PCI DSS v4.0.1 document library
The PCI Security Standards Council's official library for the standard and supporting material.
Open the PCI SSC document libraryNOTE—02
The honest first question is not which badge to put on a proposal. It is which requirement actually applies, which control outcome the buyer must evidence, and which testing method can support it.
Where PCI DSS applies, Requirement 11.4 defines penetration-testing methodology, scope, independence, recurrence, significant-change testing, correction, and repeat testing. The engagement must still confirm the cardholder-data environment and the exact applicable elements; a tester does not certify PCI compliance merely by delivering a test.
ISO/IEC 27001 is an outcome- and risk-based management-system standard. An independent test can support vulnerability-management and security-testing controls selected in the Statement of Applicability, but the standard does not impose a universal annual penetration test on every certified organization.
SOC 2 is an attestation examination, not a certification and not a blanket pentest mandate. Testing becomes specifically relevant through the entity's commitments and control description, the auditor's judgment, a customer contract, or another adopted requirement.
Use ‘designed to address applicable requirements’ only after applicability is confirmed; ‘supports readiness or control evidence’ for outcome frameworks; and ‘mapped to’ for voluntary methods and taxonomies. Never imply endorsement, certification, or guaranteed compliance.
Reviewed 15 August 2026. Version basis: PCI DSS v4.0.1; ISO/IEC 27001:2022; and the AICPA Trust Services Criteria, using the 2017 criteria with points of focus revised in 2022. Applicability owner: the client's authorized compliance owner confirms which requirements and controls apply. Redline maps agreed testing evidence to that scope; it does not certify or guarantee compliance.
The PCI Security Standards Council's official library for the standard and supporting material.
Open the PCI SSC document libraryPCI SSC's official publication notice for the limited revision to PCI DSS v4.0.
Open the PCI SSC publication noticeISO's official overview of the information security management systems standard.
Open the ISO/IEC 27001 overviewAICPA's official criteria document, including the points of focus revised in 2022.
Open the AICPA criteriaNEXT DECISION
The scoping interview creates a structured draft for human review. It does not send messages or proposals automatically.
Scope an engagement