PCI DSS Compliance Calculator
Track PCI DSS v4.0 readiness across the 12 requirements and roughly 277 sub-requirements, with compensating controls and ASV scans counted.
Inputs
v4.0 allows it, but each use needs a targeted risk analysis and a QSA-tested objective
PCI DSS Readiness Score
81.9%
Sub-Requirement Coverage
90.0%
Requirements Fully Met
66.7%
Applicable Sub-Requirements
259sub-reqs
Open Sub-Requirements
29sub-reqs
Indicative Remediation Time
6weeks
Attestation Verdict
Not compliant — 29 sub-requirement(s) open and 4 of the 12 requirements incomplete
Validation Route
Report on Compliance — annual QSA or ISA assessment plus quarterly ASV scanning
Approach Note
Defined approach only — controls must match the published PCI DSS v4.0 wording and testing procedures
Step by step
Values used
Sub-requirements in place = 230 sub-reqs; Sub-requirements not applicable to your environment = 18 sub-reqs; Sub-requirements met by a compensating control = 4 sub-reqs; Of the 12 requirements, how many are fully met = 8; Passing quarterly ASV scans in the last year = 3 scans; Validation route = Report on Compliance — Level 1 merchant or service provider; Using the customised approach for any control = No
PCI DSS Compliance
Readiness = 0.60 × sub-requirement coverage + 0.25 × requirements fully met + 0.15 × ASV scan record, where coverage = (in place + 0.75 × compensating) ÷ (277 − not applicable).
PCI DSS Readiness Score
= 81.9
Sub-Requirement Coverage
= 90.0
Requirements Fully Met
= 66.7
Applicable Sub-Requirements
= 259 sub-reqs
Open Sub-Requirements
= 29 sub-reqs
Indicative Remediation Time
= 6 weeks
How it works
PCI DSS is scored bottom-up: the 12 headline requirements decompose into roughly 277 testable sub-requirements, and compliance is binary at the sub-requirement level — an item is in place or it is not. Compensating controls count at three-quarter credit here because they satisfy an assessor only with a completed worksheet and are re-tested every year, and the ASV scan record is weighted separately because four passing quarterly scans is a hard external gate. PCI has no partial credit at attestation time, so the useful management number is how many sub-requirements are open and how long they will take — not an average that hides a single failed requirement. This is a readiness estimate; only a QSA or ISA can validate compliance.
Formula
PCI DSS Compliance
Readiness = 0.60 × sub-requirement coverage + 0.25 × requirements fully met + 0.15 × ASV scan record, where coverage = (in place + 0.75 × compensating) ÷ (277 − not applicable).
- 12
- PCI DSS requirements
- 277
- Approximate sub-requirement count in PCI DSS v4.0
- ccCredit
- Compensating controls at three-quarter credit, because each needs a worksheet and annual revalidation
Frequently Asked Questions
How is PCI DSS Compliance calculated?
Readiness = 0.60 × sub-requirement coverage + 0.25 × requirements fully met + 0.15 × ASV scan record, where coverage = (in place + 0.75 × compensating) ÷ (277 − not applicable). PCI DSS is scored bottom-up: the 12 headline requirements decompose into roughly 277 testable sub-requirements, and compliance is binary at the sub-requirement level — an item is in place or it is not. Compensating controls count at three-quarter credit here because they satisfy an assessor only with a completed worksheet and are re-tested every year, and the ASV scan record is weighted separately because four passing quarterly scans is a hard external gate.
Why does PCI DSS Compliance matter?
PCI has no partial credit at attestation time, so the useful management number is how many sub-requirements are open and how long they will take — not an average that hides a single failed requirement. This is a readiness estimate; only a QSA or ISA can validate compliance.
What values do I need to enter?
This calculator takes 7 inputs: Sub-requirements in place, Sub-requirements not applicable to your environment, Sub-requirements met by a compensating control, Of the 12 requirements, how many are fully met, Passing quarterly ASV scans in the last year, Validation route, Using the customised approach for any control. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Can I be 95% PCI compliant?
Not for the purposes of an attestation. Compliance is all-or-nothing across the applicable sub-requirements, so a 95% score means you are not compliant and have roughly fourteen items to close. The percentage is useful for tracking a programme, not for answering an acquirer.
Why is the ASV scan record weighted on its own?
Because it cannot be back-filled. Four passing quarterly external scans take a year of elapsed time, so a programme that starts scanning in month ten has an unavoidable delay no amount of remediation effort will compress.
You might also need
- ISO 27001 Compliance CalculatorCommonly used together
- Compliance Cost CalculatorCommonly used together
- Control Gap CalculatorCommonly used together
- Disaster Recovery RTO CalculatorAlso in Compliance & GRC
- Security Investment ROI CalculatorAlso in Compliance & GRC
- Residual Risk CalculatorAlso in Compliance & GRC