PCI DSS with ARRTECH

Logs your assessor can check for themselves.

Schedule a meeting

PCI DSS v4.0.1 · Mapped Sep 24, 2026

Records for your assessment that prove themselves

Collect, sign and keep the logs PCI DSS asks for, and see plainly what stays with you.

Requirements

ClauseWhat it asksARRTECH
PCI DSS 10.2.1Audit logs enabled on every system component.Status and last read time per source. →
PCI DSS 10.3.4Log data cannot change without an alert.A signature chain that breaks on change. →
PCI DSS 10.5.1At least 12 months of log history.Retention set per source. →
PCI DSS 10.7.2Failed security controls detected and alerted.A silent-source alert. →
PCI DSS 12.5.2Scope confirmed, with every place card data sits.DLP discovery by classification. →
PCI DSS 12.10.1An incident response plan ready to activate.A playbook execution history. →

Integrity

Prove nobody changed your logs

ARRTECH SIEM hashes and signs every write and chains each signature file to the one before, so a changed or missing file breaks the chain. Any source exports with a standalone verification tool, so your assessor checks it without your SIEM.

Retention

Keep a year of log history

PCI DSS asks for at least 12 months of audit log history. In ARRTECH SIEM, retention is set per source or per group. Archived logs stay searchable and export as CSV or files.

Completeness

Show every source is still sending

An assessor asks whether the logs are complete. The Data Sources page shows each source’s status, last read time and a silent-source alert, so a missing source is visible before your assessor finds it.

Discovery

Find card data before you set scope

You cannot scope what you have not found. ARRTECH DLP discovery scans endpoints, file servers and SQL databases and inventories what it finds. Card numbers are checked by algorithm, not only matched by pattern.

Response

Respond with a person deciding

ARRTECH SOAR opens incidents from SIEM alerts and keeps an execution history of playbook runs. The Operator node emails a person with up to five options and waits. Your incident response plan stays yours.

Limits

Know what stays with you

No ARRTECH product produces the record for these requirements.

PCI DSS 3.5.1

Stored card numbers made unreadable. DLP company-key encryption is not claimed as validated cryptography. The record comes from your storage encryption.

PCI DSS 8.4.2

MFA for all access into the cardholder data environment. ARRTECH does not claim MFA to its consoles. The record comes from your identity system.

PCI DSS 10.6.1

System clocks synchronized. No ARRTECH product sets or records time synchronization. The record comes from your time servers’ configuration.

By rule

Naming a clause is not a claim of certification.

PCI DSS 10.2.1

Audit logs enabled and active for all system components. ARRTECH: the Data Sources page shows each source’s status, last read time and a silent-source alert.

PCI DSS 10.3.4

Existing log data cannot change without generating alerts. ARRTECH: a signature chain that breaks on any change or missing file. The non-repudiation report highlights faulty files.

PCI DSS 10.5.1

Retain audit log history for at least 12 months. ARRTECH: retention set per source or per group, with archived logs searchable.

PCI DSS 10.7.2

Failures of critical security controls detected and alerted. ARRTECH: a silent-source alert, and a system summary report of source and agent status.

PCI DSS 12.5.2

Scope documented and confirmed, including where account data is stored. ARRTECH: DLP discovery that inventories endpoints, file servers and SQL databases by classification.

PCI DSS 12.10.1

An incident response plan ready to be activated. ARRTECH: SOAR incidents with an execution history of playbook runs.

Questions

Does ARRTECH make us PCI DSS compliant?

No product can. PCI SSC does not issue compliance certificates. Your QSA, or your own questionnaire, decides whether each requirement is in place.

Does the SIEM come into scope?

Yes, if it stores account data. It then sits in your cardholder data environment and must meet the requirements itself.

Can our assessor check the logs without ARRTECH?

Yes. Any source exports with its signatures, the SIEM certificate and a standalone verification tool.

Is there a ready PCI DSS report?

Yes. Ready reports and dashboards cover PCI DSS, and any saved query becomes a scheduled report.

Sources

Guide

What is PCI DSS?

The security standard for every organization that stores, processes or transmits payment card data. Version 4.0.1 is current.

What is a ROC or SAQ?

A Report on Compliance is written by a Qualified Security Assessor. A Self-Assessment Questionnaire is completed by the organization. Both come with an Attestation of Compliance.

What does Requirement 10 ask?

Log and monitor all access to system components and cardholder data, protect the logs from change, and keep at least 12 months of history.

Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Available now

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Early access

Prove every log. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.

Keep card data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.

ARRTECH

© 2026 ARRTECH Corporation. All rights reserved.