Skip to content
Calcrivo

PCI DSS Compliance Calculator

Track PCI DSS v4.0 readiness across the 12 requirements and roughly 277 sub-requirements, with compensating controls and ASV scans counted.

Inputs

sub-reqs
sub-reqs
sub-reqs
scans

v4.0 allows it, but each use needs a targeted risk analysis and a QSA-tested objective

PCI DSS Readiness Score

81.9%

Sub-Requirement Coverage

90.0%

Requirements Fully Met

66.7%

Applicable Sub-Requirements

259sub-reqs

Open Sub-Requirements

29sub-reqs

Indicative Remediation Time

6weeks

Attestation Verdict

Not compliant — 29 sub-requirement(s) open and 4 of the 12 requirements incomplete

Validation Route

Report on Compliance — annual QSA or ISA assessment plus quarterly ASV scanning

Approach Note

Defined approach only — controls must match the published PCI DSS v4.0 wording and testing procedures

Step by step

  1. Values used

    Sub-requirements in place = 230 sub-reqs; Sub-requirements not applicable to your environment = 18 sub-reqs; Sub-requirements met by a compensating control = 4 sub-reqs; Of the 12 requirements, how many are fully met = 8; Passing quarterly ASV scans in the last year = 3 scans; Validation route = Report on Compliance — Level 1 merchant or service provider; Using the customised approach for any control = No

  2. PCI DSS Compliance

    Readiness = 0.60 × sub-requirement coverage + 0.25 × requirements fully met + 0.15 × ASV scan record, where coverage = (in place + 0.75 × compensating) ÷ (277 − not applicable).

  3. PCI DSS Readiness Score

    = 81.9

  4. Sub-Requirement Coverage

    = 90.0

  5. Requirements Fully Met

    = 66.7

  6. Applicable Sub-Requirements

    = 259 sub-reqs

  7. Open Sub-Requirements

    = 29 sub-reqs

  8. Indicative Remediation Time

    = 6 weeks

How it works

PCI DSS is scored bottom-up: the 12 headline requirements decompose into roughly 277 testable sub-requirements, and compliance is binary at the sub-requirement level — an item is in place or it is not. Compensating controls count at three-quarter credit here because they satisfy an assessor only with a completed worksheet and are re-tested every year, and the ASV scan record is weighted separately because four passing quarterly scans is a hard external gate. PCI has no partial credit at attestation time, so the useful management number is how many sub-requirements are open and how long they will take — not an average that hides a single failed requirement. This is a readiness estimate; only a QSA or ISA can validate compliance.

Formula

PCI DSS Compliance

Readiness = 0.60 × sub-requirement coverage + 0.25 × requirements fully met + 0.15 × ASV scan record, where coverage = (in place + 0.75 × compensating) ÷ (277 − not applicable).

12
PCI DSS requirements
277
Approximate sub-requirement count in PCI DSS v4.0
ccCredit
Compensating controls at three-quarter credit, because each needs a worksheet and annual revalidation

Frequently Asked Questions

How is PCI DSS Compliance calculated?

Readiness = 0.60 × sub-requirement coverage + 0.25 × requirements fully met + 0.15 × ASV scan record, where coverage = (in place + 0.75 × compensating) ÷ (277 − not applicable). PCI DSS is scored bottom-up: the 12 headline requirements decompose into roughly 277 testable sub-requirements, and compliance is binary at the sub-requirement level — an item is in place or it is not. Compensating controls count at three-quarter credit here because they satisfy an assessor only with a completed worksheet and are re-tested every year, and the ASV scan record is weighted separately because four passing quarterly scans is a hard external gate.

Why does PCI DSS Compliance matter?

PCI has no partial credit at attestation time, so the useful management number is how many sub-requirements are open and how long they will take — not an average that hides a single failed requirement. This is a readiness estimate; only a QSA or ISA can validate compliance.

What values do I need to enter?

This calculator takes 7 inputs: Sub-requirements in place, Sub-requirements not applicable to your environment, Sub-requirements met by a compensating control, Of the 12 requirements, how many are fully met, Passing quarterly ASV scans in the last year, Validation route, Using the customised approach for any control. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Can I be 95% PCI compliant?

Not for the purposes of an attestation. Compliance is all-or-nothing across the applicable sub-requirements, so a 95% score means you are not compliant and have roughly fourteen items to close. The percentage is useful for tracking a programme, not for answering an acquirer.

Why is the ASV scan record weighted on its own?

Because it cannot be back-filled. Four passing quarterly external scans take a year of elapsed time, so a programme that starts scanning in month ten has an unavoidable delay no amount of remediation effort will compress.

You might also need