By: Derek Rogers on Sep 29, 2026, 1:33:26 PM

Parent Requirement 1.1
Processes and mechanisms for installing and maintaining network security controls are defined and understood.
PCI DSS Requirement 1.1.1
All Security policies and operational procedures that are identified in Requirement 1 are:
Priority: 6 (Lowest out of 6)
Priority Meaning: Complete remaining compliance efforts, and ensure all controls are in place. This milestone completes PCI DSS requirements and finishes all remaining related policies, procedures, and processes needed to protect the cardholder data environment.
Requirement 1.1.1 mandates that organizations formally manage the policies and procedures supporting PCI DSS Requirement 1. Organizations must create, maintain, and update security policies and operational procedures. Additionally, these documents must be actively followed and communicated to personnel responsible for implementing or supporting network security controls.
A frequent misconception is that compliance is achieved solely through documentation. However, PCI DSS requires that policies and procedures accurately reflect current practices. Personnel must understand their responsibilities, and organizations must demonstrate that documented processes are consistently followed.
To ensure compliance, organizations should be able to address the following four questions:
If any of these questions cannot be answered affirmatively, the organization may face challenges in demonstrating compliance with Requirement 1.1.1.
Network security controls, including firewalls, routers, cloud security groups, network segmentation controls, and access control lists, are essential for protecting cardholder data. However, these technologies are only effective when administrators manage them consistently and according to clear guidance.
Requirement 1.1.1 establishes the governance framework for Requirement 1 by ensuring that expectations are documented, responsibilities are clearly communicated, and processes are consistently repeatable.
In the absence of documented and maintained procedures, the following risks may arise:
Applicability of the Self-Assessment Questionnaire (SAQ)
Requirement 1.1.1 is included under PCI DSS Requirement 1 and is typically applicable in all contexts where Requirement 1 applies. This includes;
Since SAQ applicability may differ based on the payment environment and the validation method employed, organizations should consult the latest PCI SSC SAQ guidance to verify applicability.
Requirement 1.1.1 applies to the management of security policies and operational procedures governing network security controls that protect the PCI DSS environment.
PCI DSS requirements apply to the Cardholder Data Environment (CDE), which is comprised of:
PCI DSS also applies to:
Definition: Cardholder Data Environment (CDE)
The Cardholder Data Environment (CDE) encompasses the people, systems, networks, and processes responsible for storing, processing, transmitting, or protecting payment card data.
Examples include payment applications, firewalls that protect payment systems, payment databases, network administrators, and documented procedures that support these systems.
Although Requirement 1.1.1 may initially appear to be a documentation requirement, it is fundamentally a governance requirement.
The objective is to ensure that all network security activities addressed in Requirement 1 are conducted in a controlled and repeatable manner.
The requirement establishes four expectations.
Policies and Procedures Must be Documented
Personnel must not rely on memory or verbal instructions when managing network security controls. Expectations must be documented and readily accessible.
Examples may include:
- Firewall management policies
- Network security standards
- Rule review procedures
- Network configuration procedures
- Segmentation validation procedures
Policies and Procedures Must be Kept up to Date
Documentation must accurately reflect the current management of network security controls.
Documentation must be updated promptly to reflect changes in technologies, responsibilities, or processes.
Assessment failures often occur when procedures describe activities that are no longer performed or reference obsolete technologies.
Policies and Procedures Must be in Use
Well-written policies have limited value if they are not consistently followed by personnel.
Assessors routinely compare documented procedures with actual practices. Major discrepancies between documentation and operational practices may result in compliance concerns.
Policies and Procedures Must be Known to Affected Parties
Relevant personnel must understand the policies and procedures applicable to their responsibilities.
For example:
- Firewall administrators should understand firewall management procedures.
- Network engineers should understand change control requirements.
- Managers should understand approval responsibilities.
- Security personnel should understand review requirements.
Posting a document in a repository alone does not demonstrate personnel awareness.
Organizations commonly establish a hierarchical documentation structure to support Requirement 1.
Security Policy
Defines management expectations and objectives.
Example:
Network security controls must be implemented and managed to ensure the protection of the Cardholder Data Environment.
Standard
Defines mandatory requirements.
Example:
Firewall rule reviews must be conducted at a minimum of every six months.
Procedure
Describes the process by which the activity is performed.
Example:
The firewall administrator exports active rules, reviews the business justification, obtains management approval, and stores the review records.
Requirement 1.1.1 may be satisfied through several practical approaches.
Option 1: Centralized Policy Management
All PCI-related policies and procedures should be maintained in a centralized repository.
Benefits:
Example:
- SharePoint
- Document management systems
- Governance, risk, and compliance platforms
- Internal policy portals
Option 2: Formal Review Process
Periodic reviews of Requirement 1 documentation should be established.
Common review frequencies include:
An effective review process should verify the following elements:
Option 3: Change-Driven Updates
Documents should be updated whenever significant changes occur, rather than waiting for an annual review.
Examples include:
- Firewall replacement
- Cloud migration
- Network redesign
- Organizational restructuring
- New service providers
This approach is consistent with PCI DSS guidance, which recommends updating documents as soon as possible following changes.
Option 4: Formal Communication and Acknowledgment
Personnel may be required to formally acknowledge policies and procedures.
Examples include:
- Annual policy attestation
- Security awareness platforms
- Learning management systems
- Signed acknowledgments
This process demonstrates that affected individuals are aware of their responsibilities.
Baseline Evidence Requirements
Organizations are generally expected to maintain the following:
Enhanced Evidence for Maturity
Organizations demonstrating higher maturity often maintain the following:
Frequently Missing Evidence
Assessors frequently identify gaps in the following areas:
Customized Approach Objective
PCI DSS defines the customized approach objective as:
Expectations, controls, and oversight for meeting activities within Requirement 1 are defined, understood, and adhered to by affected personnel. All supporting activities are repeatable, consistently applied, and conform to management’s intent.
Organizations that adopt a customized approach must provide evidence that their practices consistently achieve the intended outcome.
Practical Customized Approach Examples
Examples of customized approaches include the following:
- Alternative methods for distributing policies
- Different training methods for communicating procedures
- Customized workflow systems used for document management
Regardless of the implementation method, organizations must ensure that documentation is current, accessible, clearly understood, and consistently followed.
Compensating Controls
Compensating controls are generally less common for Requirement 1.1.1 because the requirement focuses primarily on governance and documentation practices.
Any compensating control must provide equivalent assurance that policies and procedures are documented, maintained, utilized, and understood.
SMB Considerations
Most small and mid-sized organizations are advised to adopt the standard approach instead of implementing customized approaches or compensating controls.
Simple and well-maintained policies and procedures are generally easier to implement, assess, and maintain at a lower cost.
Assessors generally require evidence addressing all four elements of the compliance requirement:
Relevant types of evidence include the following:
Documentation Evidence
Operational Evidence
Personnel Evidence
Examine documentation and interview personnel to verify that security policies and operational procedures identified in Requirement 1 are managed in accordance with all elements specified in this requirement.
The assessor seeks to verify the following criteria:
The assessor does not merely confirm the existence of policies. Instead, the assessor seeks evidence that these policies are operationalized and consistently implemented.
What to Expect During an Assessment
The assessor may:
Organizations should be prepared to explain both the content of their documentation and the mechanisms used to ensure employee compliance.
Treating the Requirement as a Documentation Exercise
Many organizations mistakenly assume that having a written policy alone is sufficient.
PCI DSS requires that documentation be maintained, actively followed, and effectively communicated.
Updating Documents Only Once per Year
Although annual reviews are valuable, delaying updates until the next scheduled review after significant infrastructure changes can result in documentation remaining inaccurate for extended periods.
Relying on Tribal Knowledge
Organizations may rely on the expertise of experienced administrators instead of establishing and adhering to documented procedures.
This reliance introduces operational risk, which frequently becomes evident during personnel interviews.
Failing to Demonstrate Awareness
Organizations may possess comprehensive documentation but lack evidence that personnel have reviewed or understood its contents.
Overengineering the Documentation Program
Some organizations develop numerous highly complex documents, although simpler and more maintainable documentation would achieve the same objectives.
Excessive documentation frequently leads to outdated procedures and an increased administrative burden.