Here is the honest situation. You take card payments, and now your acquiring bank, your processor, or a customer will not move forward until you show PCI DSS compliance. You understand the standard. The problem is producing it: a control mapped to all 168 requirements, the network and data-flow diagrams, a defined cardholder data environment, and the evidence an assessor will examine. A consultant charges thirty to seventy-five thousand dollars. Doing it yourself is months while the pressure builds.
This Kit removes the build. It is the complete PCI DSS 4.0 control set and evidence guide, already written, that you personalize in a weekend.
What you get, the moment you buy
Plus the assessment overview (SAQ versus Report on Compliance, the CDE scope, the AOC) and clear marking of the service-provider-only and targeted-risk-analysis requirements. Editable Word and Excel files, current to PCI DSS v4.0.1.
What one requirement looks like
This is Requirement 3.5.1, exactly as it appears in the Kit. All 168 are built to this depth.
Why this is not another template pack
- The evidence is the point. Generic templates give you words. This tells you exactly what an assessor will examine, and the finding they note, for every requirement. That is what gets you a clean assessment.
- Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
- Complete, never sampled. All 168 requirements across the 12 principal requirements, with service-provider and targeted-risk items marked.
- It compounds. The controls you document here already count toward SOC 2 and ISO 27001, and the mappings show you where.
Who buys this
Merchants and service providers who need to validate PCI DSS for an acquirer, processor, or enterprise customer, and the security leads, GRC teams, and consultants who run the assessment. First-time SAQ or full ROC, you save weeks and walk in with fewer findings.
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
Does this make me PCI compliant? Compliance is validated through your SAQ or a QSA's Report on Compliance. The Kit gets you ready: the controls, the matrix, and the exact evidence they will test, so validation goes smoothly.
SAQ or ROC? Both. The controls and evidence apply whether you self-assess or are assessed by a QSA.
Is it current? Yes, PCI DSS v4.0.1 with all 12 principal requirements and the future-dated requirements marked. Updates included.
What if it is not for me? A 30-day money-back guarantee.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com