What problem does it solve? Security engineers and assessors struggle to translate raw firewall configurations into defensible PCI DSS v4.0.1 evidence, often overclaiming that an NGFW is "PCI compliant" when compliance actually applies to the entire environment, scope, and operational controls. ## Core Features & Use Cases - Requirement Mapping: Maps firewall controls to specific PCI DSS requirement IDs including Requirement 1 (network security controls), 6.4.2 (web application protection), 8.x (authentication/MFA), 10.x (logging), and 11.x (IDS/IPS and segmentation testing). - Assessment Workflow: Provides a nine-step workflow covering CDE scoping, rulebase review, inbound/outbound validation, segmentation testing, and logging verification, plus an evidence request checklist. - Evidence Markers: Defines a standard PCI:/REQ: description and tag pattern for marking PCI-relevant policies, NAT rules, zones, and objects directly in firewall configs. - Use Case: Given an exported SRX or Fortinet rulebase, produce an assessor-ready summary mapping each finding to PCI DSS requirement IDs with evidence references, open gaps, and remediation recommendations. ## Quick Start Use the pci-ngfw-compliance skill to assess this firewall configuration export against PCI DSS v4.0.1 Requirement 1 and produce a gap summary.