Information Security
Available nowPCI DSS · 4.0.1
PCI DSS 4.0.1 is the security standard for any organization that stores, processes, or transmits payment card data. Its requirements are prescriptive and non-negotiable if you touch cardholder data.
63
requirements tracked · part of the standard
Premium
Access
Add-on from $49/mo
Scope
How much of the standard Keel models
Keel models part of this standard, not all of it. A readiness score here is a percentage of the scope described below, not of the whole published standard, so read it that way, and tell your assessor the same.
What is not modeled: Modeled at the x.y sub-requirement level: 63 rows authored against a verified 259. The missing content is the defined requirements themselves (x.y.z and deeper), which is the level an assessor works. Roughly four times the current content, and every summary must be written from scratch - PCI DSS requirement text is (c) PCI Security Standards Council and is not reproduced, not in whole, not in part, and not as a lightly edited restatement of an official heading.
- Authored in Keel
- 63 requirements · part of the standard
- Defined by the standard
- 259 leaf requirements
Keel publishes this for every framework it ships, complete or not, so a readiness percentage can be read against a denominator you can see. Compare every framework
Who it is for
Who needs PCI DSS?
- Merchants and processors handling credit-card payments
- SaaS platforms that route or store cardholder data
- Teams scoping down with tokenization or a hosted payment page
What Keel does
How Keel helps with PCI DSS
- The PCI DSS 4.0.1 requirements as a trackable control set
- Evidence shared with your SOC 2 / ISO program so you are not duplicating work
- Clear visibility into which requirements are met, in progress, or a gap
Collect once, comply everywhere
PCI DSS shares canonical controls with FedRAMP Rev5 Class C, FedRAMP Rev5 Class D and NIST SP 800-53 and others in the catalog. Implement one of those controls and it counts toward every framework it satisfies, so adding PCI DSS rarely means starting from scratch.
- ISO/IEC 27001 shares canonical controls
- CIS Critical Security Controls shares canonical controls
- SOC 2 shares canonical controls
- SOX (Sarbanes-Oxley) Section 404 shares canonical controls
- NIST Cybersecurity Framework shares canonical controls
- NIST SP 800-53 shares canonical controls
- FedRAMP Rev5 Class B shares canonical controls
- FedRAMP Rev5 Class C shares canonical controls
- FedRAMP Rev5 Class D shares canonical controls
- FedRAMP 20x shares canonical controls
- FedRAMP Consolidated Rules shares canonical controls
- NIST SP 800-171 shares canonical controls
- HIPAA shares canonical controls
- GDPR shares canonical controls
- COPPA shares canonical controls
- Google Play Families no shared canonical controls
- Amazon Appstore Child-Directed Apps no shared canonical controls
- Apple App Store Kids Category no shared canonical controls
- PIPEDA shares canonical controls
- ISO 9001 shares canonical controls
- AI Governance Essentials no shared canonical controls
- ISO/IEC 42001 no shared canonical controls
- NIST AI Risk Management Framework no shared canonical controls
- EU AI Act no shared canonical controls
- ESG Essentials shares canonical controls
- US Employment Law - Federal Baseline shares canonical controls
A framework is lit when at least one canonical control satisfies both PCI DSS and that framework. Unlit means none of them do, which is an absence rather than a judgment about that standard. 19 of 26 are lit here.
Features that help with PCI DSS: Controls & crosswalk · Evidence management · AI Insights
Other frameworks: ISO/IEC 27001 · CIS Critical Security Controls · SOC 2 · SOX (Sarbanes-Oxley) Section 404 · NIST Cybersecurity Framework · NIST SP 800-53 · All frameworks