PCI DSS v4.0 Payment Card Security Compliance Training Course
| Course code | SD-CS-057 |
|---|---|
| Duration | 5 days |
| Level | Intermediate to Advanced |
| Category | Cyber Security |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Payment card environments are difficult to secure because cardholder data can move across payment applications, e-commerce pages, call-centre processes, cloud services, networks and third-party providers. PCI DSS v4.0 requires organisations to show how controls operate in practice, not simply produce policy documents. Security, risk, compliance and payment teams need a defensible method for scoping the cardholder data environment (CDE), assigning requirement ownership, testing evidence, managing gaps and preparing for a Qualified Security Assessor (QSA) review or internal assessment.
This five-day course teaches participants to interpret PCI DSS v4.0 requirements and apply them to real payment-card environments. Participants work through CDE discovery, data-flow mapping, segmentation validation, applicability analysis, customised approaches, targeted risk analysis, control testing and evidence collection. The course addresses the requirements most likely to create implementation work, including MFA, secure software development, payment-page security, logging, vulnerability management, penetration testing, service-provider oversight and incident response. Participants learn to distinguish between a policy statement, a configured technical control and the evidence needed to demonstrate operating effectiveness.
Instruction combines facilitated technical briefings with assessor-style case studies, requirement-to-control mapping exercises and group evidence reviews. Participants analyse a simulated merchant environment, identify scope and compliance gaps, select validation methods and build a remediation sequence. Each participant leaves with a PCI DSS v4.0 assessment workpack: a CDE scope statement, requirement applicability matrix, evidence register, control-testing plan, gap log and prioritised remediation roadmap that can be adapted for use in their own organisation.
The course is designed for experienced IT, security, audit, risk and payment professionals who contribute to PCI DSS compliance programmes or need to challenge their organisation's current approach. It is particularly valuable where responsibility is split across technology teams, cloud providers, payment processors and business owners.
Course objectives
By the end of this course, participants will be able to:
- Define a cardholder data environment scope using payment-data flows, system inventories and connected-system analysis
- Map PCI DSS v4.0 requirements to accountable control owners, technologies, procedures and evidence sources
- Assess segmentation controls using network diagrams, firewall rule evidence and segmentation-test results
- Apply the customised approach, including the controls matrix, targeted risk analysis and validation evidence
- Test control effectiveness for access management, logging, vulnerability management and secure configuration requirements
- Build an evidence register that links PCI DSS requirements to artefacts, testing frequency and evidence owners
- Produce a prioritised gap remediation roadmap using risk, dependency, compensating control and assessment-readiness criteria
- Prepare an internal assessment workpack for SAQ, ROC or QSA engagement activities
Benefits of attending
For you
- Gain the ability to lead a structured PCI DSS v4.0 scoping and evidence-gathering exercise
- Build credibility when challenging ambiguous CDE boundaries, weak segmentation claims and incomplete assessment evidence
- Develop practical judgement on when a customised approach or targeted risk analysis is appropriate
- Create assessment-ready artefacts that demonstrate capability in compliance, security assurance and payment-risk roles
- Communicate PCI DSS remediation priorities clearly to technical owners, executives and external assessors
For your organisation
- Reduce assessment delays by establishing a repeatable evidence register and named requirement ownership model
- Lower the risk of under-scoping payment environments, connected systems and third-party service dependencies
- Improve remediation investment decisions by ranking gaps according to requirement impact, risk and technical dependency
- Strengthen evidence of operating effectiveness for controls such as MFA, logging, vulnerability management and testing
- Create a more consistent internal readiness process before SAQ submission, ROC preparation or QSA assessment
Target competencies
Who should attend
- PCI DSS Compliance Managers — who coordinate assessment evidence, remediation owners and QSA interactions
- Information Security Managers — who must translate PCI DSS requirements into operational security controls
- IT Security Architects — who design CDE boundaries, segmentation and secure payment-system integrations
- Internal Auditors — who test control design and operating effectiveness for payment-card environments
- GRC and Risk Professionals — who maintain compliance registers, risk treatment plans and control accountability
- Payment Technology and E-commerce Managers — who oversee payment pages, processors and third-party payment services
Requirements and prerequisites
Participants should have practical experience in IT operations, information security, audit, risk or payment technology, and should understand basic networking concepts such as IP addressing, firewalls, VLANs, DNS and system administration. Familiarity with access control, vulnerability scanning, log review, incident response and policy-based controls is expected. Participants should also be able to read an architecture diagram and discuss evidence such as configuration exports, tickets and system reports. Prior PCI DSS assessment experience is helpful but not required. No coding, penetration-testing certification, QSA qualification or specialist payment gateway administration experience is required.
Training methodology
The course uses instructor-led requirement interpretation followed by assessor-style application work. Participants examine payment architectures, data-flow diagrams, firewall rules, vulnerability reports, access reviews, logging extracts and supplier documentation to decide whether controls meet PCI DSS v4.0 intent. Small groups build scope statements, test evidence against requirement criteria and defend remediation decisions in review sessions. The final day uses an integrated assessment scenario in which participants assemble their own workpack and convert findings into an implementable 90-day action plan.
Course outline
Day 1: PCI DSS v4.0 foundations and CDE scoping
- PCI DSS v4.0 structure, requirement intent and validation pathways
- Merchant, service provider, acquirer and QSA responsibilities
- Account data, cardholder data and sensitive authentication data definitions
- CDE identification using payment transaction and data-flow mapping
- In-scope system, connected-to system and out-of-scope asset decisions
- Payment-channel scoping for e-commerce, retail, MOTO and outsourced payments
- Scope reduction through tokenisation, encryption and isolation patterns
Workshop: Participants map a simulated merchant payment flow and produce an initial CDE scope statement with documented inclusion and exclusion decisions.
Day 2: Control design, segmentation and access security
- Requirement-to-control mapping across PCI DSS v4.0 requirements
- Network security controls, firewall rule governance and service exposure review
- Segmentation architecture and segmentation-test evidence
- Strong cryptography and key-management control expectations
- Identity lifecycle management, least privilege and access review testing
- Multi-factor authentication implementation and evidence requirements
- Secure configuration baselines, change control and anti-malware controls
Workshop: Participants review network diagrams, firewall rules and identity evidence to produce a segmentation validation plan and access-control gap log.
Day 3: Secure systems, payment applications and vulnerability management
- Secure software development lifecycle requirements and code-change evidence
- Payment-page script inventory, authorisation and integrity monitoring
- E-commerce skimming threats and client-side security control design
- Vulnerability management programme design and authenticated scanning evidence
- ASV scanning, internal vulnerability scans and remediation verification
- Penetration testing scope, methodology and segmentation testing requirements
- Logging, time synchronisation, alerting and log-review operating evidence
Workshop: Participants assess an e-commerce payment-page scenario and produce a control map covering script management, vulnerability remediation and logging evidence.
Day 4: Risk-based flexibility, third parties and assessment evidence
- Defined approach versus customised approach decision criteria
- Targeted risk analysis for frequency-based PCI DSS requirements
- Controls matrix construction and customised approach validation
- Compensating controls worksheet logic and residual-risk justification
- Service-provider responsibility matrices and written agreement evidence
- Third-party payment processor due diligence and compliance attestation review
- Evidence register design, sampling methods and operating-effectiveness testing
Workshop: Participants complete a targeted risk analysis and evidence register for a selected requirement, then defend their validation approach in a peer review.
Day 5: Assessment readiness and remediation planning
- SAQ selection, ROC preparation and internal assessment sequencing
- Interview, observation, document review and technical testing methods
- Evidence quality criteria: completeness, currency, traceability and ownership
- Finding classification, root-cause analysis and remediation dependency mapping
- Prioritised remediation roadmaps and management reporting
- Incident response testing and payment-card breach escalation considerations
- Continuous compliance operating model and annual assessment calendar
Workshop: Participants complete an integrated PCI DSS assessment case and produce a prioritised remediation roadmap, executive findings summary and 90-day action plan.
Tools & standards covered
PCI DSS v4.0.1, PCI DSS ROC Reporting Template, PCI DSS SAQ D, Qualys PCI ASV
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Cyber Security
CrowdStrike Falcon Endpoint Detection and Response Administration Training Course
Security teams cannot respond consistently when endpoint telemetry is incomplete, prevention policies are poorly tuned, and analysts must wo…
ISO 27001 Information Security Management Training Course
Organisations seeking ISO/IEC 27001 certification, maintaining an existing ISMS, or responding to customer security questionnaires need more…
CIS Controls v8 Implementation and Assessment Training Course
Security teams are often asked to demonstrate that their controls are effective, prioritised and connected to business risk, yet their evide…
Burp Suite Web Application Security Testing Training Course
Web applications expose business processes, customer data and internal services through complex combinations of APIs, authentication flows, …