PCI DSS v4.0 Scope Assessment Wizard
Step-by-step CDE boundary scoping, SAQ type determination (A / A-EP / B / B-IP / C / C-VT / D), compensating controls assessment, v4.0 customised approach guidance, and a compliance Policy Mandate JSON. Client-side. Zero PII.
- [1] PCI Security Standards Council, PCI DSS v4.0, March 2022: pcisecuritystandards.org
- [2] PCI SSC, SAQ Instructions and Guidelines v4.0, March 2022
- [3] PCI SSC, Guidance for PCI DSS Scoping and Network Segmentation, v1.1
- [4] PCI SSC, Summary of Changes: PCI DSS v3.2.1 to v4.0, March 2022
- [5] Visa, Global Merchant Compliance Programme
- [6] Mastercard, Site Data Protection (SDP) Programme
This wizard applies PCI SSC scoping guidance and SAQ eligibility criteria from PCI DSS v4.0 to determine the applicable Self-Assessment Questionnaire type. It covers all seven SAQ types (A, A-EP, B, B-IP, C, C-VT, D) and flags when a QSA-led Report on Compliance is required for Level 1 merchants.
PCI DSS v4.0 (March 2022) key changes covered: Customised approach with Targeted Risk Analysis (Req 12.3.2), expanded MFA (Req 8.4.2), e-commerce script management (Req 6.4.3), payment page change-detection (Req 11.6.1), and TLS 1.1 prohibition (Req 4.2.1).
PCI SSC FAQ 1331, revised 4 August 2026, governs any use of SAQ eligibility criteria to set requirement applicability in a Report on Compliance, including marking Req 6.4.3 and Req 11.6.1 as out of scope. The approach now requires agreement with the Compliance Accepting Entity, usually the acquirer or the payment brand, and the QSA retains responsibility for validating scope and applicability.
⚠ This tool provides scoping guidance only and is not a substitute for a formal QSA assessment or legal advice. Verify with your QSA and acquiring bank before completing an SAQ or ROC.