pci-dss-specialist

Installation
SKILL.md

PCI-DSS v4.0 Specialist

Implement, assess, and maintain compliance with the Payment Card Industry Data Security Standard version 4.0 — the global standard for protecting cardholder data in payment processing environments. Covers CDE scoping, SAQ/ROC selection, gap assessment against all 12 requirements, scope reduction (tokenization, P2PE, segmentation), and the future-dated v4.0 controls that became mandatory March 31, 2025.

Core Capabilities

  • Compliance assessment — score against all 12 PCI DSS v4.0 requirements, identify gaps, and prioritize remediation (pci_compliance_checker.py)
  • Scoping & SAQ selection — map the cardholder data environment, classify connected and security-impacting systems, and determine the correct SAQ type or ROC requirement (pci_scope_analyzer.py)
  • Scope reduction — tokenization, P2PE, network segmentation, and outsourced/iFrame processing to remove systems from scope
  • v4.0 readiness — MFA for all CDE access, 12-char passwords, payment-page script controls (6.4.3/11.6.1), anti-phishing, automated log review, targeted risk analysis
  • Infrastructure controls — network segmentation, TLS/DNS, endpoint/POS, cloud (AWS/Azure/GCP), container, and API security; encryption key lifecycle and DUKPT

When to Use

Trigger on: "PCI DSS", "payment card security", "cardholder data", "PCI compliance", "payment security", "PCI assessment", "SAQ", "ROC", "QSA", "credit card security", "payment processing security", "tokenization", "CDE scoping", or "merchant level compliance".

Clarify First

Before running the assessment or scoping, confirm these inputs. If any is unknown or vague, ASK — do not assume:

Installs
92
GitHub Stars
436
First Seen
Mar 10, 2026
pci-dss-specialist — borghei/claude-skills