惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
T
The Blog of Author Tim Ferriss
宝玉的分享
宝玉的分享
The Register - Security
The Register - Security
D
Docker
The Cloudflare Blog
A
About on SuperTechFans
Microsoft Security Blog
Microsoft Security Blog
Recent Announcements
Recent Announcements
月光博客
月光博客
B
Blog RSS Feed
博客园 - 【当耐特】
The GitHub Blog
The GitHub Blog
B
Blog
IT之家
IT之家
美团技术团队
Engineering at Meta
Engineering at Meta
C
Check Point Blog
云风的 BLOG
云风的 BLOG
Last Week in AI
Last Week in AI
G
Google Developers Blog
MongoDB | Blog
MongoDB | Blog
Microsoft Azure Blog
Microsoft Azure Blog
S
SegmentFault 最新的问题
V
V2EX
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Apple Machine Learning Research
Apple Machine Learning Research
U
Unit 42
H
Help Net Security
雷峰网
雷峰网
人人都是产品经理
人人都是产品经理
博客园 - 司徒正美
Stack Overflow Blog
Stack Overflow Blog
博客园 - Franky
PCI Perspectives
PCI Perspectives
J
Java Code Geeks
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
M
MIT News - Artificial intelligence
腾讯CDC
A
Arctic Wolf
C
CERT Recently Published Vulnerability Notes
量子位
C
CXSECURITY Database RSS Feed - CXSecurity.com
Latest news
Latest news
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
The Hacker News
The Hacker News
有赞技术团队
有赞技术团队
Schneier on Security
Schneier on Security
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻

PCI Perspectives

2026 North America Community Meeting Agenda Highlights Meet the Council’s New Head of Business Operations and Risk Management The AI Exchange: Innovators in Payment Security Featuring PCA Cyber Security Enhance Your Community Meeting Experience with Interactive Workshops The AI Exchange: Innovators in Payment Security Featuring PROSA Bring PCI SSC Training to Your Organization with the New Training Venue Host Program The AI Exchange: Innovators in Payment Security Featuring Utimaco Coffee with the Council Podcast: Meet This Year’s North America Community Meeting Keynote Speaker, Sharon Gai Welcome Our Newest Associate Participating Organizations The AI Exchange: Innovators in Payment Security Featuring SecurityMetrics PCI SSC Publishes New Guidance on Compensating Controls and the Customized Approach Spotlight On: Dreamplug Technologies Private Limited (CRED), a New Principal Participating Organization Request for Comments: PCI Data Security Standard (PCI DSS) v4.0.1 The AI Exchange: Innovators in Payment Security Featuring In-Solutions Global Ltd Coffee with the Council Podcast: Nominate Now for the Global Executive Assessor Roundtable (GEAR) PCI SSC Publishes PCI PTS HSM v5.0 Request for Comments: PCI Secure Software Lifecycle Standard v2.0 Spotlight On: Worldline, a New Principal Participating Organization Coffee with the Council Podcast: Stronger Together – The Value of Participating with PCI SSC The AI Exchange: Innovators in Payment Security Featuring Dreamplug Technologies Private Limited (CRED) Level Up Your Payment Security Expertise with PCI SSC Knowledge Training PCI SSC Launches Enhanced Language Microsites for Global Audience Exhibit at or Sponsor the 2026 Community Meetings Spotlight On: Stripe, a New Principal Participating Organization The AI Exchange: Innovators in Payment Security Featuring Toast, Inc. Coffee with the Council Podcast: A Panel Discussion on Cryptography The AI Exchange: Innovators in Payment Security Featuring Flywire Spotlight On: Amazon, a New Principal Participating Organization Welcome Our Newest Associate Participating Organizations The AI Exchange: Innovators in Payment Security Featuring Checkout.com Coffee with the Council Podcast: PCI SSC Publishes First-Ever Annual Report The AI Exchange: Innovators in Payment Security Featuring Bank of America Request for Comments: PCI Card Production and Provisioning Physical and Logical Security Standards v3.0.1 Spotlight On: Futurex, a New Principal Participating Organization The AI Exchange: Innovators in Payment Security Featuring Soft Space PCI Security Standards Council Publishes First-Ever Annual Report Coffee with the Council Podcast: PCI SSC Releases Version 2.0 of the PCI Secure Software Standard PCI SSC 2025 Community Meetings Now Available on Global Content Library PCI SSC Releases Version 2.0 of the PCI Secure Software Standard 2026 PCI SSC Training Schedule Announced Spotlight On: Reflectiz, a New Principal Participating Organization The AI Exchange: Innovators in Payment Security Featuring Jscrambler Meet the Council’s New Client Engagement Operations Director The AI Exchange: Innovators in Payment Security Featuring SISA Meet the Council’s New Director, Training Programs Request for Comments: PCI Key Management Operations (KMO) v1.0 Standard PCI SSC Publishes Mobile Payments on COTS (MPoC) Guidance Document The AI Exchange: Innovators in Payment Security Featuring Block, Inc. Request for Comments: PCI PTS HSM v5.0 Coffee with the Council Podcast: Nominate Your Company for the Council’s Next Brazil Regional Engagement Board 2025 Asia-Pacific Community Meeting Agenda Highlights The AI Exchange: Innovators in Payment Security Featuring Elavon Inc. Coffee with the Council Podcast: Meet the New Regional Director of Japan and South Korea, Junichi Tsuboi Internal Security Assessor (ISA) Training Case Study: WestJet Sneak Peek: 2025 Europe Community Meeting Speakers AI Principles: Securing the Use of AI in Payment Environments The AI Exchange: Innovators in Payment Security Featuring Cloud Security Alliance Beware of PCI DSS Compliance Certificates Meet the Council’s New Regional Director, Europe PCI SSC Releases New Guidance on Authentication and Cryptography Welcome Our Newest Associate Participating Organizations Sneak Peek: 2025 North America Community Meeting Speakers Coffee with the Council Podcast: Meet This Year’s Asia-Pacific Community Meeting Keynote Speaker, Sharon Gai The AI Exchange: Innovators in Payment Security Featuring Salesforce
Mapping PCI DSS v4.0.1 to the NIST Cybersecurity Framework 2.0
Alicia Malone · 2026-07-24 · via PCI Perspectives

The PCI Security Standards Council (PCI SSC) has published a document which maps the PCI Data Security Standard (PCI DSS) v4.0.1 to the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) 2.0. With both organizations sharing the common goal to enhance data security, this document provides a resource for stakeholders to use in understanding how to align security efforts to meet objectives in both PCI DSS and the NIST CSF.  

In this blog, we interviewed Chelsea Lopez, Client Engagement Operations Director at PCI SSC, to discuss how meeting PCI DSS requirements can help toward achieving NIST CSF outcomes for secure payment environments.  

1. Tell us a little about the mapping document published by PCI SSC.

Chelsea Lopez: This is a really great example of our PCI SSC community coming together to build something by the industry, for the industry. This effort represents an update to work that PCI SSC published in 2019, mapping the previous versions of these two sets of security controls.

The PCI DSS v4.0.1 to NIST Cybersecurity Framework 2.0 mapping document was developed by the PCI SSC Board of Advisors as a tool to support organizations’ security control management efforts. Recognizing that both PCI DSS v4.0.1 and NIST CSF 2.0 share the common goal of strengthening and enhancing data security, the mapping document provides a practical resource for stakeholders to use in understanding how to align security efforts to meet objectives in both PCI DSS and NIST CSF. 

2. What are the primary differences between PCI DSS and the NIST Cybersecurity Framework?

Chelsea Lopez: NIST CSF helps organizations manage cybersecurity risk by defining high-level cybersecurity outcomes rather than prescribing specific controls. It provides a common structure for understanding, assessing, prioritizing, and communicating cybersecurity risks. It can be used by any organization to better understand, assess, prioritize, and communicate its cybersecurity efforts.  

PCI DSS defines security requirements specific for the protection of payment data. PCI SSC also provides supporting validation and guidance documentation to help organizations understand the intent of the requirements. PCI DSS is designed to protect environments for organizations that are involved in storing, processing, or transmitting payment data. 

3. Are PCI DSS requirements and the NIST Cybersecurity Framework interchangeable?

Chelsea Lopez: Both PCI DSS and NIST CSF are solid security approaches that address common security goals and principles as relevant to specific risks. While NIST CSF identifies general security outcomes and activities, PCI DSS provides specific direction and guidance on how to meet security outcomes for payment environments. When used together, PCI DSS and NIST CSF can provide a holistic approach to managing cybersecurity risk. Because PCI DSS and NIST CSF are intended for different audiences and uses, they are not interchangeable, and neither one is a replacement for the other. 

cm-banner-ad-website@2x

4. How should stakeholders engage with the mapping document produced by PCI SSC?

Chelsea Lopez: Stakeholders can use this mapping to identify opportunities for control reporting efficiencies and greater alignment between organizational security objectives. For example, the mapping can help identify where the implementation of a particular security control can support both a PCI DSS requirement and a NIST Cybersecurity Framework outcome. Additionally, an entity’s internal evaluations to determine the effectiveness of implemented controls may help the entity prepare for either a PCI DSS or NIST Cybersecurity Framework assessment, or both. As a reminder, organizations should always consult with their internal security and legal counsel to determine what security requirements may be applicable to their organization. 

5. Where can stakeholders find additional resources regarding mapping PCI DSS to the NIST Cybersecurity Framework?

Chelsea Lopez: We have a variety of helpful resources available on the PCI SSC website, including a one-page Executive Brief, an At-A-Glance Summary document, and the full mapping document. These are now available in our Document Library and linked below for easy access.  

Download Mapping PCI DSS to NIST Cybersecurity Framework DocumentDownload Mapping PCI DSS to NIST Cybersecurity Framework Executive BriefDownload Mapping PCI DSS to NIST Cybersecurity Framework At-A-Glance