Kaamos

Framework reference

PCI DSS for EU B2B software companies.

PCI DSS is not an EU regulation, but it is contractually required when a company stores, processes, or transmits payment-card data. For software companies, it matters when payment flows, card data, or payment infrastructure are in scope.

Kaamos support
Supported in Kaamos
Category
Public-sector and contractual criteria
Obligation
Binding
Last updated

Who it applies to

  • Companies storing, processing, or transmitting payment-card data.
  • Fintech and commerce software with payment-card environments.
  • Vendors asked to show PCI DSS alignment by customers or payment partners.

What you need to do

  • Network security, access control, vulnerability management, monitoring, testing, and policy controls.
  • Evidence that cardholder data environments are scoped and protected.
  • Recurring control checks and remediation tracking.

How Kaamos helps

  • Track PCI DSS 4.0.1 requirements for your payment-data environment.
  • Link applicable controls to findings, owners and evidence.
  • Prepare control and evidence exports for assessment.

Sources

Company profiles this applies to

Supported in Kaamos

Manage PCI DSS controls, owners and evidence in Kaamos. Talk to us about the framework scope and connected systems you need.