Install any skill in seconds. Free to start, no credit card required.
Get Started Free →PCI DSS v4.0 payment card data security compliance, assessment, and implementation. Use for PCI DSS scoping, cardholder data environment (CDE) security, SAQ and ROC preparation, QSA engagement, tokenization, and merchant compliance.
.claude/skills/borghei-pci-dss-specialist/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-03 | ✗→✓ | ▲ Improved | 15% | 0% |
| case-13 | ✗→✓ | ▲ Improved | 33% | 0% |
| case-04 | ✗→✓ | ▲ Improved | 18% | 0% |
| case-05 | ✗→✓ | ▲ Improved | 25% | 0% |
| case-06 | ✗→✓ | ▲ Improved | 101% | 0% |
Implement, assess, and maintain compliance with the Payment Card Industry Data Security Standard version 4.0 — the global standard for protecting cardholder data in payment processing environments. Covers CDE scoping, SAQ/ROC selection, gap assessment against all 12 requirements, scope reduction (tokenization, P2PE, segmentation), and the future-dated v4.0 controls that became mandatory March 31, 2025.
pci_compliance_checker.py)pci_scope_analyzer.py)Trigger on: "PCI DSS", "payment card security", "cardholder data", "PCI compliance", "payment security", "PCI assessment", "SAQ", "ROC", "QSA", "credit card security", "payment processing security", "tokenization", "CDE scoping", or "merchant level compliance".
Before running the assessment or scoping, confirm these inputs. If any is unknown or vague, ASK — do not assume:
Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the report.
bash# Check PCI compliance status (JSON report) python scripts/pci_compliance_checker.py --input controls.json --output compliance_report.json # Compliance gap report for stakeholders (Markdown) python scripts/pci_compliance_checker.py --input controls.json --format markdown --output gap_report.md # Determine SAQ type / analyze CDE scope python scripts/pci_scope_analyzer.py --input business_model.json --output scope_report.json python scripts/pci_scope_analyzer.py --input business_model.json --format markdown --output scope_analysis.md
Run --requirements 3,4,7,8 to scope the checker to specific requirements. Full tool detail, input JSON formats, and flag reference live in the tools reference below.
Load the reference that matches the task — keep this file lean and pull detail on demand:
In Scope:
Out of Scope:
| Skill | Integration | |-------|------------| | infrastructure-compliance-auditor | Validates network segmentation, TLS configuration, endpoint security, and logging controls that satisfy PCI DSS Requirements 1, 2, 4, 10, 11 | | nist-csf-specialist | CSF functions map to PCI DSS requirements; use the control mapper to build unified control matrices for dual-compliance programs | | soc2-compliance-expert | SOC 2 CC6 (access), CC7 (operations), CC8 (change management) overlap significantly with PCI DSS; leverage shared evidence | | information-security-manager-iso27001 | ISO 27001 Annex A controls provide a management system framework supporting PCI DSS compliance | | nis2-directive-specialist | EU entities subject to both NIS2 and PCI DSS can map shared controls (encryption, incident response, access control) |
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→fail | 4,972 | 31,187 | +527% | 1 | 1 | 0% | 744 | 2,048 | +175% | 0 | 0 | — |
case-02 | fail→fail | 23,941 | 34,743 | +45% | 1 | 1 | 0% | 4,159 | 6,760 | +63% | 0 | 0 | — |
case-03 | fail→pass | 10,872 | 3,746 | -66% | 1 | 1 | 0% | 1,856 | 2,139 | +15% | 0 | 0 | — |
case-13 | fail→pass | 9,453 | 2,493 | -74% | 1 | 1 | 0% | 1,520 | 2,023 | +33% | 0 | 0 | — |
case-04 | fail→pass | 10,890 | 2,838 | -74% | 1 | 1 | 0% | 1,831 | 2,161 | +18% | 0 | 0 | — |
case-05 | fail→pass | 11,660 | 5,867 | -50% | 1 | 1 | 0% | 2,090 | 2,611 | +25% | 0 | 0 | — |
case-06 | fail→pass | 7,516 | 4,751 | -37% | 1 | 1 | 0% | 1,228 | 2,468 | +101% | 0 | 0 | — |
case-07 | pass→pass | 8,930 | 2,495 | -72% | 1 | 1 | 0% | 1,440 | 1,993 | +38% | 0 | 0 | — |
case-08 | fail→pass | 9,686 | 5,187 | -46% | 1 | 1 | 0% | 1,690 | 2,577 | +52% | 0 | 0 | — |
case-09 | fail→pass | 8,211 | 3,154 | -62% | 1 | 1 | 0% | 1,351 | 2,231 | +65% | 0 | 0 | — |
case-10 | fail→pass | 8,942 | 4,306 | -52% | 1 | 1 | 0% | 1,541 | 2,320 | +51% | 0 | 0 | — |
case-11 | fail→pass | 8,132 | 3,852 | -53% | 1 | 1 | 0% | 1,255 | 2,400 | +91% | 0 | 0 | — |
case-12 | fail→pass | 15,438 | 4,065 | -74% | 1 | 1 | 0% | 2,472 | 2,305 | -7% | 0 | 0 | — |
case-14 | pass→pass | 15,740 | 7,995 | -49% | 1 | 1 | 0% | 2,525 | 3,054 | +21% | 0 | 0 | — |
case-15 | pass→pass | 25,308 | 21,315 | -16% | 1 | 1 | 0% | 2,964 | 5,442 | +84% | 0 | 0 | — |
case-16 | pass→pass | 11,605 | 13,627 | +17% | 1 | 1 | 0% | 1,980 | 4,004 | +102% | 0 | 0 | — |
case-17 | pass→pass | 5,309 | 5,500 | +4% | 1 | 1 | 0% | 876 | 2,551 | +191% | 0 | 0 | — |
case-18 | fail→pass | 8,489 | 2,896 | -66% | 1 | 1 | 0% | 1,167 | 2,046 | +75% | 0 | 0 | — |
case-19 | pass→pass | 16,030 | 18,070 | +13% | 1 | 1 | 0% | 2,373 | 4,820 | +103% | 0 | 0 | — |
case-20 | pass→pass | 6,415 | 13,149 | +105% | 1 | 1 | 0% | 905 | 3,646 | +303% | 0 | 0 | — |
case-21 | pass→pass | 8,585 | 13,155 | +53% | 1 | 1 | 0% | 1,441 | 3,336 | +132% | 0 | 0 | — |
case-22 | pass→pass | 10,739 | 11,050 | +3% | 1 | 1 | 0% | 1,621 | 3,264 | +101% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted, and 21 counted toward the lift figure. The other 1 produced results that are not comparable between the two arms, so they are excluded from the headline rather than averaged into it. The headline lift of +50 percentage points is the difference between those two pass rates over the 21 comparable cases. 1 case got worse with the skill loaded, and it is included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.