🇸🇦 Kingdom of Saudi Arabia 📞 +966 549983377 ✉ contact@pristinesaudi.com
24/7 SOC ACTIVE
🌐 عربي Client Portal
Home
About
Services
Solutions
Compliance
Industries
Insights
Home/Compliance/PCI DSS v4.0
PCI DSS v4.0 · Payment Card Security · QSA Certified · Saudi Arabia

Protect Every
Cardholder
Transaction.

Pristine InfoSolutions delivers end-to-end PCI DSS v4.0 compliance for Saudi merchants, payment processors, banks, fintechs, and e-commerce organisations — from initial scoping and gap assessment through to QSA-supported Report on Compliance (ROC) and Annual SAQ guidance. 100% compliance achievement rate.

100%Compliance Achieved
v4.0Current Standard
12Requirement Domains
QSACertified Assessors
PCI DSS v4.0 COMPLIANCE CONSOLE
ASSESSED
// 12 Requirements — Coverage Score
Req 1-2 — Network Security Controls
100%
Req 3-4 — Protect Account Data
100%
Req 5-6 — Vulnerability Management
100%
Req 7-9 — Access Control Measures
100%
Req 10-11 — Monitor & Test Networks
100%
Req 12 — Information Security Policy
100%
COMPLIANT
PCI DSS v4.0 Status
SAQ-D
Applicable SAQ Type
Next AOC / ROC DueMarch 2026 — On Track
PCI DSS v4.0
12 Requirements
QSA Assessment
SAQ-A · SAQ-B · SAQ-D
ROC — Report on Compliance
AOC — Attestation
Network Segmentation
Cardholder Data Environment
SAMA PCI Requirement
E-Commerce Security
Tokenisation
P2PE
3DS Authentication
ASV Scanning
PCI DSS v4.0
12 Requirements
QSA Assessment
SAQ-A · SAQ-B · SAQ-D
ROC — Report on Compliance
AOC — Attestation
Network Segmentation
Cardholder Data Environment
SAMA PCI Requirement
E-Commerce Security
Tokenisation
P2PE
3DS Authentication
ASV Scanning

The Global Standard Protecting Every Saudi Card Transaction

The Payment Card Industry Data Security Standard (PCI DSS) — maintained by the PCI Security Standards Council — is the mandatory security standard for any organisation that stores, processes, or transmits payment card data. Version 4.0 (March 2022, fully effective March 2025) introduces significant new requirements covering multi-factor authentication, customised implementation options, and targeted risk analysis.

In Saudi Arabia, PCI DSS compliance is mandatory not only through card brand rules (Visa, Mastercard, Mada) but is also explicitly referenced in the SAMA Cybersecurity Framework for financial institutions processing cardholder data. Non-compliant merchants face card acceptance suspension, fines from acquiring banks, and reputational damage following a breach.

  • PCI DSS v4.0 effective March 2024 — all transition requirements fully effective March 2025. v3.2.1 retired
  • 12 requirement domains — from network security and data protection through to security policy and testing
  • SAMA CSF Sub-domain 3.2.3 explicitly requires PCI DSS compliance for SAMA-supervised entities handling cardholder data
  • Mada (Saudi payment network) mandates PCI DSS for all participants in the Saudi domestic payment system
  • Pristine QSA-certified assessors conduct formal PCI DSS assessments — SAQ, ROC, and ongoing compliance support
Get Free PCI Scoping Call →
// PCI DSS v4.0 Key Facts
VersionPCI DSS v4.0 (March 2022)
Fully EffectiveMarch 2025 (v3.2.1 retired)
Requirements12 Requirement Domains
Sub-RequirementsHundreds of testable controls
New in v4.0Multi-Factor Auth expanded
New in v4.0Customised Implementation option
New in v4.0Targeted Risk Analysis required
Saudi DriverSAMA CSF Sub-domain 3.2.3
Saudi DriverMada network requirements
Pristine Rate100% Compliance Achievement

Any Organisation Touching Cardholder Data Must Comply

PCI DSS applies to any entity that stores, processes, or transmits payment account data — regardless of size, transaction volume, or geography. In Saudi Arabia, Mada and international card brands enforce compliance through acquiring banks.

🏦

Saudi Banks & Processors

Acquiring banks, issuing banks, and payment processors handling cardholder data. SAMA Sub-domain 3.2.3 mandated. Highest level of PCI DSS assessment required.

SAQ-D / ROC
💳

Fintechs & Payment Providers

SAMA-licensed payment service providers, digital wallets, BNPL operators, and money transfer businesses processing Saudi cardholder data.

SAQ-D / SAQ-A-EP
🛒

E-Commerce Merchants

Saudi e-commerce platforms accepting online card payments. Scope depends on payment page ownership — redirected payments (SAQ-A) vs hosted payment pages (SAQ-A-EP or SAQ-D).

SAQ-A / SAQ-A-EP
🏪

Retail Merchants

Physical retail merchants using point-of-sale terminals connected to Saudi payment networks including Mada. SAQ type depends on POS configuration and network connectivity.

SAQ-B / SAQ-C
☁️

Cloud & SaaS Providers

Technology companies whose platforms are used by merchants or processors to store, process, or transmit cardholder data — third-party service providers subject to PCI DSS.

SAQ-D (TPSP)
🔧

Managed Service Providers

IT and security service providers with access to cardholder data environments or the ability to affect its security — assessed as Third Party Service Providers (TPSPs).

SAQ-D (TPSP)
🏨

Hospitality & Travel

Hotels, airlines, and travel companies accepting card payments in Saudi Arabia — subject to Mada and international card brand compliance requirements.

SAQ-C / SAQ-D
🏥

Healthcare & Government

Saudi healthcare providers and government entities accepting card payments for services — increasingly subject to PCI DSS as digital payment adoption expands.

SAQ-B / SAQ-C

Complete Implementation Across All 12 Requirements

PCI DSS v4.0 organises its requirements into six control objectives spanning network security, data protection, access control, monitoring, and policy governance. Pristine implements every applicable control — with evidence packages formatted for QSA review.

Requirements 1–2: Build & Maintain Secure Networks

The network security foundation of PCI DSS — defining what constitutes your Cardholder Data Environment (CDE), implementing firewall controls to protect it, and eliminating vendor-supplied defaults. Network segmentation to reduce PCI scope is one of the highest-value activities Pristine performs for Saudi organisations.

  • Req 1 — Network Security Controls: Firewall rules protecting CDE inbound and outbound. All traffic to/from CDE documented, justified, and reviewed quarterly. Untrusted networks blocked at all entry points
  • Req 2 — Secure Configurations: All system defaults changed before deployment — default passwords, unnecessary services, and insecure protocols eliminated. Configuration standards maintained for every system component in the CDE
  • Scope Reduction (Critical): Pristine's network segmentation strategy can reduce PCI scope by 60-80% — dramatically lowering compliance cost and effort by isolating cardholder data from other systems
Discuss Scope Reduction →
Req 1–2 Coverage
✓ CDE SEGMENTED
Req 1.1 — NSC Policies
100%
Req 1.2 — CDE Network Seg.
100%
Req 1.3 — CDE Inbound/Outbound
100%
Req 2.1 — Secure Config Process
100%
Req 2.2 — System Config Standards
100%
✓ Pristine's network segmentation routinely reduces Saudi merchant PCI scope by 60–80%

Requirements 3–4: Protect Stored & Transmitted Account Data

The core data protection requirements — ensuring cardholder data is protected at rest (encryption, truncation, tokenisation) and in transit (TLS 1.2+ for all transmissions over open networks). PCI DSS v4.0 significantly strengthens cryptographic requirements with new key management controls.

  • Req 3 — Protect Stored Data: Primary Account Numbers (PAN) stored encrypted (AES-256 minimum), truncated, or tokenised. CVV/CVC never stored. Cardholder data discovery scanning. Key management programme compliant with PCI DSS v4.0 enhanced requirements
  • Req 4 — Protect Transmitted Data: TLS 1.2 or 1.3 enforced for all PAN transmissions over open/public networks. SSL and early TLS eliminated. Certificate management and expiry monitoring. Wireless transmission encryption
  • Tokenisation (Recommended): Pristine designs tokenisation architectures that remove PANs from merchant environments entirely — minimising PCI scope to only the token vault
Discuss Data Protection →
Req 3–4 Coverage
✓ ENCRYPTION VERIFIED
Req 3.3 — PAN Storage Encryption
100%
Req 3.5 — Key Management
100%
Req 3.7 — CHD Discovery Scans
100%
Req 4.2 — TLS 1.2+ Enforced
100%
Req 4.2.1 — Cert Inventory
100%

Requirements 5–6: Vulnerability Management Programme

Protecting CDE systems from malware, unpatched software, and web application vulnerabilities. PCI DSS v4.0 requires a new Targeted Risk Analysis (TRA) approach for many controls — replacing fixed timelines with risk-based frequency determination. Pristine implements compliant TRA processes and vulnerability management programmes across Saudi merchant and payment environments.

  • Req 5 — Malware Protection: Anti-malware deployed on all applicable CDE systems. Periodic evaluation of systems not at risk. Anti-phishing mechanism protecting users — new in PCI DSS v4.0
  • Req 6 — Secure Software Development: All payment software developed using PCI secure coding guidelines. OWASP Top 10 addressed in web-facing payment applications. Web Application Firewall (WAF) deployed for public-facing payment pages. Script management controls for payment page JavaScript — new in v4.0
  • New in v4.0 — Script Integrity: All scripts on payment pages must be authorised and integrity verified — targeting Magecart/e-skimming attacks targeting Saudi e-commerce checkout pages
Discuss Vulnerability Management →
Req 5–6 Coverage
✓ WAF + SCRIPT MGMT
Req 5.2 — Malware Protection
100%
Req 5.4 — Anti-Phishing (New v4)
100%
Req 6.3 — Security Vuln Process
100%
Req 6.4 — WAF on Payment Pages
100%
Req 6.4.3 — Script Mgmt (New v4)
100%

Requirements 7–9: Restrict Access to System Components

PCI DSS access control requirements — ensuring only authorised individuals and systems access cardholder data environments. PCI DSS v4.0 significantly strengthens MFA requirements — expanding phishing-resistant MFA to all access into the CDE, not just remote access.

  • Req 7 — Restrict CDE Access: Access to system components and cardholder data restricted to individuals whose job requires it. Least-privilege enforcement. Access control models documented and implemented
  • Req 8 — Identify Users & Authenticate: MFA now required for all access to the CDE — not just remote access. Passwords minimum 12 characters. Password manager acceptable for user-facing systems. Service account management strengthened
  • Req 9 — Restrict Physical Access: Physical security controls for CDE systems — server rooms, network devices, POS terminals. Media handling and destruction procedures. Point-of-Interaction device tampering inspection programme
Discuss Access Controls →
Req 7–9 Coverage
✓ MFA + LEAST PRIVILEGE
Req 7 — Least Privilege Access
100%
Req 8.4 — MFA (All CDE Access)
100%
Req 8.3 — Password Requirements
100%
Req 9.1 — Physical CDE Security
100%
Req 9.4 — POI Device Programme
100%

Requirements 10–12: Monitor, Test & Maintain Policy

Ongoing monitoring, testing, and information security policy requirements — ensuring the PCI DSS programme remains effective and responsive to the evolving threat landscape. Includes logging, ASV scanning, penetration testing, and the overarching information security policy framework.

  • Req 10 — Log & Monitor: Audit logs for all CDE components. Automated log review mechanisms — new in v4.0. Minimum 12-month log retention. Failure of critical security controls alerted immediately
  • Req 11 — Test Security: Quarterly ASV (Approved Scanning Vendor) external vulnerability scans. Annual penetration testing of CDE boundaries and internal CDE networks. Intrusion detection/prevention systems. Change-targeted analysis for new threats
  • Req 12 — Security Policy: Information security policy covering all PCI DSS requirements. Annual risk assessment. Targeted Risk Analysis (TRA) for all flexible requirements. Security awareness training including social engineering
Discuss Testing Programme →
Req 10–12 Coverage
✓ ASV + PENTEST
Req 10.2 — Audit Log Events
100%
Req 10.7 — Automated Log Review
100%
Req 11.3 — ASV External Scans
100%
Req 11.4 — Penetration Testing
100%
Req 12.3 — Risk Analysis (TRA)
100%

Complete PCI DSS Compliance Services

Every PCI DSS service Saudi merchants, banks, and payment organisations need — from initial scoping and gap assessment through to ongoing compliance maintenance.

🎯

PCI DSS Scoping & Gap Assessment

Define your Cardholder Data Environment (CDE), identify all in-scope systems, and assess current controls against all applicable v4.0 requirements. Scope reduction strategy delivered — often cutting scope by 60-80%.

ScopingCDEGap AssessmentSAQ Type
📋

Self-Assessment Questionnaire (SAQ)

Expert guidance through SAQ-A, SAQ-A-EP, SAQ-B, SAQ-B-IP, SAQ-C, and SAQ-D completion — the correct SAQ type selected and all questions answered with supporting evidence.

SAQ-ASAQ-DSAQ-CEvidenceAttestation
🔍

ASV External Vulnerability Scanning

Quarterly Approved Scanning Vendor (ASV) external vulnerability scans of all CDE-connected IP addresses — required for all SAQ types. Scan disputes managed and remediation guidance provided.

ASVQuarterly ScanExternalIP Scan
⚔️

PCI Penetration Testing

Annual internal and external penetration testing of CDE boundaries — aligned to PCI DSS Requirement 11.4. Segmentation testing validating scope reduction. CREST-qualified testers.

PentestSegmentation TestReq 11.4CREST
🏗️

Network Segmentation Design

Architecture design and implementation to isolate your CDE from other networks — reducing PCI scope and compliance cost. Firewall rule review and documentation aligned to Requirement 1.

SegmentationFirewallCDE IsolationScope Reduction
🔐

Tokenisation & Encryption

Replace stored PANs with tokens — removing cardholder data from your environment and dramatically reducing PCI scope. Encryption key management programme aligned to PCI DSS v4.0 enhanced requirements.

TokenisationEncryptionAES-256Key Management
📱

E-Commerce Payment Security

Secure payment page implementation — SAQ-A redirect configuration, script integrity controls for v4.0 compliance, Magecart/e-skimming protection, and 3D Secure (3DS) implementation.

E-CommerceSAQ-AScript IntegrityMagecart3DS
📊

QSA — Report on Compliance (ROC)

Full QSA-supported Report on Compliance for Level 1 merchants and service providers — on-site assessment, evidence review, and formal ROC and Attestation of Compliance (AOC) issuance.

QSAROCAOCLevel 1Formal Assessment
🔄

Ongoing PCI Compliance Maintenance

Year-round PCI DSS compliance management — quarterly ASV scans, quarterly access reviews, patch management tracking, security awareness training, and annual penetration testing coordination.

OngoingQuarterlyAnnualMaintenanceCompliance

PCI DSS Compliance Programmes

Three structured PCI DSS programmes for every Saudi organisation — from SAQ self-assessment support to full QSA-supported Level 1 ROC.

// Package 01
PCI SAQ

Self-Assessment Questionnaire support for smaller merchants — SAQ-A, SAQ-B, or SAQ-C with gap assessment, ASV scans, and expert guidance.

  • PCI DSS scoping & SAQ type selection
  • Full SAQ completion with evidence
  • Quarterly ASV external scan (year 1)
  • Network segmentation guidance
  • CDE firewall documentation
  • Req 12 risk assessment support
  • Attestation of Compliance (AOC) support
  • 1-week delivery for urgent deadlines
Enquire — SAQ →
// Package 03
PCI Enterprise

Full QSA-supported Report on Compliance for Level 1 merchants, acquiring banks, and payment processors requiring formal ROC and AOC.

  • All Professional features included
  • QSA on-site assessment support
  • Formal ROC documentation assistance
  • AOC issuance coordination
  • SAMA CSF PCI integration
  • Dedicated QSA programme manager
  • 3-year compliance maintenance plan
  • Board compliance reporting (Arabic)
Enquire — Enterprise →

Why Saudi Organisations Choose Pristine for PCI DSS

🎯

QSA-Certified Assessors

Pristine's PCI DSS practice includes QSA-certified assessors trained and qualified by the PCI Security Standards Council — providing formal assessment services that no unqualified firm can deliver.

📉

60-80% Scope Reduction

Most Saudi merchants significantly over-scope their PCI environments. Pristine's network segmentation strategy typically reduces PCI scope — and therefore cost — by 60-80%, often in the first engagement.

🇸🇦

SAMA CSF Integration

SAMA Sub-domain 3.2.3 requires PCI DSS for financial institutions handling cardholder data. Pristine integrates PCI DSS and SAMA compliance in a single programme — one evidence set satisfying both standards.

v4.0 Ready Today

PCI DSS v4.0 introduced significant new requirements — script integrity controls, expanded MFA, customised implementation, and targeted risk analysis. Pristine's methodology is fully v4.0 compliant from day one.

🔐

Tokenisation Expertise

Pristine designs and implements tokenisation architectures that remove cardholder data from merchant environments entirely — the most effective PCI scope reduction strategy available for Saudi e-commerce.

🏦

Saudi Payment Network Knowledge

Deep understanding of Saudi payment infrastructure — Mada, SPAN, and SADAD — and the specific PCI DSS implementation requirements applicable to Saudi payment network participants.

What Our PCI DSS Clients Say

★★★★★

Pristine reduced our PCI DSS scope from 340 systems to 47 through their network segmentation design. Our annual compliance cost dropped by 65% and our QSA assessment time halved. The SAMA integration meant we satisfied both PCI and SAMA Sub-domain 3.2.3 from one programme. Outstanding value.

KA
Khalid Al-Anazi
CISO, Saudi Commercial Bank
★★★★★

We had been trying to achieve PCI DSS SAQ-D compliance for 18 months. Pristine assessed our environment, identified that we qualified for SAQ-A through redirect-only payment processing, and completed our compliance in 3 weeks. The simplification saved us enormous effort and cost. Expert guidance.

LN
Lena Al-Nasser
CTO, Saudi E-Commerce Platform
★★★★★

Our PCI DSS v4.0 transition was blocked by the new script integrity requirements — we had 23 third-party scripts on our payment pages with no management process. Pristine implemented a complete script authorisation and integrity verification programme in 6 weeks. v4.0 compliant before the March 2025 deadline.

HM
Hamad Al-Mutairi
Head of Security, Saudi Fintech

PCI DSS v4.0 FAQs

PCI DSS v4.0 was published in March 2022 and became the only active standard in March 2024, with all new requirements fully effective from March 2025. Key changes include: expanded MFA requirements — now required for all access to the CDE, not just remote access; new script integrity controls for payment pages (targeting Magecart e-skimming attacks); Targeted Risk Analysis (TRA) replacing fixed timelines for many controls; customised implementation option for organisations that can demonstrate alternative control effectiveness; enhanced key management requirements; and new anti-phishing controls. Organisations still using v3.2.1 controls as their baseline are non-compliant.
SAQ type depends on how you accept card payments. SAQ-A: no electronic storage and outsourced processing to PCI-compliant third party with redirect-only payment pages. SAQ-A-EP: outsourced card processing but your website manages payment page elements. SAQ-B: imprint machines or standalone dial-out terminals only. SAQ-C: POS payment applications connected to internet. SAQ-D: all other merchants and service providers. Pristine's free scoping call determines the correct SAQ type — many Saudi organisations qualify for simpler SAQs than they realise, dramatically reducing compliance effort.
Yes — for any business accepting Visa, Mastercard, Mada, American Express, or other payment card brand transactions. Compliance is enforced through your acquiring bank. Non-compliance discovered during a breach investigation results in: fines from card brands (SAR 35,000–350,000+ per incident); card acceptance suspension; forensic investigation costs at your expense; and increased transaction fees. SAMA-supervised financial institutions face additional regulatory consequences under SAMA Sub-domain 3.2.3.
The most effective scope reduction strategies are: (1) Tokenisation — replace PANs with tokens throughout your systems, reducing scope to only the token vault; (2) Point-to-Point Encryption (P2PE) using a PCI SSC validated solution — encrypting card data at the point of interaction; (3) Redirect payment pages — using SAQ-A compliant redirect to a payment service provider rather than hosting payment page elements yourself; (4) Network segmentation — isolating CDE systems from other business networks. Pristine's scoping assessment identifies which strategies are applicable to your Saudi business model and calculates the scope reduction impact.
A Qualified Security Assessor (QSA) is an organisation certified by the PCI Security Standards Council to perform formal PCI DSS assessments. You need a QSA for: (1) Report on Compliance (ROC) — required for all Level 1 merchants (over 6 million Visa/Mastercard transactions annually) and all Level 1 service providers. You can complete an SAQ yourself for Level 2-4 merchants — but many organisations prefer QSA guidance for accurate SAQ completion. Pristine provides QSA-supported assessments and SAQ guidance across all merchant levels.
SAMA CSF Sub-domain 3.2.3 explicitly requires PCI DSS compliance for SAMA-supervised financial institutions that store, process, or transmit cardholder data — making PCI DSS a formal regulatory obligation, not just a contractual card brand requirement. SAMA examiners verify PCI DSS compliance status during supervisory examinations. Pristine integrates PCI DSS and SAMA compliance in a single programme — satisfying both standards simultaneously and collecting shared evidence once.

PCI DSS v4.0 Compliant.
Protect Every Transaction.

Request a free PCI DSS scoping call — our QSA-certified assessors will determine your correct SAQ type, estimate your compliance scope, and identify the fastest path to compliance at no cost.

📍 Riyadh, Saudi Arabia

Request Your Free Compliance Assessment

A senior Pristine specialist will contact you within 4 business hours. All assessments are conducted under NDA.

🔒 Data processed within Saudi Arabia · PDPL compliant · Response within 4 business hours

Explore Related Pristine Services

🏦
SAMA Framework
SAMA Sub-domain 3.2.3 requires PCI DSS for financial institutions processing cardholder data.
→ Explore
🔍
Penetration Testing
PCI DSS Req 11.4 mandates annual penetration testing of CDE boundaries.
→ Explore
📋
GRC & Compliance
PCI DSS integrated with SAMA, NCA ECC, and ISO 27001 in a unified programme.
→ Explore
☁️
Cloud Security
Cloud-hosted CDE environments scoped and secured against PCI DSS cloud requirements.
→ Explore