Cyber Essentials → PCI DSS crosswalk
A control-by-control mapping between UK Cyber Essentials and PCI DSS v4.0. 5 mappings.
| Cyber Essentials | PCI DSS | Relationship | Notes |
|---|---|---|---|
| CE-1 Firewalls | Req. 2 Apply secure configurations to all system components | PartialCurated | Secure configuration & hardening |
| CE-2 Secure configuration | Req. 2 Apply secure configurations to all system components | EquivalentCurated | Secure configuration & hardening |
| CE-3 User access control | Req. 7 Restrict access by business need to know | EquivalentCurated | Access control & identity |
| CE-3 User access control | Req. 8 Identify users and authenticate access | EquivalentCurated | Access control & identity |
| CE-5 Security update management | Req. 11 Test security of systems and networks regularly | EquivalentCurated | Vulnerability management |
Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.