SYSTEMIC ASPECTS OF PREPARING ORGANIZATIONS FOR A PCI DSS COMPLIANCE AUDIT

Authors

DOI:

https://doi.org/10.31673/2409-7292.2026.029908

Abstract

The article examines the organizational and practical aspects of ensuring organizations’ readiness for PCI DSS
audits. It justifies the feasibility of perceiving the process of confirming compliance with the standard requirements not
as a formal annual procedure, but as a continuous information security management process. It analyzes typical problems
that arise during the audit, in particular, errors in determining the scope of application, insufficient level of documentation
of procedures, and irregularity in the implementation of control measures. The paper systematizes the main stages of an
audit conducted by a qualified security assessor (QSA) and identifies key areas for preparing an organization for an
external assessment or self-assessment. Particular attention is paid to the issues of optimizing the cardholder data
environment (CDE), conducting gap analysis, implementing corrective actions, and ensuring regular operating procedures
during the review period. The importance of documenting processes, allocating responsibilities, and integrating the
standard requirements into the organization’s daily activities is revealed. The role of internal audits and mock audits as
tools for early detection of non-conformities and minimizing the risks of a negative assessment result is determined. A
comprehensive approach to preparing for and maintaining PCI DSS compliance has been shown to reduce the risk of
security incidents, minimize financial and reputational losses, and build trust with customers and partners. The findings
can be used by organizations that process payment card data to improve audit preparation and ensure ongoing compliance.
Keywords: information security management, PCI DSS, payment data protection, external audit, self-assessment,
cardholder data environment.

References
1. PCI DSS v4.0.1. URL: https://www.pcisecuritystandards.org/document_library/.
2. PCI compliance audit checklist: An expert guide to passing your audit in 2025. URL: https://www.scrut.io/hub
/pci-dss/pci-compliance-audit-checklist.
3. PCI Audit: Requirements and 5 Steps to Prepare for Your Audit. URL: https://www.exabeam.com/
explainers/pci-compliance/pci-audit-requirements-and-5-steps-to-prepare-for-your-audit/.
4. Compliance benchmark. Report 2025. URL: https://go.a-lign.com/Benchmark-Report-2025?_ga=2.121865032.
29657354.1742913437-1057260875.1742913437.
5. 2024 Payment Security Report. URL: https://www.verizon.com/business/reports/payment-security-report/.
6. Chippagiri, S, Rames, A. (2025). PCI DSS: a critical analysis of implementation, effectiveness, and legislative
impact in payment card security. International journal of scientific research in computer science, engineering and
information technology, 11 (1), 1258-1266. https://doi.org/10.32628/CSEIT251112115.
7. Rahaman, S., Wang, G., & Yao, D. (2019). Security certification in payment card industry: Testbeds,
measurements, and recommendations. Proceedings of the 2019 ACM SIGSAC conference on computer and
communications security. November 11–15, 2019, London, United Kingdom. 481-498. https://doi.org/10.1145/
3319535.3363195.
8. ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection, Information security
management systems, Requirements. URL: https://www.iso.org/standard/54534.html.
9. ISO/IEC 27002:2022 Information security, cybersecurity and privacy protection, Information security controls.
URL: https://www.iso.org/standard/75652.html.
10. Кухарська, Н. П, Семенюк С. А., & Полотай, О. І. (2025). Ключові аспекти оновленого стандарту
ISO/IEC 27002:2022. Сучасний захист інформації, 2, 76-87. https://doi.org/10.31673/2409-7292.2025.023969.
11. Курій, Є., & Опірський, І. (2024). Безпека платіжних операцій: огляд і характеристика ключових змін
у новій редакції стандарту PCI DSS. Електронне фахове наукове видання “Кібербезпека: освіта, наука, техніка”,
3(23), 145–155. https://doi.org/10.28925/2663-4023.2024.23.145155.
12. Joshi, P. K. (2024). Achieving PCI-DSS compliance in payment gateways: a comprehensive approach. Journal
of technology and systems, 6(7), 13–31. https://doi.org/10.47941/jts.2299.

Published

2026-06-25

Issue

Section

Articles