info@nexoprivacy.com +254 768200243 Mon - Sat | 24 Hours
Home Policies PCI DSS v4.0
International · Global (Payment Card Industry)

PCI DSS v4.0

Mandatory technical and operational standard for any organisation that stores, processes or transmits cardholder data.

Quick facts

  • Code: PCI
  • Jurisdiction: Global (Payment Card Industry)
  • Region: International
  • Enforcement:
    Fines, increased transaction fees, loss of card-brand privileges
  • Official source

PCI DSS v4.0 introduces customised approaches, stronger authentication and continuous control validation. We deliver scoping, gap assessments, ASV-scan readiness, SAQ and RoC support.


Key principles & obligations

Build & maintain a secure network
Protect cardholder data
Vulnerability management
Strong access control
Regular monitoring
Information security policy
More in International

Related frameworks.

Global

ISO/IEC 27701 - Privacy Information Management

Extends ISO/IEC 27001 with privacy-specific controls - the de-facto international certification for a Privacy Information Management System (PIMS).

Read summary
Global

ISO/IEC 27001:2022 - Information Security

The international standard for an Information Security Management System (ISMS) - increasingly demanded by enterprise buyers worldwide.

Read summary
United States / Global

SOC 2 Type I & Type II

The AICPA Trust Services Criteria report demanded by enterprise buyers - a must-have for B2B SaaS.

Read summary