← PCI DSS 4.0.1 · Req 12 — Policies and programmes
12.5.2 — PCI DSS scope documented and confirmed annually
Requirement
PCI DSS scope is documented and confirmed at least once every 12 months and upon significant change — identifying all data flows, locations where account data is stored, processed and transmitted, connected systems, and segmentation controls — together with an inventory of in-scope system components.
What the engine looks for
Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.
Equivalent controls elsewhere
Matched on shared topics. Satisfying this control usually moves these too.
| Framework | Control | Title | Shared topics |
|---|---|---|---|
| GDPR | Art.30 | Records of processing activities | records inventory |
| GDPR | Art.5(2) | Accountability | records |
| CCPA/CPRA | Regs 7101 | Records of consumer requests kept for 24 months | records |
| SOC 2 | CC2.1 | Quality information for internal control | records |
| ISO 27001 | A.5.9 | Inventory of information and other associated assets | inventory |
| ISO 27001 | A.5.31 | Legal, statutory, regulatory and contractual requirements | records |
| GLBA | 314.4(c)(2) | Inventory of data, personnel, devices and systems | inventory |
| NIST CSF 2.0 | ID.AM-01 | Inventories of hardware are maintained | inventory |