projects/pci-dss-4-0-1/case-study.md
public summary

Azion

PCI DSS 4.0.1 early adoption

Helped lead delivery of PCI DSS 4.0.1 Level 1 Service Provider compliance, coordinating the implementation of newly applicable requirements across a globally distributed technology platform.

PCI DSS 4.0.1Audit ReadinessControl Design
organization
Azion
publication
Public, sanitized summary
result.output
Newly applicable requirements delivered ahead of schedule

01 / context

The challenge.

Move an established PCI DSS program to version 4.0.1 while addressing newly applicable requirements and maintaining a clear, evidence-backed path to assessment.

02 / responsibility

My responsibility.

Helped lead the compliance program, translating new requirements into implementation work, coordinating accountable teams, and supporting readiness for independent assessment.

03 / approach

How the work was approached.

  1. Reviewed the standard changes and identified newly applicable requirements.

  2. Converted compliance requirements into clear implementation and evidence expectations.

  3. Coordinated progress and ownership across the teams involved in the assessment scope.

  4. Maintained audit-readiness visibility through structured tracking and documentation.

04 / outcomes

Verified outcomes.

  • Delivered newly applicable requirements ahead of schedule.

  • Supported Azion's attestation as a PCI DSS 4.0.1 Level 1 Service Provider.

  • Strengthened the operating foundation for recurring PCI DSS compliance.

verify certification(opens in a new tab)

05 / disclosure

Responsible disclosure.

This public summary omits control implementation details, assessment evidence, system architecture, and information protected by confidentiality obligations.

Browse all selected projects