Compliance — PCI DSS v4.0
PCI DSS v4.0 monitoring — Requirement 10 covered, every day
PCI DSS Requirement 10 mandates daily log review, 12-month retention, and tamper-evident logging across all CDE components. ManySignal automates all three — with QSA-ready evidence export and Magecart detection for checkout page integrity.
PCI DSS v4.0 — what changed and why it matters
Requirement 6.4.2 — Web Application Protection
New in v4.0: organisations must have an automated technical solution (not just a WAF policy) to detect and protect against web application attacks on payment pages. ManySignal's checkout integrity monitoring directly addresses this requirement.
Daily Log Review Automation
Requirement 10.4.1 has been clarified in v4.0 to support automated log review as the preferred method over manual sampling. ManySignal's automated daily review provides stronger evidence than manual processes and eliminates the sampling risk.
Customised Approach
v4.0 introduces a Customised Approach option for meeting requirements via alternative controls. ManySignal's behavioural analytics capabilities can support Customised Approach implementations where standard controls are operationally impractical.
Control mapping — PCI DSS v4.0 to ManySignal
| Requirement | Control Name | ManySignal Capability |
|---|---|---|
| PCI DSS 10.2.1 | Audit Log Events | Log collection from all CDE in-scope components — firewalls, servers, databases, payment applications, and access control systems |
| PCI DSS 10.3.2 | Audit Log Protection | Tamper-evident log storage — any modification to log data triggers an immediate alert |
| PCI DSS 10.4.1 | Daily Log Review | Automated daily log analysis — eliminates manual review burden while providing evidence of the required daily review |
| PCI DSS 10.5.1 | Audit Log Retention — 12 months | 12-month hot retention with 3-month immediate accessibility for PCI DSS-scoped components |
| PCI DSS 10.6.1 | Time Synchronisation | NTP synchronisation anomaly detection — clock drift on CDE systems flagged immediately |
| PCI DSS 11.5.1 | Change-Detection Mechanisms | File integrity monitoring for critical CDE system files and checkout page content |
| PCI DSS 12.10.1 | Incident Response Plan | Automated response playbooks for PCI-relevant incident types — triggered immediately on suspected cardholder data breach |
| PCI DSS 12.10.4 | Incident Response Training | Incident exercise evidence — tabletop exercise documentation and response metrics |
| PCI DSS 6.4.2 | Web Application Controls | WAF log monitoring for web application attack patterns — SQL injection, XSS, and API abuse detection |
| PCI DSS 8.3.6 | MFA for Admin Access | MFA bypass and fatigue attack detection for administrative access to CDE systems |
QSA-ready evidence export
Coverage report
A per-CDE-component report showing which systems are monitored, which log sources are connected, and which Requirement 10.2.1 event types are collected. QSAs use this to validate scope coverage.
Daily review log
A timestamped record of every automated daily log review event for the assessment period. Each day shows: alerts generated, anomalies detected, cases opened, and auto-closed false positives.
Incident response evidence
For any PCI-relevant incidents during the assessment period, ManySignal generates a Requirement 12.10.1-formatted incident report — detection timeline, containment actions, and evidence of plan execution.
Compliance and audit status
ManySignal's SOC 2 Type II report (available under NDA at trust@manysignal.com) covers the security controls relevant to PCI DSS trust. ManySignal is not itself a PCI DSS-certified service — it is a monitoring tool used to achieve and evidence PCI DSS compliance. Customers are responsible for selecting a QSA and completing their own PCI DSS assessment.
PCI DSS compliance — common questions
Does ManySignal address PCI DSS v4.0 specifically, or just v3.2.1?
ManySignal maps to PCI DSS v4.0 (March 2022), which became the only active version in March 2024 after v3.2.1 retirement. The platform addresses all new v4.0 requirements relevant to monitoring — including the updated Requirements 6.4.2 (automated web application protection) and 12.10.4 (security team training evidence). The control mapping table on this page uses v4.0 requirement IDs.
Can ManySignal help establish my PCI DSS scope and demonstrate segmentation?
ManySignal monitors network traffic crossing your CDE scope boundary and generates a segmentation validation report — documenting which systems can and cannot communicate with the CDE. This supports Requirement 4 (protect cardholder data in transit) and the scoping reduction evidence that QSAs review during assessments. Any unexpected connection from an out-of-scope system to the CDE triggers an immediate alert.
How does ManySignal address Requirement 10.4.1 — Daily Log Review?
Requirement 10.4.1 mandates daily review of security event logs for CDE components. ManySignal automates this: the system reviews 100% of logs daily (not a sample), surfaces anomalies, and generates a daily review summary report. This report serves as evidence of the required daily review and is more comprehensive than manual sampling — which is explicitly noted in v4.0 as the preferred approach.
Can ManySignal detect Magecart-style web skimming attacks relevant to PCI DSS Requirement 6.4.2?
Yes. PCI DSS v4.0 Requirement 6.4.2 requires an automated technical solution to detect and protect against web application attacks for payment pages. ManySignal monitors checkout page content integrity via synthetic monitoring probes, WAF logs for script injection patterns, and unusual POST requests from checkout pages to external domains — all of which are Magecart attack indicators. Detection typically occurs within minutes of injection.
What is the QSA's role versus ManySignal's role in PCI DSS compliance?
A QSA (Qualified Security Assessor) validates that your controls meet PCI DSS requirements through assessment, sampling, and evidence review. ManySignal provides the monitoring infrastructure and evidence that the QSA assesses. ManySignal's evidence export is designed to reduce QSA assessment effort: the audit package provides all Requirement 10 log evidence in a structured format, with the coverage report showing which CDE components are monitored.
See PCI DSS evidence export in action
Connect your CDE scope, walk through the Requirement 10 coverage report, and see a QSA-ready evidence package generated from live data — in one session.