Security Questionnaire Mapper
Framework

PCI DSS v4.0.1: what it anchors in a questionnaire

Asked by card merchants, banks and payment processors. A cardholder data question reaches past an ISO 27001 or SOC 2 report.

The text of this standard is not held in full here, so it is not quoted: each requirement carries a one-line statement of what it asks for, with its code and title, and the standard itself holds the wording. Ticked by default for bank and card merchant or payment processor customers.

Families anchored here

11 families, 12 clauses cited
FamilyClause
Multi-factor authentication8.4.2
Access provisioning and review7.2.4
Encryption at rest3.5.1
Encryption in transit4.2.1
Data retention and secure deletion3.2.1
Cardholder data and PCI DSS3.2.1 · 12.5.2
Logging and monitoring10.4.1
Vulnerability and patch management6.3.3 · 11.3.1
Penetration testing11.4.3
Incident response plan12.10.1
Subcontractors and subprocessors12.8.1

Every PCI DSS clause the register cites, with its text and evidence