PCI DSS 4.0 compliance, without the spreadsheet sprawl.
Any business that touches cardholder data is in scope for PCI DSS. Uzado scopes, implements, scans, and maintains your PCI programme as a managed service.
PCI DSS 4.0 in plain language
The Payment Card Industry Data Security Standard governs every business that stores, processes, or transmits cardholder data. PCI DSS 4.0 is the current version, with future-dated requirements becoming mandatory through 2025.
PCI DSS organises around 12 requirements covering network security, data protection, vulnerability management, access control, monitoring, and security policy. The size of your control set depends on how you handle card data: SAQ A merchants outsource everything to a validated third party and have a small control set; SAQ D merchants store, process, or transmit cardholder data themselves and have the full control set.
PCI DSS 4.0 introduced the customised approach, expanded MFA requirements, formalised targeted risk analysis, and tightened script integrity controls. The practical implication: more documented analysis of how you meet the standard, and less ability to defer the operational controls until audit week.
The "we use Stripe so we're covered" trap
Concrete examples of in-scope businesses we see most often:
- SaaS companies taking subscription payments via a hosted checkout (typically SAQ A).
- E-commerce platforms handling cart-to-checkout flows (typically SAQ A or A-EP).
- B2B businesses storing tokenised card references for recurring billing (SAQ A or D depending on storage).
- Any business with a call centre that takes card payments by phone (typically SAQ C or D).
Using a payment processor like Stripe does not remove you from scope; it changes which SAQ you complete. Uzado picks the right SAQ based on how cardholder data actually moves through your environment.
A complete PCI DSS managed service
The cheapest PCI DSS programme is the one with the smallest cardholder data environment. Uzado redesigns flows and segmentation to remove systems from scope wherever possible.
Pick the right Self-Assessment Questionnaire (A, A-EP, B, C, D) based on how you actually handle card data. Most businesses get this wrong on the first pass and over-attest as a result.
Approved Scanning Vendor scans every 90 days against externally-facing systems in the cardholder data environment, run on Qualys with Uzado managing remediation.
Annual segmentation testing to confirm the cardholder data environment is isolated from the rest of the network. Required for merchants relying on segmentation to reduce scope.
Internal and external penetration testing on the in-scope environment, scoped to PCI DSS Requirement 11. Reports are written for the QSA who will read them next.
PCI DSS 4.0 expects ongoing controls, not point-in-time evidence. Uzado's Managed GRC keeps the programme operational between assessments.
A five-step PCI programme
Trace every flow that touches a primary account number. Identify systems, networks, and people in scope; remove what can be removed.
Map current state to the relevant SAQ or full DSS. Document the gaps with remediation cost and risk so leadership can prioritise.
Implement the missing controls: encryption, access management, MFA, logging, change control, incident response, and the rest of the 12 requirements.
Quarterly ASV scans, annual penetration tests, and segmentation testing run by Uzado against the in-scope environment.
Ongoing operation through Managed GRC. Annual attestation supported with continuous evidence. The next assessment is incremental.
Common PCI DSS questions
Do I need PCI DSS if I use Stripe?+
Probably yes, at the SAQ A level. Stripe handles the cardholder data, but if your e-commerce site or checkout integration touches card data even briefly (for example via a redirect or hosted iframe), the merchant is still responsible for an annual self-assessment. SAQ A is the simplest version and the one most Stripe-integrated businesses end up filing.
What's the difference between SAQ A and SAQ D?+
SAQ A is for merchants that fully outsource cardholder data handling to a PCI-validated third party. SAQ D applies to merchants that store, process, or transmit cardholder data themselves. The control set in SAQ D is roughly an order of magnitude larger. Most of the work in PCI scoping is finding out whether you can credibly file SAQ A instead of SAQ D.
How often do I need ASV scans?+
Quarterly external vulnerability scans by an Approved Scanning Vendor are required for any externally-facing systems in the cardholder data environment. Failed scans must be remediated and rescanned to a clean pass. Uzado runs these on Qualys, with remediation tracked through close.
What changed in PCI DSS 4.0?+
PCI DSS 4.0 introduced the customised approach (alternative ways to meet a requirement's intent), expanded MFA requirements to all access into the cardholder data environment, formalised targeted risk analysis, and tightened script integrity controls for e-commerce. The 4.0 future-dated requirements became mandatory in 2025.
Do I need penetration testing for PCI DSS?+
Yes. Requirement 11.4 requires internal and external penetration testing against the in-scope environment, at least annually and after significant change. Segmentation testing is also required at least annually for service providers and every two years for merchants. Uzado runs all three.
How does scope reduction work?+
Scope reduction means designing your environment so fewer systems handle cardholder data. Common moves: route all card flows through a PCI-validated third party, segment the cardholder data environment with strict network controls, and tokenise stored card data. Reducing scope is the single highest-leverage thing you can do for ongoing PCI cost.
Can Managed GRC handle PCI on an ongoing basis?+
Yes. Uzado's Managed GRC runs the controls, evidence, ASV scanning, and annual attestation as a continuous service. The annual SAQ or RoC submission becomes a packaging exercise rather than a project.
Need a PCI programme that actually runs?
Talk to Uzado. We will scope your cardholder data environment, pick the right SAQ, and run the controls year-round.

