← All postsHow-to

PCI compliance checklist: the recurring tasks behind the annual sign-off

Compliance is a set of things that happen quarterly and monthly. The annual questionnaire only records whether they did.

How-toP

A PCI compliance checklist is the working list of recurring tasks that keep a merchant genuinely compliant between annual validations. It is not the questionnaire, not a substitute for it, and not the same thing as knowing your pci compliance levels: the questionnaire asks whether these things are true, and the checklist is how they become true and stay true.

Framing it this way matters because the common failure is not a missing control, it is a control that existed on the day of the attestation and lapsed the following month. Access reviews, scan schedules and policy acknowledgements are the items that decay quietly, and they are exactly what an investigation after an incident examines.

The recurring items on a PCI compliance checklist

  • External vulnerability scans on the required cadence by an approved scanning vendor, with passing results retained — a failed scan that was never re-run is a gap with a date on it.
  • Internal vulnerability scanning and remediation on the schedule the standard sets for your scope.
  • User access review: who has access to systems in scope, whether they still need it, and removal of leavers.
  • Password and authentication settings checked against the requirements, including multi-factor where required.
  • Patching within the timeframes for critical vulnerabilities.
  • Log review, and evidence that it happened rather than that it was possible.
  • Annual policy review and re-acknowledgement by staff, with the acknowledgements kept.
  • Security awareness training, recorded per person.
  • Service provider list with each provider’s current compliance status — their expiry dates are yours to track.
  • Incident response plan tested, not merely written.

The service provider list is the one nobody keeps

Merchants are responsible for confirming that the providers handling card data on their behalf are themselves compliant, and for keeping a list of them with what each is responsible for. In practice that list is compiled once during a first assessment and never updated, while the business quietly adds a new gateway, a new analytics script on the checkout page, or a new hosting arrangement. Review it on the same cycle as everything else and treat a new script on a payment page as a change that needs checking, because that is precisely where recent card-skimming attacks have lived.

Evidence has to be contemporaneous. A screenshot taken during the annual questionnaire showing a setting is correct today says nothing about the year behind it. Capture the scan reports, review sign-offs and training records when they happen, not when the questionnaire is due.

Making it survive staff changes

The checklist works when each item has a named owner, a cadence and a place the evidence lands — and when that survives the person who set it up leaving. Ettex Sheets holds the checklist with owners, due dates and last-completed dates, so what is overdue is visible rather than remembered; Ettex Records keeps the evidence per item and per period; and the annual submission it feeds is covered in pci saq.

To be clear: this is a spreadsheet and a file, not PCI software, and none of it is security advice. The requirements come from the current version of the standard, the validation obligation from your acquirer, and a qualified assessor is the authority on scope and applicability.

Frequently asked

What goes on a PCI compliance checklist?

The recurring tasks between annual validations: vulnerability scans, access reviews, patching, log review, policy review, training, provider status checks and incident response testing.

How often are external scans required?

On the cadence set by the standard for your scope, by an approved scanning vendor, with passing results retained. A failed scan must be remediated and re-run.

Do we have to track our providers’ compliance?

Yes. Merchants keep a list of providers handling card data on their behalf, with what each is responsible for and their current status.

Is the checklist the same as the SAQ?

No. The questionnaire records whether the controls are in place; the checklist is the recurring work that keeps them in place.

EP
Written by Elena P.

Part of the Ettex team — writing about product, engineering and the future of work.

More posts
Get the best of the Ettex blogProduct news, guides and tips — straight to your inbox, no spam.