PCI DSS v4.0.1 policy mapping: which policies cover the 12 requirements
Every 2026 assessment runs against PCI DSS v4.0.1 with all formerly future-dated requirements now mandatory. Requirement 12 demands documented policies — but in practice every one of the 12 requirement families tests policy content, from network rule lifecycles (Req 1) to log-review cadence (Req 10). Here is where each family's obligations should live in your policy set.
Requirement-family map
| Req | Family | Principal policies |
|---|---|---|
| 1 | Network security controls | Network Security (architecture, default-deny, segmentation, rule lifecycle); PCI Compliance policy for scope |
| 2 | Secure configurations | Asset & Media (baselines); Network Security; Virtualization for hypervisor estates |
| 3 | Protect stored account data | Cryptography & Key Management; Data Retention & Disposal (quarterly purge verification); Classification & Handling |
| 4 | Cryptography in transit | Cryptography; Network Security; Electronic Communications (PAN via end-user messaging prohibited) |
| 5 | Anti-malware | Malware Protection; Asset & Media for removable-media scanning |
| 6 | Secure systems & software | Vulnerability Management; Change Management; Secure Software Development for bespoke code; payment-page scripts via the PCI policy |
| 7 | Need-to-know access | Access Control incl. six-monthly recertification |
| 8 | Identify & authenticate | Access Control + Password — the full 8.2/8.3/8.4 parameter set (MFA, lockout, 12-character minimum) |
| 9 | Physical access | Physical & Environmental (incl. POI device inspection); Asset & Media for media controls |
| 10 | Log & monitor | Logging & Monitoring — 12-month retention, daily review, time sync, change detection |
| 11 | Security testing | Vulnerability Management — quarterly ASV scans, annual pen test, segmentation testing |
| 12 | Programme & governance | PCI DSS Compliance policy (charter, scoping, TPSPs, training, BAU) + core governance, risk, IR and vendor policies |
What no policy pack can write for you
Assessors will additionally require artifacts only your organisation can produce: current network and data-flow diagrams (1.2.3–1.2.4), per-platform configuration standards (2.2.x), the populated scope confirmation (12.5.2), quarterly ASV attestations, training records, and the executed SAQ/ROC and AOC. Good policies mandate each of these and templates can carry the recurring evidence — but the content is yours. Any vendor claiming otherwise is selling you an audit finding.
Shortcut: the MeerLock PCI Bundle (Professional pack + the PCI DSS Compliance Policy + ISMS Toolkit) provides requirement-level coverage of all 250 v4.0.1 requirements plus Appendices A1/A2, with the scoping workbook and periodic evidence register templated. See what's inside →
250 requirements, one bundle
PCI Bundle: €1,490 one-time, ISMS Toolkit included — or check which pack fits with the 3-question picker.
Find my pack →