STANDARD · CARD DATA · ALL JURISDICTIONS
PCI DSS v4.0 compliance for payment institutions in MENA.
Card data requirements mapped to the same control set as your regulator, evidenced continuously rather than rebuilt before each assessment.
What PCI DSS v4.0 covers
PCI DSS v4.0 is the payment card industry’s security standard for anyone who stores, processes or transmits cardholder data, published by the card schemes rather than by a government.
It has no jurisdiction of its own: it reaches you through your acquirer and the schemes, wherever you operate, and you demonstrate it by assessment rather than by supervision — so it sits alongside your regulator instead of replacing it.
Thiqa maps its requirements onto the controls you already run for that regulator, collects evidence from cloud and identity systems on schedule, and derives readiness from the evidence that exists, so a requirement going unanswered surfaces when it happens rather than at the assessment.
Runs alongside CBE
PCI DSS v4.0 FAQ
- Does PCI DSS replace what my regulator asks for?
- No, it sits alongside it. PCI DSS requirements map onto the same control set as CBE, FRA, SAMA or CBUAE, so an overlapping control is evidenced once rather than twice.
- What does continuous evidence change before an assessment?
- Readiness is derived from the evidence that exists rather than asserted in the weeks before, so an unanswered requirement shows as a gap when it happens instead of at the assessment.