Skip to content
Menu ▾
Patent pending

Regulayer  /  The 146 laws  /  Security standards

PCI DSS v4.0.1 · Requirement 10

Logging & monitoring of cardholder data access.

Applies to: Anyone storing/processing payment card data. Built · mandatory since 31 Mar 2025

What the signed record shows

Audit-log creation, protection from modification, review state, and retention.

The proof is a signed, tamper-evident record. Anyone can check it, free, without an account, and nothing has to leave the building to make it. Evidence, not a promise.

Citation: PCI DSS v4.0.1 Req 10.2/10.3/10.4/10.5.1

In the same family

What to do about it

Seven days free, then $349 a month.

A signed record of which AI you used and what you checked, sealed to the exact file you deliver, made on your own machine and checkable free by anyone you send it to.

Start the free weekOr verify a real record, free →

Part of the Regulayer proof catalogue: 146 laws and standards, one sealed engine. This page is a product description, not legal advice.

What the standard requires, section by section

PCI Security Standards Council, Payment Card Industry Data Security Standard (PCI DSS) v4.0.1. Requirement 10, "Log and Monitor All Access to System Components and Cardholder Data". Sub-requirements this mapper evidences from the per-event signed record:

10.2
Audit logs are implemented to support the detection of anomalies and suspicious activity, and the forensic analysis of events.
10.3
Audit logs are protected from destruction and unauthorized modifications.
10.4
Audit logs are reviewed to identify anomalies or suspicious activity.
10.5.1
Retain audit log history for at least 12 months, with at least the most recent three months immediately available for analysis. PCI DSS v4.0's future-dated requirements became mandatory on 31 March 2025.

Taken from the Regulayer entry for this instrument, which is built against the primary text.