---
title: "PCI DSS: controls supported by Noraina"
description: "Which PCI DSS controls Noraina's infrastructure, backup and Cloudflare services support, how, and what evidence you get for the audit."
url: https://www.noraina.cloud/compliance/pci-dss/
language: en
---
# PCI DSS: controls supported by Noraina

Merchants, payment service providers and any company whose website or systems touch card payments.

> Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier.

## PCI DSS v4.0.1

Security standard of the payment card industry for every system that stores, processes or transmits card data. References are PCI DSS requirement numbers; titles are our own summaries.

9 controls supported.

### Complete edge logging

- Control: 10.2.1 (Audit logs enabled and active); 10.5.1 (Audit log history kept for at least twelve months)
- How we help: Logpush sends every request, security event and access decision to storage you control, such as R2, retained for twelve months or more.
- Evidence you get: Logpush job inventory, retention settings, sample log queries.
- Status: Mapping under review

### Application and DDoS protection

- Control: 4.2.1 (Strong cryptography for card data over public networks); 6.4.2 (Automated protection of public-facing web applications); 6.4.3 (Inventory and authorisation of payment page scripts); 11.6.1 (Detection of unauthorised changes to payment pages)
- How we help: Cloudflare WAF is the automated solution in front of your public web applications, TLS is enforced at the edge, and Page Shield keeps an inventory of the scripts on your payment pages and alerts on unauthorised changes.
- Evidence you get: WAF configuration and blocked-attack reports, TLS settings, Page Shield script inventory and change alerts.
- Status: Mapping under review

### Zero Trust access and data protection

- Control: 1.3.1 (Inbound traffic to the card data environment restricted); 7.2.1 (Access granted by role and need to know); 8.4.2 (Multi-factor authentication for access to the card data environment)
- How we help: Systems in the card data environment are reachable only through Cloudflare Access, per role and with multi-factor authentication, with no inbound ports open to the internet.
- Evidence you get: Access policy export, authentication logs, tunnel configuration.
- Status: Mapping under review


We reply with the controls we can cover, what stays on your side, and a realistic timeline. https://www.noraina.cloud/compliance/pci-dss/#assessment
