PCI DSS 4.0 became mandatory March 2024 and 4.0.1 issued June 2024. Target paid $202M after their breach; Block paid $175M to the CFPB. Most violations stem from gaps in three areas: scoping, segmentation evidence, and continuous monitoring. This checklist walks the 12 requirements in order with the controls 4.0.1 actually demands.
Drop your existing PCI DSS policy or upload a draft — ComplianceIQ runs the same checklist against your document and returns a 0–100 score, gap-by-gap with exact fixes and remediation copy.