PCI DSS Book Series

A practical multi-volume series on PCI DSS compliance for business and technical professionals.

The goal of this book series is to provide a common understanding for business and technical people alike, and to provide a way for those people to communicate better about PCI DSS compliance and information security in general.

Different distribution channels exist for the book including physical paperback copies sold via Amazon, as well as digital copies of individual volumes. Publication to v4.0.1 is underway in September 2026.

Physical Book

The paperback PCI DSS Made Easy is a compilation of volumes 1–4 (see detail on individual volumes below), available on Amazon. The paperback has been updated to 4.0.1

Digital Volumes

Available on Amazon Kindle and Apple Books. Updated for PCI DSS 4.0 in 2022 (2026 shortly).

Individual Volume Information

1

A Business Case for the PCI DSS

Why PCI DSS matters, where it came from, who needs it, and where it's going.

Table of Contents →
2

PCI DSS Scoping

How to define and document scope — the foundation of any PCI DSS program.

Table of Contents →
3

Building a PCI DSS Information Security Program

How to apply PCI DSS effectively to people, processes, and technology.

Table of Contents →
4

Hypothetical Case Studies

Follow Jane Doe as her small business grows while staying PCI DSS compliant.

Table of Contents →

The summary of changes in the 4.0.1 edition is available.

January 1, 0001

Summary of changes in the 4.0 edition of the book

Back to books home

Summary of changes in the 4.0 edition of the book

The original 3 volumes were written between fall 2014 and summer 2015 for PCI DSS 3.1; the fourth in 2017 for …

January 1, 0001

Summary of changes in the 4.0.1 edition of the book

Back to books home

Summary of changes in the 4.0.1 edition of the book

The original 3 volumes were written between fall 2014 and summer 2015 for PCI DSS 3.1; the fourth in 2017 for …

January 1, 0001

Table of Content - Volume 1 (PCI DSS 4.0.1 edition)

Back to books home

Volume 1 - A Business Case for the PCI DSS (PCI DSS 4.0.1 edition)

  • 1.1 Volume Introduction
  • 1.2 Why PCI DSS?
    • 1.2.1 The value of card information
    • 1.2.2 The costs …

January 1, 0001

Table of Content - Volume 2 (PCI DSS 4.0.1 edition)

Back to books home

Volume 2 - PCI DSS Scoping (PCI DSS 4.0.1 edition)

  • 2.1 Volume Terminology and Acronyms
  • 2.2 PCI Resources basic diagrams
    • 2.2.1 PCI Resources Base Network …

January 1, 0001

Table of Content - Volume 3 (PCI DSS 4.0.1 edition)

Back to books home

Volume 3 - Building a PCI DSS Information Security Program (PCI DSS 4.0.1 edition)

Volume 3 - Building a PCI DSS Information Security Program

  • 3.1 Volume …

January 1, 0001

Table of Content - Volume 4 (PCI DSS 4.0.1 edition)

Back to books home

Volume 4 - Hypothetical Case Studies - From Jane’s Flower Attic to Jane’s Flower Emporium (PCI DSS 4.0.1 edition)

  • Volume 4 - Hypothetical Case …