Compliance, PCI DSS

PCI DSS Compliance with Offline Secure Storage

Protect cardholder data and meet PCI DSS 4.0 requirements by removing sensitive payment data from network-accessible environments.

  • Offline by default
  • Identity locked access
  • Hardware encrypted
Framework matrix
Security analyst reviewing an isolated workstation with disconnected cables

$4.88M

Average cost of a payment data breach

12

Core PCI DSS requirements

2025

PCI DSS 4.0 full enforcement year

01The requirement

PCI DSS 4.0 Requirements

PCI DSS 4.0 introduces stricter requirements for protecting stored cardholder data, with customised approaches requiring demonstrable security controls.

This is a mapping, not a certification claim. Firevault holds Cyber Essentials Plus. Everything else on this page is stated as alignment: Offline Secure Storage® produces evidence you can point at in your own submission, assessment or audit.

02What is tested

PCI DSS Core Requirements

Each line below is something an assessor, regulator or underwriter can ask you to evidence.

Protect stored cardholder data

Encrypt transmission of cardholder data

Restrict access to cardholder data by business need

Regularly monitor and test networks

03Consequences

Non-Compliance Risks

What happens when the control is missing, and the record cannot be produced.

Processing Restrictions

Loss of ability to process card payments

Financial Penalties

Fines from $5,000 to $100,000 per month

Forensic Audits

Mandatory third-party security assessments

Increased Liability

Full liability for fraudulent transactions

04The architecture

How OSS Supports PCI DSS Compliance

Offline Secure Storage removes cardholder data from network-accessible systems, directly addressing multiple PCI DSS requirements.

Network Segmentation

Physical disconnection is the ultimate network segmentation

Access Control

Identity-verified access with full audit trails

Encryption

Hardware-level encryption for all stored data

Scope Reduction

Reduce your CDE footprint by moving archived data offline

05What sits offline

Payment Data Protected

The records most often moved into Offline Secure Storage® for this framework.

Archived cardholder data

Transaction records and logs

Payment processing documentation

Security audit evidence

Key management records

Compliance assessment reports

Mark Fermor
David Bailey
Kenny Phipps
Online Now
Concierge

Tell us which framework you are being tested against.

We will map Offline Secure Storage® to the outcomes your assessor is checking, and give you the wording and evidence to submit.

Takes about 2 minutes. No account needed.

Free2 minsNo sign-up