Framework
PCI DSS v4.0.1: what it anchors in a questionnaire
Asked by card merchants, banks and payment processors. A cardholder data question reaches past an ISO 27001 or SOC 2 report.
The text of this standard is not held in full here, so it is not quoted: each requirement carries a one-line statement of what it asks for, with its code and title, and the standard itself holds the wording. Ticked by default for bank and card merchant or payment processor customers.
Families anchored here
11 families, 12 clauses citedEvery PCI DSS clause the register cites, with its text and evidence