Requirement 10 requires logging and monitoring of all access to system components and cardholder data, and since 31 March 2025, control 10.4.1.1 requires automated mechanisms that review those logs daily, flag anomalies, generate alerts and evidence the review. That deadline has passed, so a daily review performed manually no longer meets the control.
On 31 March 2025, control 10.4.1.1 of PCI DSS moved from a future-dated item in v4.0 to a full requirement. Every assessment against v4.0.1 since that date tests it in full, and many merchants have not implemented it.
10.4.1.1 requires audit log reviews performed daily through automated mechanisms capable of flagging anomalies, generating alerts, and evidencing that the daily review happened. Each term narrows what qualifies. Daily excludes a weekly batch review. Automated mechanisms excludes a person reading a console. Evidencing excludes a spreadsheet in which someone records completion.
Daily review evidence is dated and gaps cannot be backfilled. The next assessment examines the whole assessment period, and every day without an evidenced automated review sits in the record as a day of non-compliance, with no retroactive review available to close it. A merchant who passed an assessment before the deadline demonstrated compliance with the previous rulebook rather than with the control as it now stands.
Requirement 10 is one of the twelve PCI DSS requirements, covering logging and monitoring of all access to system components and cardholder data. Its purpose is a trustworthy record of activity in the cardholder data environment, with detection fast enough to act on.
| Control | What it requires |
|---|---|
| Requirement 10 (overall) | Log and monitor all access to system components and cardholder data |
| 10.4.1.1 | Automated mechanisms to perform audit log reviews — daily, capable of flagging anomalies, generating alerts, and evidencing the daily review |
Meeting 10.4.1.1 decomposes into four parts. Collection: logs from the in-scope systems flowing into one place the mechanism can read, since a review cannot cover logs that never arrive. Analysis: automated review with enough of a baseline to flag deviation, because a mechanism that never flags anything attracts the same assessor scrutiny as no mechanism. Alerting: flagged anomalies becoming alerts that reach a person, with a record of the response. Evidence: a per-day artefact produced by the mechanism itself, showing the review ran, what it found, and what followed.
The evidence component takes the most design attention, because the assessment consumes it directly. A retrievable record for any named day in the period is what the assessor examines. Where the evidence is a by-product of the mechanism running, assessment preparation becomes retrieval.
Scope discipline applies as well. Requirement 10 attaches to access to system components and cardholder data, so the collection has to match the assessed scope rather than the systems that are straightforward to instrument. Deferred log sources are the ones assessors sample.
Paraphrasing PCI DSS v4.0.1: Requirement 10 requires that access to system components and cardholder data is logged and monitored. Control 10.4.1.1 requires that automated mechanisms are used to perform audit log reviews; the reviews are daily, and the mechanisms must be capable of flagging anomalies, generating alerts, and providing evidence that the daily review occurred. This is a paraphrase rather than the standard’s text; the authoritative wording is in PCI DSS v4.0.1, available from the PCI Security Standards Council.
| Framework | Control | How it compares |
|---|---|---|
| ISO 27001:2022 | Annex A 8.15 — Logging | The recording half: event logs with required content (user ID, activities, time, device and location, network addresses and protocols) |
| ISO 27001:2022 | Annex A 8.16 — Monitoring Activities | The analysis half: monitoring for anomalous behaviour and evaluating potential incidents. PCI combines both halves into Requirement 10 and adds the fixed daily cadence |
An assessment completed before 31 March 2025 tested 10.4.1.1 as a future-dated item, which means it was noted rather than enforced. The next assessment applies the current rulebook across the whole period since.
The related error is treating the requirement as a tooling purchase, where a SIEM licence is acquired and the control marked complete. The requirement is the daily review demonstrably happening — anomalies flagged, alerts handled, evidence produced, every day of the assessment period. A licensed but partly deployed tool carries the cost without closing the gap.
The assessor’s own test is worth running internally: select a random date from two months ago and produce the review evidence for it.
Our log management platform collects and retains logs from your in-scope systems, and our SIEM runs the automated review daily: flagging anomalies against your environment’s baseline, raising alerts our analysts triage, and writing a per-day evidence record your assessor can read for any date in the period. That removes both the gaps to explain and the reconstruction before assessment. Where the mechanism is not yet running in your environment, a call scopes it against your cardholder data environment.
Is 10.4.1.1 already mandatory?
Yes. It became mandatory on 31 March 2025, having been a future-dated requirement in PCI DSS v4.0. Every assessment against v4.0.1 since that date tests it as a full requirement.
Can a person do the daily log review manually?
No. 10.4.1.1 requires automated mechanisms to perform the audit log reviews, capable of flagging anomalies, generating alerts and evidencing that the daily review happened.
What does Requirement 10 cover overall?
Logging and monitoring of all access to system components and cardholder data. The controls under it cover producing the logs, protecting them and reviewing them. 10.4.1.1 is the review control carrying the automation mandate.
We missed the deadline. What now?
Implement the mechanism now to limit the gap. Days without an evidenced automated review cannot be backfilled, so each week of delay adds to the non-compliant window your next assessment examines.
What evidence does an assessor want for the daily review?
Output from the automated mechanism showing the review ran each day, what anomalies it flagged, what alerts it raised, and what was done about them. A completed calendar reminder does not evidence a review.
Does ISO 27001 have an equivalent requirement?
The same ground is split across two Annex A controls: A.8.15 Logging for the record and A.8.16 Monitoring Activities for the analysis, without PCI’s fixed daily cadence.