PCI DSS v4.0 - Payment Card Industry Data Security Standard

PCI DSS Compliance.
Evidence-Led. Audit-Ready.

Compliance belongs to your culture. The burden belongs to us.

Simplif-i maps your PCI DSS controls, documents your cardholder data environment, and keeps your compliance evidence continuously updated - so your QSA isn't the first person to find the gaps.

PCI DSS v4.0
12 Requirements
AI-powered evidence mapping
Built by a certified ISO Lead Auditor
Built by a certified ISO Lead Auditor
PCI DSS v4.0 ready
All 12 requirements covered
10/10 penetration tested - Zero vulnerabilities
TLS 1.3 encrypted

PCI DSS Non-Compliance Costs More Than the Fines

Card brand fines for non-compliance run from $5,000 to $100,000 per month. A data breach involving cardholder data costs multiples of that - in fines, remediation, reputational damage, and lost merchant status.

But most PCI DSS failures aren't sophisticated attacks. They're documentation failures. Controls that existed but weren't evidenced. Policies that were written once and never maintained. A Cardholder Data Environment that grew without anyone updating the scope.

PCI DSS v4.0 raised the bar. Customised controls, enhanced authentication requirements, targeted risk analysis for every requirement. The evidence burden increased significantly.

Compliance belongs to your culture. The burden belongs to us.

All 12 Requirements. Continuously Evidenced.

Document your CDE scope

Document your Cardholder Data Environment against the relevant PCI controls. Evidence your network segmentation. Simplif-i structures the documentation and keeps it current as your environment changes.

Map existing controls to requirements

Upload your security policies and documentation. Simplif-i maps every document to the relevant PCI DSS requirement automatically. Gaps identified. Remediation steps in plain English.

Capture evidence from your systems

Firewall rules, access logs, patch records, vulnerability scan results - navigate to any system, paste the URL, hit capture. Evidence filed against the specific requirement. No integrations. One button.

Maintain continuous compliance

Evidence freshness tracked. Stale evidence flagged before your QSA finds it. Quarterly review schedules automated. Annual assessment pack ready at any time.

One-click QSA pack

Everything your Qualified Security Assessor needs - formatted, ordered, and ready. No last-minute assembly. No missing sections.

All 12 Requirements. All the Evidence.

CDE Documentation

Cardholder Data Environment scope documented and evidenced against PCI controls.

Requirement Mapping

All 12 PCI DSS v4.0 requirements. Evidence mapped automatically.

Evidence Collector

Any system. Any URL. One button. Vulnerability scan results, firewall configs, access logs - all captured and filed.

Policy Architect

PCI DSS aligned policies through plain business questions.

Risk Assessment

Targeted risk analysis per requirement as mandated by v4.0.

Vulnerability Evidence

Capture scan results from any scanner as compliance evidence. Filed against the relevant requirement.

QSA Pack Generator

One click. Everything your assessor needs. Formatted and ready.

Compliance Calendar

Quarterly reviews, annual assessments, penetration test schedules. Nothing missed.

Vendor Due Diligence

Third-party service provider management. Questionnaires scored automatically.

Trust Portal

Your live PCI DSS compliance status. Shareable with partners and clients.

Built by Someone Who Understands Security Evidence

Simplif-i was built by a certified ISO Lead Auditor, ex-CTO and ex-COO with 25 years of experience implementing security frameworks across regulated environments.

That's why the evidence collector works without integrations - because the systems storing cardholder data rarely have compliance-friendly APIs.

That's why the QSA pack is one click - because the annual scramble to compile evidence is where PCI DSS projects fail.

That's why v4.0's customised controls approach is supported - because the standard evolved and your compliance platform should have kept up.

Compliance belongs to your culture. The burden belongs to us.

We Hold Ourselves to the Same Standard

Independently penetration tested. 35 tests. Zero outstanding vulnerabilities.

Authentication secure. Payment wall secured separately from platform data. Data isolation enforced at every layer. TLS 1.3 throughout.

Your data belongs to you. The AI operates exclusively on your evidence. Full security architecture report available on request.

Founding Member Pricing. First 50 Only.

Lite

£49/month

Core compliance tools. PCI DSS framework. Evidence logging. Gap analysis.

1 user - 500MB - 150 AI credits/month
Most Popular

Pro

£499/month

Rises to £299 on general release - save £1,800 in year one.

Full platform. All 30+ frameworks. Risk assessment module. Vendor management. Board Pack Generator.

5 users - 5GB - 150 AI credits/month

Enterprise

POA

White label available. Unlimited users. Dedicated account manager. Bespoke onboarding.

Custom configuration

Founding member pricing locked for 12 months. Closes permanently when the first 50 cohort is full.

7-day free trial. No charge if you cancel before day 7.

Frequently Asked Questions

PCI DSS compliance that holds up under QSA scrutiny.

Not a policy pack and a self-assessment questionnaire. A continuously evidenced compliance programme - all 12 requirements documented, cardholder data environment maintained, QSA pack ready at any time - built on the principle that compliance belongs to your culture, and the burden belongs to us.

First 50 founding members. £499/month. Locked for 12 months.

Simplif-iSimplif-i
simplif-i.com-TLS 1.3 encrypted-10/10 pen tested-Built by a certified ISO Lead Auditor

© 2026 Simplif-i. All rights reserved.

Install Simplif-i

Add to your home screen for quick access & offline viewing