Framework reference
PCI DSS for EU B2B software companies.
PCI DSS is not an EU regulation, but it is contractually required when a company stores, processes, or transmits payment-card data. For software companies, it matters when payment flows, card data, or payment infrastructure are in scope.
- Kaamos support
- Supported in Kaamos
- Category
- Public-sector and contractual criteria
- Obligation
- Binding
- Last updated
Who it applies to
- Companies storing, processing, or transmitting payment-card data.
- Fintech and commerce software with payment-card environments.
- Vendors asked to show PCI DSS alignment by customers or payment partners.
What you need to do
- Network security, access control, vulnerability management, monitoring, testing, and policy controls.
- Evidence that cardholder data environments are scoped and protected.
- Recurring control checks and remediation tracking.
How Kaamos helps
- Track PCI DSS 4.0.1 requirements for your payment-data environment.
- Link applicable controls to findings, owners and evidence.
- Prepare control and evidence exports for assessment.
Sources
Company profiles this applies to
- EU B2B SaaS company with 15-100 employees — watches PCI DSS as it grows.
- EU fintech or software supplier to financial customers — watches PCI DSS as it grows.
Supported in Kaamos
Manage PCI DSS controls, owners and evidence in Kaamos. Talk to us about the framework scope and connected systems you need.