PCI DSS Compliance
Go deep on PCI DSS: what the card-brand standard actually requires, how to shrink your cardholder data environment (the biggest cost lever), the 12 requirements, how you validate (SAQ, ASV scans, ROC), running a gap assessment, and staying compliant continuously. The payments deep-dive spoke — take it after the Compliance Frameworks hub. Educational, not legal/QSA advice.
"We use a processor so our CDE is tiny, we've mapped the 12 requirements, and here's our SAQ-ready gap-closed plan"
6 Interactive Sessions
Short, interactive sessions — watch it work, steer it, then build it yourself. Go deeper anytime with the full code walkthrough.
- 1
What PCI DSS actually is — and who makes the rules
PCI DSS is a standard the card brands wrote to protect cardholder data — enforced through your bank by contract, not by any government — and it applies the moment you store, process, or transmit card data.
- 2
The cardholder data environment & scope reduction — the one lever that decides the whole job
PCI applies to the cardholder data environment (CDE) — the systems that store, process, or transmit card data (and those connected to them) — so shrinking the CDE shrinks the work.
- 3
The 12 requirements — the whole shape on one page
PCI DSS's 12 requirements aren't 12 unrelated hurdles — they group into 6 goals, and most of them ARE the shared security controls you already know (access, encryption, logging, vuln management, policy), just made prescriptive for card data.
- 4
Validation & evidence — how you prove PCI compliance
PCI compliance isn't a claim you make — it's something you validate with the right method (SAQ or ROC) and back with real, dated evidence that shows your controls actually operate.
- 5
The gap assessment — know where you stand before you validate
A gap assessment is a self-audit against the 12 PCI DSS requirements before you validate — you rate each one (in place / partial / missing), but first you shrink what's in scope, because the cheapest gap to close is the requirement you no longer have.
- 6
Staying compliant
PCI is a continuous program, not an annual scramble: the shared security core plus PCI's overlays have to keep operating all year, with scope, scans, and validation on a recurring cadence.
Production patterns you'll master
Synthetic data included
- CDE scope examples (in/out)
- The 12 requirements (6 goals)
- Validation paths (SAQ/ROC/ASV/AOC)
- Gap checklist (12 items)
What you walk away with
Shareable portfolio
A public URL showing your module timeline, patterns mastered, and completion status.
All the code
Download everything as a ZIP — pipelines, guardrails, deployment configs. Yours forever.
Module walkthrough
Each module documented with deliverables and the production pattern you implemented.
Ready to build your pci dss compliance?
First course free. $20 per course after that.