PCI DSS v4.0 Payment Card Security Compliance Training Course

5 days Cyber Security Certificate on completion
Course codeSD-CS-057
Duration5 days
LevelIntermediate to Advanced
CategoryCyber Security
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Payment card environments are difficult to secure because cardholder data can move across payment applications, e-commerce pages, call-centre processes, cloud services, networks and third-party providers. PCI DSS v4.0 requires organisations to show how controls operate in practice, not simply produce policy documents. Security, risk, compliance and payment teams need a defensible method for scoping the cardholder data environment (CDE), assigning requirement ownership, testing evidence, managing gaps and preparing for a Qualified Security Assessor (QSA) review or internal assessment.

This five-day course teaches participants to interpret PCI DSS v4.0 requirements and apply them to real payment-card environments. Participants work through CDE discovery, data-flow mapping, segmentation validation, applicability analysis, customised approaches, targeted risk analysis, control testing and evidence collection. The course addresses the requirements most likely to create implementation work, including MFA, secure software development, payment-page security, logging, vulnerability management, penetration testing, service-provider oversight and incident response. Participants learn to distinguish between a policy statement, a configured technical control and the evidence needed to demonstrate operating effectiveness.

Instruction combines facilitated technical briefings with assessor-style case studies, requirement-to-control mapping exercises and group evidence reviews. Participants analyse a simulated merchant environment, identify scope and compliance gaps, select validation methods and build a remediation sequence. Each participant leaves with a PCI DSS v4.0 assessment workpack: a CDE scope statement, requirement applicability matrix, evidence register, control-testing plan, gap log and prioritised remediation roadmap that can be adapted for use in their own organisation.

The course is designed for experienced IT, security, audit, risk and payment professionals who contribute to PCI DSS compliance programmes or need to challenge their organisation's current approach. It is particularly valuable where responsibility is split across technology teams, cloud providers, payment processors and business owners.

Course objectives

By the end of this course, participants will be able to:

  • Define a cardholder data environment scope using payment-data flows, system inventories and connected-system analysis
  • Map PCI DSS v4.0 requirements to accountable control owners, technologies, procedures and evidence sources
  • Assess segmentation controls using network diagrams, firewall rule evidence and segmentation-test results
  • Apply the customised approach, including the controls matrix, targeted risk analysis and validation evidence
  • Test control effectiveness for access management, logging, vulnerability management and secure configuration requirements
  • Build an evidence register that links PCI DSS requirements to artefacts, testing frequency and evidence owners
  • Produce a prioritised gap remediation roadmap using risk, dependency, compensating control and assessment-readiness criteria
  • Prepare an internal assessment workpack for SAQ, ROC or QSA engagement activities

Benefits of attending

For you

  • Gain the ability to lead a structured PCI DSS v4.0 scoping and evidence-gathering exercise
  • Build credibility when challenging ambiguous CDE boundaries, weak segmentation claims and incomplete assessment evidence
  • Develop practical judgement on when a customised approach or targeted risk analysis is appropriate
  • Create assessment-ready artefacts that demonstrate capability in compliance, security assurance and payment-risk roles
  • Communicate PCI DSS remediation priorities clearly to technical owners, executives and external assessors

For your organisation

  • Reduce assessment delays by establishing a repeatable evidence register and named requirement ownership model
  • Lower the risk of under-scoping payment environments, connected systems and third-party service dependencies
  • Improve remediation investment decisions by ranking gaps according to requirement impact, risk and technical dependency
  • Strengthen evidence of operating effectiveness for controls such as MFA, logging, vulnerability management and testing
  • Create a more consistent internal readiness process before SAQ submission, ROC preparation or QSA assessment

Target competencies

CDE scope analysisControl evidence testingSegmentation validationTargeted risk analysisRequirement ownership mappingRemediation roadmap design

Who should attend

  • PCI DSS Compliance Managers — who coordinate assessment evidence, remediation owners and QSA interactions
  • Information Security Managers — who must translate PCI DSS requirements into operational security controls
  • IT Security Architects — who design CDE boundaries, segmentation and secure payment-system integrations
  • Internal Auditors — who test control design and operating effectiveness for payment-card environments
  • GRC and Risk Professionals — who maintain compliance registers, risk treatment plans and control accountability
  • Payment Technology and E-commerce Managers — who oversee payment pages, processors and third-party payment services

Requirements and prerequisites

Participants should have practical experience in IT operations, information security, audit, risk or payment technology, and should understand basic networking concepts such as IP addressing, firewalls, VLANs, DNS and system administration. Familiarity with access control, vulnerability scanning, log review, incident response and policy-based controls is expected. Participants should also be able to read an architecture diagram and discuss evidence such as configuration exports, tickets and system reports. Prior PCI DSS assessment experience is helpful but not required. No coding, penetration-testing certification, QSA qualification or specialist payment gateway administration experience is required.

Training methodology

The course uses instructor-led requirement interpretation followed by assessor-style application work. Participants examine payment architectures, data-flow diagrams, firewall rules, vulnerability reports, access reviews, logging extracts and supplier documentation to decide whether controls meet PCI DSS v4.0 intent. Small groups build scope statements, test evidence against requirement criteria and defend remediation decisions in review sessions. The final day uses an integrated assessment scenario in which participants assemble their own workpack and convert findings into an implementable 90-day action plan.

Course outline

Day 1: PCI DSS v4.0 foundations and CDE scoping

  • PCI DSS v4.0 structure, requirement intent and validation pathways
  • Merchant, service provider, acquirer and QSA responsibilities
  • Account data, cardholder data and sensitive authentication data definitions
  • CDE identification using payment transaction and data-flow mapping
  • In-scope system, connected-to system and out-of-scope asset decisions
  • Payment-channel scoping for e-commerce, retail, MOTO and outsourced payments
  • Scope reduction through tokenisation, encryption and isolation patterns

Workshop: Participants map a simulated merchant payment flow and produce an initial CDE scope statement with documented inclusion and exclusion decisions.

Day 2: Control design, segmentation and access security

  • Requirement-to-control mapping across PCI DSS v4.0 requirements
  • Network security controls, firewall rule governance and service exposure review
  • Segmentation architecture and segmentation-test evidence
  • Strong cryptography and key-management control expectations
  • Identity lifecycle management, least privilege and access review testing
  • Multi-factor authentication implementation and evidence requirements
  • Secure configuration baselines, change control and anti-malware controls

Workshop: Participants review network diagrams, firewall rules and identity evidence to produce a segmentation validation plan and access-control gap log.

Day 3: Secure systems, payment applications and vulnerability management

  • Secure software development lifecycle requirements and code-change evidence
  • Payment-page script inventory, authorisation and integrity monitoring
  • E-commerce skimming threats and client-side security control design
  • Vulnerability management programme design and authenticated scanning evidence
  • ASV scanning, internal vulnerability scans and remediation verification
  • Penetration testing scope, methodology and segmentation testing requirements
  • Logging, time synchronisation, alerting and log-review operating evidence

Workshop: Participants assess an e-commerce payment-page scenario and produce a control map covering script management, vulnerability remediation and logging evidence.

Day 4: Risk-based flexibility, third parties and assessment evidence

  • Defined approach versus customised approach decision criteria
  • Targeted risk analysis for frequency-based PCI DSS requirements
  • Controls matrix construction and customised approach validation
  • Compensating controls worksheet logic and residual-risk justification
  • Service-provider responsibility matrices and written agreement evidence
  • Third-party payment processor due diligence and compliance attestation review
  • Evidence register design, sampling methods and operating-effectiveness testing

Workshop: Participants complete a targeted risk analysis and evidence register for a selected requirement, then defend their validation approach in a peer review.

Day 5: Assessment readiness and remediation planning

  • SAQ selection, ROC preparation and internal assessment sequencing
  • Interview, observation, document review and technical testing methods
  • Evidence quality criteria: completeness, currency, traceability and ownership
  • Finding classification, root-cause analysis and remediation dependency mapping
  • Prioritised remediation roadmaps and management reporting
  • Incident response testing and payment-card breach escalation considerations
  • Continuous compliance operating model and annual assessment calendar

Workshop: Participants complete an integrated PCI DSS assessment case and produce a prioritised remediation roadmap, executive findings summary and 90-day action plan.

Tools & standards covered

PCI DSS v4.0.1, PCI DSS ROC Reporting Template, PCI DSS SAQ D, Qualys PCI ASV

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

Previous PCI DSS assessment experience is useful but not essential. You should already understand core IT security controls, networking and how operational evidence such as configuration records, scan reports and access reviews is produced.

A laptop is recommended for working with the course templates, architecture diagrams and evidence samples. The exercises use provided case materials rather than requiring access to your employer's cardholder data environment or proprietary compliance platform.

Yes. Technical participants learn how PCI DSS requirements translate into architecture, access, vulnerability, logging and testing evidence, while compliance participants learn how to assess those controls intelligently. The course is built around the hand-offs between both groups.

This course focuses on performing compliance work: scoping the CDE, testing control evidence, applying targeted risk analysis and planning remediation. It goes beyond requirement familiarisation by using assessment scenarios and producing a reusable workpack.

You can use the scope statement, applicability matrix, evidence register and remediation roadmap structures immediately in an internal readiness review. The methods also help you prepare focused questions for system owners, cloud providers, payment processors and QSAs.

You leave with completed course templates for CDE scoping, requirement ownership, evidence collection, gap tracking and remediation planning. These are populated during the case exercises and designed to be adapted to your organisation's payment environment.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Cyber Security

5 Days Certificate

CrowdStrike Falcon Endpoint Detection and Response Administration Training Course

Security teams cannot respond consistently when endpoint telemetry is incomplete, prevention policies are poorly tuned, and analysts must wo…

5 Days Certificate

ISO 27001 Information Security Management Training Course

Organisations seeking ISO/IEC 27001 certification, maintaining an existing ISMS, or responding to customer security questionnaires need more…

5 Days Certificate

CIS Controls v8 Implementation and Assessment Training Course

Security teams are often asked to demonstrate that their controls are effective, prioritised and connected to business risk, yet their evide…

5 Days Certificate

Burp Suite Web Application Security Testing Training Course

Web applications expose business processes, customer data and internal services through complex combinations of APIs, authentication flows, …