A PCI DSS gap assessment compares your current controls against the Payment Card Industry Data Security Standard and produces a prioritised remediation plan. It is the step that turns "we take card payments" into a clear, costed path to compliance - and the single biggest factor in the result is scope.
Start with scope, not controls
PCI DSS applies to the cardholder data environment (CDE): every system that stores, processes or transmits cardholder data, plus any connected system that could affect its security. Before assessing a single requirement:
- Map the full payment flow from card entry to authorisation and settlement.
- Identify every location where cardholder data is stored - including logs, backups, call recordings and spreadsheets.
- Document connected and security-impacting systems.
- Look for opportunities to reduce scope through segmentation, tokenisation or a redirect or iframe payment integration.
Scope reduction is the highest-return activity in any PCI programme. Outsourcing card capture to a compliant provider can move you from hundreds of applicable controls to a fraction of them.
The twelve requirements at a glance
- Install and maintain network security controls.
- Apply secure configurations to all system components.
- Protect stored account data.
- Protect cardholder data with strong cryptography during transmission.
- Protect all systems and networks from malicious software.
- Develop and maintain secure systems and software.
- Restrict access to system components and cardholder data by business need to know.
- Identify users and authenticate access to system components.
- Restrict physical access to cardholder data.
- Log and monitor all access to system components and cardholder data.
- Test security of systems and networks regularly.
- Support information security with organisational policies and programmes.
Running the assessment
- Confirm your validation level - driven by annual transaction volume and your acquirer, this determines whether you need a QSA-led Report on Compliance or a Self-Assessment Questionnaire.
- Select the correct SAQ type if self-assessing. Choosing the wrong SAQ invalidates the exercise, so match it to how you actually accept payments.
- Assess each requirement as in place, not in place, not applicable, or in place with a compensating control - with evidence for every judgement.
- Record compensating controls carefully. They need a documented constraint, a rigorous justification and equivalent risk mitigation.
- Prioritise remediation by risk and by effort - stored unencrypted card data first, always.
- Re-test and validate, then plan for annual revalidation and quarterly scanning.
Turn your gap assessment into a tracked remediation plan
GRC Copilot assesses each PCI DSS requirement against your evidence, highlights the gaps, and tracks remediation through to revalidation.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Findings that appear in almost every first assessment
- Cardholder data discovered outside the defined CDE - typically in logs, exports or email.
- Default vendor credentials or configurations still in place.
- Segmentation asserted but never penetration-tested.
- Missing or incomplete quarterly vulnerability scans by an Approved Scanning Vendor.
- Log retention shorter than required, or logs that nobody reviews.
- No documented, tested incident response plan for a card data breach.
Frequently asked questions
What is the difference between a gap assessment and a formal PCI audit?
A gap assessment is an internal readiness exercise with no formal outcome - it tells you where you stand. Formal validation is either a QSA-led Report on Compliance or a signed Self-Assessment Questionnaire submitted to your acquirer.
How do I know which SAQ applies to us?
It depends on how you accept card payments - fully outsourced e-commerce, card-present terminals, virtual terminals and so on each map to a different SAQ. Your acquirer confirms the requirement.
Does using a payment provider make us compliant automatically?
No, but it dramatically reduces scope. You remain responsible for how you integrate, who has access, and your own policies and vendor due diligence.
How often must PCI DSS be revalidated?
Annually, with quarterly external vulnerability scans by an Approved Scanning Vendor and ongoing operational requirements throughout the year.
Key takeaways
- Scope determines cost - reduce the cardholder data environment before assessing it.
- Choose the SAQ that matches how you truly accept payments.
- Compensating controls require documented constraints and equivalent mitigation.
- Stored, unencrypted card data is always the first thing to fix.