSA-led Report on Compliance is on the table.

Cardholder-data-environment scope

Define the CDE and your segmentation, and mark out-of-scope requirements with justification — readiness then scores over the applicable requirements only.

AI readiness analyser

Per-requirement verdicts with cited evidence across all twelve requirements, persisted as snapshots so progress is visible over time.

Obligara is your internal self-assessment and readiness workspace. A Level-1 entity still needs a QSA-led Report on Compliance — this gets you there prepared, not surprised.

See your PCI DSS readiness

Scope your cardholder-data environment and watch the SAQ and readiness scorecard populate from your controls — live.