Track PCI DSS v4.0 readiness across the 12 requirements and roughly 277 sub-requirements, with compensating controls and ASV scans counted.
PCI DSS is scored bottom-up: the 12 headline requirements decompose into roughly 277 testable sub-requirements, and compliance is binary at the sub-requirement level — an item is in place or it is not. Compensating controls count at three-quarter credit here because they satisfy an assessor only with a completed worksheet and are re-tested every year, and the ASV scan record is weighted separately because four passing quarterly scans is a hard external gate. PCI has no partial credit at attestation time, so the useful management number is how many sub-requirements are open and how long they will take — not an average that hides a single failed requirement. This is a readiness estimate; only a QSA or ISA can validate compliance.
PCI DSS Compliance
Readiness = 0.60 × sub-requirement coverage + 0.25 × requirements fully met + 0.15 × ASV scan record, where coverage = (in place + 0.75 × compensating) ÷ (277 − not applicable).
Readiness = 0.60 × sub-requirement coverage + 0.25 × requirements fully met + 0.15 × ASV scan record, where coverage = (in place + 0.75 × compensating) ÷ (277 − not applicable). PCI DSS is scored bottom-up: the 12 headline requirements decompose into roughly 277 testable sub-requirements, and compliance is binary at the sub-requirement level — an item is in place or it is not. Compensating controls count at three-quarter credit here because they satisfy an assessor only with a completed worksheet and are re-tested every year, and the ASV scan record is weighted separately because four passing quarterly scans is a hard external gate.
PCI has no partial credit at attestation time, so the useful management number is how many sub-requirements are open and how long they will take — not an average that hides a single failed requirement. This is a readiness estimate; only a QSA or ISA can validate compliance.
This calculator takes 7 inputs: Sub-requirements in place, Sub-requirements not applicable to your environment, Sub-requirements met by a compensating control, Of the 12 requirements, how many are fully met, Passing quarterly ASV scans in the last year, Validation route, Using the customised approach for any control. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Not for the purposes of an attestation. Compliance is all-or-nothing across the applicable sub-requirements, so a 95% score means you are not compliant and have roughly fourteen items to close. The percentage is useful for tracking a programme, not for answering an acquirer.
Because it cannot be back-filled. Four passing quarterly external scans take a year of elapsed time, so a programme that starts scanning in month ten has an unavoidable delay no amount of remediation effort will compress.