The official PCI DSS 4.0 requirements spreadsheet is the Prioritized Approach Tool, published by the PCI Security Standards Council as an XLSX file in its Document Library.1PCI Security Standards Council. Document Library It lists every requirement in version 4.0.1, the testing procedure the assessor uses to verify each one, and a status column you fill in as you work through your environment. If you searched for a single spreadsheet that maps the whole standard, this is the file. The other core compliance documents — the Report on Compliance template and the Self-Assessment Questionnaires — are published as PDFs, not spreadsheets.
Which Official Template You Actually Need
The Council publishes three related documents, and confusion between them is the most common reason people download the wrong file:
- The Prioritized Approach Tool is the XLSX spreadsheet. It maps every requirement to a priority milestone and gives you filterable, sortable columns for tracking implementation status. Most organizations use it as the internal backbone of their compliance work and then transfer findings into an SAQ or ROC for formal submission.1PCI Security Standards Council. Document Library
- The Report on Compliance (ROC) Template is a PDF used by Qualified Security Assessors conducting Level 1 merchant audits.2PCI Security Standards Council. PCI SSC Releases ROC Template for PCI DSS v4.0.1
- The Self-Assessment Questionnaires (SAQs) are the primary validation documents for merchants below Level 1. Each SAQ covers a different subset of the standard, and the correct one depends on how you accept payments.3PCI Security Standards Council. PCI DSS v4: What’s New with Self-Assessment Questionnaires
Use the Prioritized Approach Tool to do the work. Use the correct SAQ or ROC to document the result for your acquiring bank.
Confirm You’re Working from Version 4.0.1
Version 3.2.1 was retired on March 31, 2024.4PCI Security Standards Council. PCI DSS v3.2.1 is Retiring on 31 March 2024 – Are You Ready? The current standard is version 4.0.1, published on June 11, 2024, which added clarifications but no new or deleted requirements.5PCI Security Standards Council. Just Published: PCI DSS v4.0.1 Any spreadsheet you download should say 4.0.1 in the filename or header. Older 4.0 files still circulate online, and while the requirements themselves are the same, the wording clarifications matter when an assessor is reading your evidence.
One date changes what your spreadsheet has to cover. On March 31, 2025, 51 requirements that had been labeled “best practice” became fully mandatory.6PCI Security Standards Council. Now is the Time for Organizations to Adopt the Future-Dated Requirements of PCI DSS v4.x If your previous assessment predated that cutoff, several rows in the spreadsheet that you might have skipped are now in scope. The ones that catch organizations by surprise:
- Requirement 5.4.1: automated mechanisms to detect and protect personnel against phishing attacks.7PCI Security Standards Council. Five Perspectives to Help You Understand the New PCI DSS v4.0 Requirements
- Requirement 6.4.2: automated technical solutions to detect and prevent web-based attacks on public-facing web applications, plus an inventory and monitoring of every script loaded on payment pages.
- Requirement 8.4.2: multi-factor authentication for all access into the cardholder data environment, not just administrative access. Remote authentication into your network does not count as the second factor when a user then reaches the CDE from inside.6PCI Security Standards Council. Now is the Time for Organizations to Adopt the Future-Dated Requirements of PCI DSS v4.x
- Requirements 3.5.1.1 and 3.5.1.2: keyed cryptographic hashing where hashing is used to protect primary account numbers, and disk-level encryption alone no longer qualifies on certain system types.
- Requirement 12.5.2: a formal annual exercise to validate the boundaries of your PCI DSS scope.
- Requirements 1.1.2 through 12.1.2: formally documented and assigned roles and responsibilities for each of the twelve requirement categories. A generic security policy no longer satisfies this.
Filling In the Spreadsheet
Each row in the Prioritized Approach Tool has a requirement ID, the requirement text, the testing procedure the assessor will use, and a status field. The standard status options are In Place, In Place with Remediation, Not In Place, Not Applicable, and Not Tested. Choosing a status is the easy part; the value of the spreadsheet comes from what you write next to it.
Cite specific configurations rather than vague assertions. For Requirement 8.4.2, name the MFA product, list the user groups enrolled, and identify the system components it covers. For Requirement 3, document the encryption algorithm, key length, and key management procedures protecting stored account data. For Requirement 5.4.1, name the anti-phishing tool and the population of users it protects. Assessors reading a row want to know what, where, and who — not that a control “is enforced.”
If a control is not in place, the row needs a realistic target remediation date and a credible plan. Vague future dates without an implementation path get flagged. Where you use the Customized Approach (an alternative control that meets the security objective behind a requirement rather than the literal wording), the documentation load is heavier: you need a targeted risk analysis, a description of the alternative control, and evidence that it delivers equivalent protection.8PCI Security Standards Council. PCI DSS v4.0: Compensating Controls vs Customized Approach The Customized Approach fits organizations with mature security programs; most merchants stay with the Defined Approach and meet each requirement as written.
Targeted Risk Analysis Rows
Version 4.0 lets you set the frequency of some periodic activities based on a targeted risk analysis instead of a preset schedule. Requirement 12.3.1 governs this. When a spreadsheet row references a TRA, your documentation needs to cover five points: the assets being protected, the specific threats the control guards against, the risk factors affecting likelihood and impact, the justification for the frequency you chose, and confirmation that the analysis has been reviewed within the past twelve months. Update the TRA whenever the environment, threats, or business operations change materially.
Match the Spreadsheet to the Right SAQ
The Prioritized Approach Tool contains every requirement in the standard, but your reporting obligation may only cover a subset. That subset is defined by your SAQ type, and choosing the wrong one means wasted work and a rejected submission. The main options:3PCI Security Standards Council. PCI DSS v4: What’s New with Self-Assessment Questionnaires
- SAQ A — payment pages fully hosted by a third-party processor through iframe or URL redirect; you never touch card data.
- SAQ A-EP — e-commerce merchants whose payment pages come from a third party but whose website could still affect transaction security.
- SAQ B-IP — merchants using standalone, PCI-approved point-of-interaction devices not connected to other devices in the same network zone.
- SAQ C-VT — payments processed through a virtual terminal on a standalone computer.
- SAQ P2PE — merchants using a validated point-to-point encryption solution.
- SAQ D — the catch-all for more complex merchant environments, and the only option for service providers. It covers essentially every requirement in the standard.
Your merchant level determines whether an SAQ is even available to you. Visa defines Level 1 as merchants processing more than six million payment card transactions annually across all channels, and Level 1 merchants must undergo an onsite audit by a Qualified Security Assessor and file a full Report on Compliance.9Visa. Account Information Security Program and PCI Smaller merchants validate through the appropriate SAQ.
Where the Finished Package Goes
Completed documentation goes to your acquiring bank or payment brand partners, not to the PCI Security Standards Council. Most acquirers provide an online portal for uploading your SAQ and the accompanying Attestation of Compliance. Level 1 merchants work with their QSA, who submits the ROC alongside an Attestation of Compliance signed by a senior officer.
That signature is not a formality. The Attestation declares that the SAQ or ROC accurately represents your security posture, and a breach that later reveals inaccurate documentation exposes the organization to significantly worse consequences. Acquirers may request clarification or additional evidence before confirming compliance, and the whole cycle repeats annually to account for changes in your environment, technology, and threats.
What It Costs to Get the Spreadsheet Wrong
PCI DSS compliance is a contractual obligation imposed by payment processors and card brands, not a government regulation.9Visa. Account Information Security Program and PCI The financial penalties are still severe. Card brands reportedly impose monthly fines that start in the range of $5,000 to $10,000 and climb to $50,000 or $100,000 per month for organizations that remain out of compliance beyond six months. The fines are assessed against the acquiring bank, which passes them through to the merchant.
Beyond fines, non-compliant organizations face higher transaction fees and possible loss of payment processing privileges. If a breach happens while you are out of compliance, the exposure escalates: card brands may assess fraud losses and reissuing costs, and some cyber liability insurers exclude or limit PCI-related claims when merchant negligence contributed. The forensic investigation alone after a breach can cost more than a year of proper compliance work. Filling in the spreadsheet carefully, with specific evidence in every row, is the cheaper path by a wide margin.