T226 · Cat-19 · Payment Schemes · PCI DSS

PCI DSS v4.0 Scope Assessment Wizard

Step-by-step CDE boundary scoping, SAQ type determination (A / A-EP / B / B-IP / C / C-VT / D), compensating controls assessment, v4.0 customised approach guidance, and a compliance Policy Mandate JSON. Client-side. Zero PII.

Compliant scope reduces PCI fines ($5K–$100K/month) and breach-event remediation cost. v1.0
Scope & reliance — 🔒 All inputs are processed locally in your browser. No data is transmitted. Do not enter real personal data — use synthetic or anonymised inputs only. Embedded rates, thresholds, and regulatory citations are static reference values that may age — verify against current primary sources and your own data before relying on any output for commercial, legal, or compliance decisions. Deterministic logic · no inference · zero PII · runs offline · CC BY 4.0.
Educational Use Only This tool provides a self-assessment / educational framework for internal planning purposes only. It is not a regulatory audit, legal advice, or a substitute for a formal compliance review by a qualified advisor. Verify all interpretations against the official source text and applicable RTS/ITS/guidance published by the relevant authority.
1
Organisation
2
Channels
3
Card Data
4
Architecture
Step 1: Organisation Profile
Visa / Mastercard transaction volume thresholds
Step 2: Payment Channels
Step 3: Card Data Handling
CHD = PAN, expiry date, cardholder name
SAD = CVV/CVV2, full magnetic stripe, PIN block
AoC = Attestation of Compliance. Req 12.8.4
Step 4: Network Architecture & Assessment Approach
Validated segmentation significantly reduces PCI DSS scope
Customised approach requires QSA validation of Targeted Risk Analysis
PCI DSS v4.0 Req 4.2.1: TLS 1.1 and below prohibited
Scope Assessment Results
Regulatory Citations
  • [1] PCI Security Standards Council, PCI DSS v4.0, March 2022: pcisecuritystandards.org
  • [2] PCI SSC, SAQ Instructions and Guidelines v4.0, March 2022
  • [3] PCI SSC, Guidance for PCI DSS Scoping and Network Segmentation, v1.1
  • [4] PCI SSC, Summary of Changes: PCI DSS v3.2.1 to v4.0, March 2022
  • [5] Visa, Global Merchant Compliance Programme
  • [6] Mastercard, Site Data Protection (SDP) Programme
About This Tool

This wizard applies PCI SSC scoping guidance and SAQ eligibility criteria from PCI DSS v4.0 to determine the applicable Self-Assessment Questionnaire type. It covers all seven SAQ types (A, A-EP, B, B-IP, C, C-VT, D) and flags when a QSA-led Report on Compliance is required for Level 1 merchants.

PCI DSS v4.0 (March 2022) key changes covered: Customised approach with Targeted Risk Analysis (Req 12.3.2), expanded MFA (Req 8.4.2), e-commerce script management (Req 6.4.3), payment page change-detection (Req 11.6.1), and TLS 1.1 prohibition (Req 4.2.1).

PCI SSC FAQ 1331, revised 4 August 2026, governs any use of SAQ eligibility criteria to set requirement applicability in a Report on Compliance, including marking Req 6.4.3 and Req 11.6.1 as out of scope. The approach now requires agreement with the Compliance Accepting Entity, usually the acquirer or the payment brand, and the QSA retains responsibility for validating scope and applicability.

⚠ This tool provides scoping guidance only and is not a substitute for a formal QSA assessment or legal advice. Verify with your QSA and acquiring bank before completing an SAQ or ROC.

✓