TAC and PCI DSS v4.0
How TAC maps to the Payment Card Industry Data Security Standard requirements for protecting access to cardholder data environments.
Note: This guide describes how TAC’s capabilities align to key PCI-DSS v4.0 requirements. PCI-DSS compliance is assessed by a Qualified Security Assessor (QSA) against your complete control environment.
Control Mapping
TAC addresses access control, authentication, audit, and monitoring requirements for applications within your CDE, and reduces attack surface relevant to security testing — PCI-DSS Requirements 1, 7, 8, 10, and 11.
TAC controls access to applications and systems within the CDE — administrative consoles, operations tools, customer service portals, dashboards, and other applications that interact with cardholder data. TAC addresses access control, authentication, audit, and monitoring requirements (Requirements 1, 7, 8, 10) for systems in scope, and reduces the attack surface that Requirement 11 scans must cover.
TAC does not encrypt PAN at rest, tokenise cardholder data, mediate payment processing, replace network segmentation, or perform vulnerability scans or penetration tests. Requirements such as Req 3 (storage), Req 4 (CHD transmission), Req 5 (anti-malware), and Req 6 (secure development) are satisfied by other controls in your environment.
Unique Advantages
Four capabilities that make TAC especially effective for controlling access to applications in the CDE.
Close All Ports — Shrink the Access Attack Surface
TAC closes all inbound firewall ports except one encrypted channel (TLS 1.2 or TLS 1.3 with FIPS 140-2 modules) for the CDE applications it fronts. Administrative consoles, ops tools, and customer service portals handling cardholder data are not directly exposed to the internet. Most competing approaches leave datacenter ports open behind their cloud or concentrator — TAC closes them.
Legacy Application Protection
Many payment processing organisations operate critical CDE applications on legacy systems that cannot natively support MFA or modern authentication. TAC injects MFA, device posture, and continuous validation in front of any application — without changing a single line of code or requiring re-certification.
Single-Tenant Isolation
Every TAC deployment is a dedicated, isolated Secure Virtual Appliance — on-premises, in your cloud account, or hybrid. Access policies and audit data for your CDE never co-mingle with another organisation’s environment. Matters where shared-cloud architecture creates QSA or board-level concerns.
All-Inclusive Licensing — No Compliance Gaps
TAC includes every security feature in the base licence: all MFA methods, device posture validation, AI agent governance, SSO, and 24×7 support. No add-on tiers, no per-user MFA surcharges. Eliminates the common PCI risk where organisations skip controls because they are priced as premium add-ons.
Preparing for a PCI-DSS Assessment?
Our team can walk through your specific cardholder data environment and show how TAC addresses each applicable requirement.