PCI DSS Requirement 1 – Explained

PCI DSS Requirement 1 explained

PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards designed to ensure that all companies that process, store, or transmit credit card information maintain a secure environment. This article focuses on Requirement 1 of PCI DSS v4.0.1, covering what it entails, how it has evolved from v3.2.1, and what your organisation needs to do to stay compliant. 

For more on PCI DSS, see our Ultimate Guide. 

What is PCI DSS Requirement 1? 

Requirement 1: Install and Maintain Network Security Controls. 

This requirement aims to protect your Cardholder Data Environment (CDE) by ensuring a secure network perimeter is established and maintained. In PCI DSS v4.0.1, the focus is on network security controls (NSCs), which are technologies and processes designed to control traffic into and out of environments where cardholder data is stored, processed, or transmitted. 

By implementing robust NSCs, organisations can significantly reduce the risk of unauthorised access and strengthen their overall security posture. 

Why is Requirement 1 important? 

Requirement 1 lays the foundation for all other PCI DSS requirements. If your network is not properly segmented and controlled, attackers may gain access to sensitive systems more easily. NSCs are the first line of defence – if they are not properly configured and maintained, the effectiveness of other security measures is undermined. 

What’s changed in PCI DSS v4.0.1? 

In PCI DSS v3.2.1, Requirement 1 was stated as: 

“Install and maintain a firewall configuration to protect cardholder data.” 

In v4.0.1, this has been updated to: 

“Install and maintain network security controls.” 

This change reflects a broader and more flexible approach, recognising that firewalls alone may no longer be sufficient. The term network security controls encompasses a wider range of technologies, including: 

  • Cloud-native security controls 
  • Software-defined networking (SDN) 
  • Micro-segmentation tools 
  • Next-generation firewalls (NGFWs) 
  • Intrusion prevention systems (IPS) 

While the flexibility is welcome, it also introduces more complexity. Businesses must ensure controls are appropriately configured, documented, and monitored. 

A breakdown of Requirement 1 

1.1 Processes and mechanisms for installing and maintaining network security controls are defined and understood 

Organisations must establish and maintain a formal programme for deploying and managing NSCs. This programme must clearly document the purpose, configuration, and management of these controls. It should also define who is responsible for each control and how changes to configurations are approved and reviewed. A complete inventory of NSCs must be maintained, and configurations must be reviewed at least every six months to confirm that they are still effective, relevant, and secure. These requirements ensure that network defences are not only deployed but actively managed in a consistent and accountable way. 

1.2 Network security controls (NSCs) are configured and maintained 

This section requires NSCs to follow the principle of least privilege. All traffic must be denied by default, and only traffic that is explicitly authorised for a documented business need may be allowed. Controls must ensure that only necessary services, ports, and protocols are enabled, and those that remain must be configured securely. This minimises the attack surface and ensures that all permitted communication has a clear and deliberate purpose. 

1.3 Network access to and from the cardholder data environment is restricted 

Access between the cardholder data environment (CDE) and any other part of the network must be tightly controlled. NSCs must be placed between the CDE and both trusted and untrusted networks. Where wireless networks are present, NSCs must prevent all wireless traffic into the CDE by default. Only explicitly authorised wireless traffic may be allowed, and only where it is justified by a documented business need. Without effective segmentation, the entire network would be in PCI DSS scope, making segmentation a critical strategy for reducing risk and compliance overhead. 

1.4 Network connections between trusted and untrusted networks are controlled 

This requirement addresses how network traffic flows across trust boundaries. NSCs must be implemented between all trusted and untrusted networks, with configuration standards and network diagrams used to support enforcement. Inbound traffic from untrusted sources must be strictly limited to only authorised services and protocols, with all other traffic denied. Additional controls must include measures to block spoofed IP addresses and to protect internal IP addressing and routing information from disclosure. These protections help to prevent unauthorised access and reduce exposure to external threats, particularly in environments that include public-facing services such as DMZs. 

1.5 Risks to the CDE from computing devices that are able to connect to both untrusted networks and the CDE are mitigated 

Devices that connect to both untrusted networks (such as the internet) and the CDE, including employee-owned and company-managed laptops, present a significant risk if not properly secured. Organisations must ensure that such devices are configured with appropriate security settings, that those controls are always active, and that users cannot disable them without formal authorisation. Even temporary exceptions must be approved and documented. This requirement is especially important in mobile and remote working environments, where endpoints are more exposed to threats and can become a bridge for attacks into the CDE. 

Common challenges with Requirement 1 

Many organisations struggle with Requirement 1 due to: 

  • Poorly documented network architecture 
  • Limited in-house expertise to manage modern NSCs 
  • Legacy systems that don’t support granular controls 
  • Misconfigured or outdated firewall rule sets 

These issues often emerge during a PCI DSS gap analysis or formal assessment. An external review can help identify weaknesses and confirm whether your existing controls are truly effective. 

How Securious Can Help 

Securious has been a PCI QSAC since 2016, with a team of qualified, highly experienced PCI DSS QSA and 3DS assessors ready to assist you in achieving and maintaining compliance with the latest PCI DSS standards. 

Based in Exeter, Devon, we undertake PCI QSA work both nationally and internationally. As the only PCI DSS QSA company in the region, organisations in Devon, Cornwall, or Somerset can benefit from cost efficiencies with on-site assessments. 

Our mission is to build cybersecurity confidence. When it comes to PCI DSS compliance, we collaborate with you to make the process as efficient as possible, helping you understand what needs to be done and why. 

We offer three options to assist our clients with PCI DSS compliance: 

  1. PCI DSS QSA Gap Analysis & Assessment (one-off fee) 
    Read more about our PCI DSS QSA Gap Analysis & Assessment by clicking here.
  1. Managed PCI DSS Compliance Service (fixed monthly fee) 
    Read more about our Managed PCI DSS Compliance Service by clicking here.
  1. Assisted PCI DSS SAQ Compliance Service (one-off fee) 
    Read more about our Assisted PCI DSS SAQ Compliance Service by clicking here. 

Get in Touch to Get Started 

To learn more, visit our PCI services page, call us on 01392 247 110, email info@securious.co.uk, or send us a message using the form below. 

Find out whether you’re ready for PCI DSS v4.0.1 in minutes. 

Find out how much a PCI DSS engagement with Securious is likely to cost you with our online, free quote generator.