PCI DSS 4.0.1 compliance software
Run your PCI DSS 4.0.1 self-assessment in one workspace — the full 697-control library, a guided SAQ workflow across all nine SAQ types, a versioned Scope Statement, quarterly ASV scan tracking, and the AOC your acquirer expects.
Free to start, no card · see pricing
What PCI DSS 4.0.1 requires
PCI DSS 4.0.1 is the current Payment Card Industry Data Security Standard. It governs how organizations that store, process, or transmit cardholder data protect it — across network security, encryption, access control, monitoring, and the Requirement 12 program-management duties (scope, targeted risk analysis, and the customized approach). Validation runs annually, either by self-assessment (SAQ) for merchants and service providers below the Level 1 threshold, or a QSA-led Report on Compliance for the largest merchants and most service providers.
Your one-stop shop for the PCI DSS SAQ
Everything the Self-Assessment Questionnaire actually needs, in one workspace, in the order your acquirer expects: confirm your merchant or service-provider level, define and version the cardholder data environment, pick the right SAQ type from your scope answers, walk every applicable requirement with evidence attached, log the quarterly ASV scan attestations, sign and export the Attestation of Compliance, and produce the bridge letters customers ask for between revalidations. No spreadsheet workbook from your acquirer to wrestle with. No separate scan tracker. No last-minute scramble before the renewal date. The same source of truth feeds next year's revalidation, so each cycle is a smaller delta and not a fresh start.
Do you need a QSA, or can you self-assess?
Most merchants and most service providers do not need a Qualified Security Assessor. Level 2, 3, and 4 merchants typically self-assess via SAQ; Level 1 merchants and most Level 1 service providers need a QSA-led Report on Compliance. The thresholds are set per card brand — broadly, more than 6 million card transactions a year (or any breach-driven designation) is the line above which a QSA becomes mandatory; below it, you can typically self-attest. SentinelPanda runs both paths in one workspace: the SAQ workflow walks self-assessors through A, A-EP, B, B-IP, C, C-VT, P2PE, D-Merchant, or D-Service Provider; the ROC path invites your QSA in as an auditor-layer seat to review evidence, approve controls, and request more information — without you re-keying anything into the QSA's own toolchain.
A guided PCI self-assessment, from scope to signed AOC
Most teams reach for an SAQ workbook from their acquirer and try to fill it in. SentinelPanda turns the SAQ into a workflow: confirm your merchant or service-provider level, define and version the cardholder data environment, pick the right SAQ from your scope answers, walk every applicable requirement with evidence attached, log the quarterly ASV scan attestations, and generate a signed Attestation of Compliance ready for the acquirer portal. Every step is tracked, dated, and exportable — no spreadsheet, no copy-paste, no last-minute scramble before revalidation.
Scope your cardholder data environment — then keep it under change control
Most PCI effort is wasted on systems that were never in scope. SentinelPanda starts with a guided scoping workflow that identifies your cardholder data environment (CDE), connected-to systems, and segmentation boundaries, then captures the result as a versioned Scope Statement under change control for Requirement 12.5.2. Re-confirm scope each year, diff it against last year, and show an assessor exactly what changed and why — instead of rebuilding a spreadsheet from memory.
Pick the right SAQ automatically — or run the full ROC path
Choosing the wrong Self-Assessment Questionnaire is a common, expensive mistake. SentinelPanda derives SAQ eligibility (A, A-EP, B, B-IP, C, C-VT, P2PE, D-Merchant, or D-Service Provider) directly from your scope answers, so you assess against the right control subset. Pursuing a Level 1 Report on Compliance instead? The same 697-control library drives a QSA-ready ROC and an Attestation of Compliance for merchants and service providers, generated from live assessment data — no separate workbook.
Track quarterly ASV scans alongside the SAQ
PCI requires four passing ASV scan attestations a year, not just four scans. SentinelPanda tracks ASV engagements alongside the SAQ workflow — scheduled scan dates, attached scan reports, the latest passing attestation per quarter, and remediation tickets for any failing finding. When the SAQ is finalised, the four quarterly attestations are already attached as supporting evidence; nothing has to be hunted down at signing time.
Targeted risk analysis and the customized approach, handled in-product
PCI DSS 4.0.1 lets you set your own frequency for many activities, but each one needs a documented Targeted Risk Analysis (Req 12.3.1), and the customized approach (Req 12.3.2) requires a controls matrix with evidence. SentinelPanda gives every TRA and customized-approach control a structured, reviewable record tied to the requirement it satisfies — and continuous evidence connectors keep that proof fresh between assessments. Because controls are cross-mapped, the same evidence also advances your ISO 27001 and SOC 2 programs, so PCI work is rarely single-use; and the append-only history means an assessor can trace exactly who changed what, and when, across the whole program year.
How SentinelPanda helps
Further reading
Practitioner-level guides on PCI DSS 4.0.1 from the SentinelPanda team.
PCI DSS 4.0.1 — frequently asked questions
Does SentinelPanda help with the PCI DSS self-assessment (SAQ)?
Yes — the SAQ is a first-class workflow. The workspace walks scope, SAQ type selection, every applicable requirement, ASV scan attestations, and the signed AOC, in the order your acquirer expects to see them.
Which SAQ types are supported?
All nine: A, A-EP, B, B-IP, C, C-VT, P2PE, D-Merchant, and D-Service Provider, with applicability auto-detected from your scope.
Does it also generate a PCI DSS Report on Compliance?
Yes — for Level 1 merchants and most service providers, the same 697-control library drives a QSA-ready ROC and AOC, generated from live assessment data.
How does it handle the customized approach and targeted risk analysis?
Each customized-approach control gets a structured controls matrix with linked evidence, and every Req 12.3.x flexible frequency is backed by a documented, reviewable Targeted Risk Analysis.
Can it track quarterly ASV scans?
Yes — ASV engagements, scheduled scan dates, attached scan reports, and the latest passing attestation per quarter all live alongside the SAQ workflow.
Can I reuse PCI evidence for other frameworks?
Yes — cross-framework mapping means an implemented PCI control automatically credits its equivalents in ISO 27001, SOC 2, and NIST CSF, so you do not collect the same evidence twice.