PCI DSS v4.0.1 policy mapping: which policies cover the 12 requirements

Every 2026 assessment runs against PCI DSS v4.0.1 with all formerly future-dated requirements now mandatory. Requirement 12 demands documented policies — but in practice every one of the 12 requirement families tests policy content, from network rule lifecycles (Req 1) to log-review cadence (Req 10). Here is where each family's obligations should live in your policy set.

Requirement-family map

ReqFamilyPrincipal policies
1Network security controlsNetwork Security (architecture, default-deny, segmentation, rule lifecycle); PCI Compliance policy for scope
2Secure configurationsAsset & Media (baselines); Network Security; Virtualization for hypervisor estates
3Protect stored account dataCryptography & Key Management; Data Retention & Disposal (quarterly purge verification); Classification & Handling
4Cryptography in transitCryptography; Network Security; Electronic Communications (PAN via end-user messaging prohibited)
5Anti-malwareMalware Protection; Asset & Media for removable-media scanning
6Secure systems & softwareVulnerability Management; Change Management; Secure Software Development for bespoke code; payment-page scripts via the PCI policy
7Need-to-know accessAccess Control incl. six-monthly recertification
8Identify & authenticateAccess Control + Password — the full 8.2/8.3/8.4 parameter set (MFA, lockout, 12-character minimum)
9Physical accessPhysical & Environmental (incl. POI device inspection); Asset & Media for media controls
10Log & monitorLogging & Monitoring — 12-month retention, daily review, time sync, change detection
11Security testingVulnerability Management — quarterly ASV scans, annual pen test, segmentation testing
12Programme & governancePCI DSS Compliance policy (charter, scoping, TPSPs, training, BAU) + core governance, risk, IR and vendor policies

What no policy pack can write for you

Assessors will additionally require artifacts only your organisation can produce: current network and data-flow diagrams (1.2.3–1.2.4), per-platform configuration standards (2.2.x), the populated scope confirmation (12.5.2), quarterly ASV attestations, training records, and the executed SAQ/ROC and AOC. Good policies mandate each of these and templates can carry the recurring evidence — but the content is yours. Any vendor claiming otherwise is selling you an audit finding.

Shortcut: the MeerLock PCI Bundle (Professional pack + the PCI DSS Compliance Policy + ISMS Toolkit) provides requirement-level coverage of all 250 v4.0.1 requirements plus Appendices A1/A2, with the scoping workbook and periodic evidence register templated. See what's inside →

250 requirements, one bundle

PCI Bundle: €1,490 one-time, ISMS Toolkit included — or check which pack fits with the 3-question picker.

Find my pack →