Daily Ranking

What are you looking for?

What Is Network Segmentation in PCI DSS? A Complete Guide

What Is Network Segmentation in PCI DSS? A Complete Guide

Network segmentation in PCI DSS is the practice of separating the Cardholder Data Environment (CDE) from other systems and networks using security controls that restrict unnecessary communication. The goal is to limit access to payment data, reduce exposure, and, when effective, potentially reduce the number of systems that need to be included in PCI DSS scope.

A common misconception is that PCI DSS requires every organization to implement network segmentation. It does not. However, organizations that rely on segmentation to reduce PCI DSS scope must be able to demonstrate that the segmentation controls are effective. PCI SSC guidance explains that segmentation can reduce the number of systems requiring PCI DSS controls, but ineffective segmentation can leave a much larger environment in scope.

What Is Network Segmentation in PCI DSS?

Network segmentation divides an organization's infrastructure into separate security zones and controls the traffic allowed between those zones. In a PCI DSS environment, one of the most important boundaries is between the CDE and systems that do not need access to payment data.

For example, a retailer might place its payment terminals and payment servers in a protected CDE while keeping employee laptops and guest Wi-Fi in separate networks. A firewall or another appropriate control can then restrict which systems are allowed to communicate with the CDE.

PCI SSC describes segmentation as the use of additional logical, physical, or combined controls to separate systems with different security needs. Common approaches include firewalls, router configurations, network configurations, and physical controls.

A Simple PCI DSS Network Segmentation Example

Consider an online retailer with four major network areas:

  • Guest Wi-Fi

  • Employee network

  • POS network

  • Payment servers

Without segmentation, these environments might have unnecessary paths between them. If an employee workstation is compromised, an attacker could potentially use that access to move toward payment systems.

With effective segmentation, the architecture could look like this:

Guest Wi-Fi → Blocked from CDE

Employee Network → Restricted Access → CDE

POS Network → Required Payment Access → CDE

Payment Servers → Protected CDE

The important point is that simply creating separate networks does not automatically establish an effective PCI DSS scope boundary. The actual communication paths and security controls must be evaluated.

Is Network Segmentation Required by PCI DSS?

No. Network segmentation itself is not a mandatory PCI DSS requirement.

PCI SSC has explicitly stated that segmentation is not a PCI DSS requirement, but it is a valuable strategy for limiting the systems that have access to cardholder data and potentially reducing assessment effort and cost.

However, there is an important distinction. If an organization claims that certain systems are outside PCI DSS scope because of segmentation, the segmentation must actually isolate those systems from the CDE. PCI SSC says that where segmentation is used to reduce scope, the assessor must verify that the segmentation controls are effective.

So, the practical rule is:

Segmentation is optional; effective security boundaries are not.

Organizations should also avoid treating segmentation as a replacement for broader security controls. PCI SSC warns that out-of-scope systems can still become attack paths into the CDE.

What Is the Cardholder Data Environment (CDE)?

The Cardholder Data Environment, or CDE, consists of the people, processes, and technologies that store, process, or transmit cardholder data or sensitive authentication data.

But the CDE is only the starting point when determining PCI DSS scope.

Organizations also need to consider systems that connect to the CDE or can affect its security. These may include authentication infrastructure, management systems, monitoring platforms, backup systems, administrative workstations, and other supporting services.

For example, a payment server might be isolated from ordinary employee computers, but its authentication server could still provide access to the payment environment. That supporting infrastructure therefore cannot simply be ignored when determining scope.

PCI SSC's scoping guidance emphasizes evaluating the CDE, cardholder-data flows, connected systems, and supporting components rather than assuming that only the systems storing payment data are relevant.

How Does Network Segmentation Reduce PCI DSS Scope?

Network segmentation can reduce PCI DSS scope by preventing systems that do not need access to cardholder data from communicating with or affecting the CDE.

Without adequate segmentation, PCI SSC states that the entire network may be considered part of the PCI DSS environment. When effective segmentation isolates the CDE, systems that have no relevant connectivity or impact may potentially be excluded from scope.

Network design

Potential PCI DSS impact

Flat network

Potentially broad scope

Partially segmented

Scope depends on actual connectivity

Properly isolated CDE

Potentially reduced scope

Microsegmented environment

Scope depends on verified boundaries and connections

This does not mean that putting a payment server behind a firewall automatically makes every other system out of scope. The organization must understand all possible communication and access paths and verify that the segmentation works as intended.

PCI SSC recommends starting scoping exercises with the assumption that everything is in scope until adequate controls and effective segmentation have been verified.

Flat Network vs. Segmented Network

A flat network allows many systems to communicate within a broad network environment. While this architecture can be simpler to operate, it can increase the potential attack surface and make it harder to isolate payment systems.

A segmented network creates defined security boundaries and limits communication between zones.

Feature

Flat Network

Segmented Network

Network zones

Few or none

Multiple

CDE isolation

Limited

Controlled

Lateral movement

Potentially easier

More restricted

PCI DSS scope

Potentially larger

Potentially smaller

Access control

Broad

More granular

Breach containment

More difficult

Easier

The objective is not to create as many network segments as possible. Instead, organizations should create meaningful boundaries based on business requirements, data flows, trust relationships, and security needs.

How Does PCI DSS Network Segmentation Work?

Effective segmentation starts with understanding where payment data flows.

First, identify the CDE and map connections between payment systems and other infrastructure. Next, determine which connections are genuinely required. Security controls can then be configured to allow necessary traffic while blocking unauthorized paths.

Common controls include:

  • Firewalls

  • Router access control lists

  • Network ACLs

  • Security groups

  • Private network configurations

  • Physical separation

  • Cloud-native security controls

  • Microsegmentation technologies

The principle is straightforward: allow only the communication that is required and restrict everything else.

Network diagrams should also reflect the actual environment. If the architecture changes but documentation does not, the organization's understanding of PCI DSS scope can quickly become inaccurate.

Common PCI DSS Network Segmentation Methods

Firewalls

Firewalls are one of the most common segmentation controls. An internal firewall can restrict communication between a corporate network and the CDE, allowing only approved traffic.

VLANs

VLANs can separate network traffic into logical zones. However, a VLAN by itself should not be treated as proof that PCI DSS scope has been reduced. The effectiveness of the overall controls and permitted communication must be evaluated.

PCI SSC identifies properly configured firewalls, routers with strong access controls, network configurations, and physical controls among possible segmentation approaches.

ACLs and Routing Controls

Access control lists and routing policies can restrict which systems communicate with particular destinations, ports, or services.

Physical Segmentation

In some environments, separate physical infrastructure can create strong boundaries between systems with different security requirements.

Cloud Segmentation

Cloud environments can use private subnets, security groups, network ACLs, cloud firewalls, and other controls to establish boundaries.

Microsegmentation

Microsegmentation takes segmentation further by applying granular controls around individual workloads, applications, identities, or services rather than relying exclusively on traditional network zones.

What Are the PCI DSS 4.0.1 Network Segmentation Requirements?

The current PCI DSS standard is PCI DSS v4.0.1, which PCI SSC published as a limited revision of v4.0. PCI DSS v4.0 was retired on December 31, 2024, making v4.0.1 the active version. PCI SSC says v4.0.1 did not add or remove requirements but clarified existing requirements and guidance.

Network segmentation intersects with several PCI DSS areas, particularly requirements concerning network security controls, traffic restrictions, and testing.

PCI DSS area

Relevance to segmentation

Requirement 1

Network security controls

Requirement 1.2

Configuration and management of network security controls

Requirement 1.3

Restricting traffic to and from the CDE

Requirement 1.4

Controls for trusted and untrusted connections

Requirement 11.4

Penetration testing and segmentation validation

The exact requirements applicable to an organization depend on its environment and assessment method. Therefore, organizations should not interpret a segmentation design as a complete PCI DSS compliance program.

PCI SSC's v4.x resource hub provides the official standard and supporting resources for organizations working with PCI DSS v4.0.1.

How to Test PCI DSS Network Segmentation

Testing is critical when segmentation is being used to establish a PCI DSS scope boundary.

Start by reviewing the network architecture and identifying every path between the CDE and other environments. Then test whether unauthorized systems can actually reach CDE systems or services.

A segmentation test may examine:

  • TCP connectivity

  • UDP connectivity

  • ICMP behavior

  • Open ports

  • Firewall rules

  • Routing

  • ACLs

  • Security groups

  • Remote-access paths

  • Administrative connections

Testing should cover the segmentation methods actually used in the environment. Results should be documented, including the systems tested, methodology, findings, remediation, and retesting where necessary.

The key objective is not merely proving that a firewall exists. It is demonstrating that the controls effectively enforce the intended security boundary.

Network Segmentation in Cloud and Hybrid Environments

Modern PCI DSS environments increasingly combine traditional networks with cloud, multi-cloud, hybrid, Zero Trust, and microsegmented architectures.

PCI SSC published dedicated guidance in 2024 for scoping and segmentation in modern network architectures. It addresses topics including Zero Trust, microsegmentation, multi-cloud environments, cloud asset inventories, and scope boundaries for dynamic systems.

For example, a company might host payment services in a private cloud subnet while employee applications run elsewhere. Security groups, cloud firewalls, identity controls, and private connectivity can restrict access between those environments.

However, cloud architecture does not automatically make systems out of scope. Organizations still need to understand connectivity, data flows, supporting services, and controls affecting the CDE.

Common PCI DSS Network Segmentation Mistakes

Several mistakes can undermine an otherwise well-designed segmentation strategy:

  1. Assuming a VLAN automatically removes systems from PCI DSS scope.

  2. Forgetting authentication or management systems.

  3. Allowing unnecessary firewall rules.

  4. Ignoring remote-access pathways.

  5. Failing to maintain network diagrams.

  6. Not testing segmentation boundaries.

  7. Assuming cloud resources are automatically isolated.

  8. Forgetting third-party connections.

  9. Treating out-of-scope systems as unimportant.

  10. Failing to reassess scope after major architecture changes.

PCI SSC has specifically warned that attackers may compromise systems considered out of scope and use them as pathways toward systems containing cardholder data.

PCI DSS Network Segmentation Best Practices

A strong segmentation strategy should:

  • Identify the CDE accurately.

  • Map cardholder-data flows.

  • Separate systems according to their security requirements.

  • Minimize connections into the CDE.

  • Apply least-privilege access.

  • Restrict unnecessary ports and protocols.

  • Document segmentation boundaries.

  • Maintain accurate network diagrams.

  • Review firewall and ACL rules regularly.

  • Test segmentation controls.

  • Retest after relevant changes.

  • Continuously reassess PCI DSS scope.

Segmentation should be treated as part of an overall security architecture rather than as a shortcut to compliance.

Does Network Segmentation Make You PCI DSS Compliant?

No.

Network segmentation can help an organization reduce PCI DSS scope, limit exposure to cardholder data, and make security controls more manageable. It does not, by itself, demonstrate compliance with PCI DSS.

A useful way to remember the difference is:

Segmentation → helps define and potentially reduce scope.

PCI DSS compliance → requires the applicable controls to be implemented and validated for the environment.

Organizations with complex environments should work with their internal compliance team, acquirer, or appropriately qualified assessor when making formal scoping decisions.

Conclusion

Network segmentation is one of the most useful strategies for controlling PCI DSS scope and protecting payment environments. By separating the CDE from unnecessary systems and restricting communication between security zones, organizations can reduce exposure and potentially make PCI DSS assessments more manageable.

The most important lesson is that network segmentation is not a checkbox. A VLAN, firewall, cloud subnet, or microsegmentation platform does not automatically establish a PCI DSS scope boundary. Organizations must understand their CDE, map connections, implement effective controls, test those controls, and keep scope documentation current.

For modern environments, this also means considering cloud, hybrid infrastructure, Zero Trust, and microsegmentation rather than relying only on traditional network boundaries. PCI SSC's 2024 guidance specifically addresses these modern architectures and their impact on PCI DSS scoping and segmentation.

FAQs About PCI DSS Network Segmentation

What is network segmentation in PCI DSS?

Network segmentation in PCI DSS separates the CDE from other systems using controls such as firewalls, ACLs, network configurations, physical controls, or microsegmentation. Effective segmentation can potentially reduce the number of systems within PCI DSS scope.

Is network segmentation required by PCI DSS?

No. PCI SSC states that network segmentation is not itself a PCI DSS requirement. However, organizations using segmentation to reduce scope need to verify that the controls effectively isolate the CDE.

Does network segmentation reduce PCI DSS scope?

It can. Effective segmentation may prevent systems that do not need access to payment data from being included in the same scope as the CDE. The actual scope depends on connectivity, access, security impact, and the effectiveness of implemented controls.

Can VLANs be used for PCI DSS network segmentation?

Yes. VLANs can be part of a segmentation design, but a VLAN alone should not be considered sufficient proof of effective isolation. The complete set of controls and communication paths must be evaluated.

What is a PCI DSS network segmentation example?

A simple example is placing POS terminals and payment servers in a protected CDE while separating employee laptops and guest Wi-Fi into other networks. Firewalls and access controls can then restrict unnecessary traffic to the CDE.

Is microsegmentation compatible with PCI DSS?

Yes. PCI SSC's modern network architecture guidance specifically addresses microsegmentation, Zero Trust, and multi-cloud environments. The key consideration remains whether the implemented controls effectively establish and maintain the intended scope boundaries.

Does segmentation alone make an organization PCI DSS compliant?

No. Segmentation can reduce scope and improve security, but PCI DSS compliance involves implementing and validating the requirements applicable to the organization's environment.

Leave a Reply

Your email adress will not be published, Requied fileds are marked*.