Blog

PCI DSS

PCI DSS requirements, scoping, SAQs and assessments.

All posts120PCI DSS25Vulnerability Management35Security Posture25Compliance35
2025
PCI DSS
Segmentation Testing: What Requirement 11.4.5 Actually Requires
What PCI DSS Requirement 11.4.5 requires for segmentation testing: how often to test, who can test, what to cover, and how 11.4.6 differs for service providers.
August 12, 2025 · 7 min readRead →
PCI DSS
Preparing for Your QSA Assessment: Evidence Collection Tips
How to prepare for a PCI DSS v4.0.1 QSA assessment: evidence types, how the ROC Template works, organizing evidence, targeted risk analyses and vendor AOCs.
May 13, 2025 · 8 min readRead →
PCI DSS
SAQ A Changes in 2025: Why 6.4.3 and 11.6.1 Were Removed and What Replaced Them
The January 2025 SAQ A drops requirements 6.4.3 and 11.6.1 and adds a script eligibility criterion. Here's what changed and what merchants should do now.
February 18, 2025 · 7 min readRead →
2024
PCI DSS
The March 31, 2025 Deadline: A Checklist of PCI DSS 4.0 Future-Dated Requirements
A checklist of every PCI DSS 4.0 future-dated requirement due March 31, 2025, grouped by theme and split between all entities and service providers.
October 15, 2024 · 8 min readRead →
PCI DSS
Automating Log Review to Meet Requirement 10.4.1.1
PCI DSS requirement 10.4.1.1 makes automated log review mandatory on March 31, 2025. Learn what it requires, which tools fit and what evidence to keep.
August 13, 2024 · 8 min readRead →
PCI DSS
What PCI DSS 4.0.1 Clarified (and What It Didn't)
PCI DSS 4.0.1 is a limited revision with no new requirements. What it clarified on patching, MFA and payment page scripts, and what stays exactly the same.
July 16, 2024 · 8 min readRead →
PCI DSS
MFA for All Access Into the CDE: Requirement 8.4.2 Explained
PCI DSS requirement 8.4.2 extends MFA to all access into the CDE from March 31, 2025. How it fits with 8.4.1, 8.4.3 and 8.5.1, and ways to implement it.
May 21, 2024 · 7 min readRead →
PCI DSS
Authenticated Internal Scanning: What Requirement 11.3.1.2 Means for You
PCI DSS requirement 11.3.1.2 makes authenticated internal scanning mandatory from March 31, 2025. What sufficient privileges, exceptions and scan accounts mean.
March 19, 2024 · 7 min readRead →
PCI DSS
PCI in the Cloud: Understanding Shared Responsibility
How PCI DSS shared responsibility works in the cloud: provider AOCs, responsibility matrices under 12.8.5 and 12.9.2, IaaS vs. SaaS, containers, segmentation.
February 20, 2024 · 9 min readRead →
PCI DSS
Securing Payment Page Scripts: Requirements 6.4.3 and 11.6.1 Explained
PCI DSS 4.0 requirements 6.4.3 and 11.6.1 cover payment page scripts and tamper detection. Learn what each requires and how to prepare before March 2025.
January 23, 2024 · 9 min readRead →
2023
PCI DSS
PCI Compliance for Call Centers and Phone Payments
PCI compliance for call centers: how phone payments bring VoIP, call recordings and agent desktops into scope, and how pause-and-resume and DTMF masking differ.
December 5, 2023 · 8 min readRead →
PCI DSS
PCI DSS 3.2.1 Retires March 31, 2024: Are You Ready for the Switch?
PCI DSS 3.2.1 retires March 31, 2024. Learn what changes for your next assessment, what stays best practice until 2025, and how to prepare for v4.0.
November 14, 2023 · 8 min readRead →
PCI DSS
Annual Scope Confirmation: Why Card Data Discovery Matters
PCI DSS 4.0 requirement 12.5.2 makes annual scope confirmation mandatory. Learn what it covers and how card data discovery finds PAN outside your expected CDE.
October 10, 2023 · 8 min readRead →
PCI DSS
Building a PCI Responsibility Matrix With Your Service Providers
How to build a PCI responsibility matrix with your service providers, covering PCI DSS v4.0 requirements 12.8.1 to 12.8.5 and 12.9, owners and evidence.
August 22, 2023 · 8 min readRead →
PCI DSS
How to Perform a Targeted Risk Analysis Under PCI DSS 4.0
A practical guide to the PCI DSS 4.0 targeted risk analysis: which requirements need one under 12.3.1, what it must contain, and how to do one step by step.
June 13, 2023 · 9 min readRead →
PCI DSS
The New PCI Password Rules: 12 Characters and Beyond
PCI DSS 4.0 password requirements raise the minimum to 12 characters by 2025. Here's what 8.3.6, 8.3.9, 8.3.7, 8.3.10.1 and 8.6 require and when.
April 11, 2023 · 8 min readRead →
PCI DSS
Protecting Stored Account Data: A Guide to PCI DSS Requirement 3
A practical guide to PCI DSS Requirement 3 in version 4.0: data retention, sensitive authentication data, PAN masking, encryption, hashing and key management.
March 14, 2023 · 9 min readRead →
PCI DSS
Choosing the Right SAQ: A Plain-English Guide for Merchants
Choosing the right PCI SAQ comes down to how you take card payments. Compare the PCI DSS v4.0 SAQ types, their eligibility rules and common selection mistakes.
February 14, 2023 · 9 min readRead →
PCI DSS
Point-to-Point Encryption (P2PE): How It Cuts Your PCI Scope
How point-to-point encryption (P2PE) cuts PCI scope for card-present merchants: listed solutions, SAQ P2PE, the PIM, and handling and inspecting devices.
January 17, 2023 · 8 min readRead →
2022
PCI DSS
Tokenization vs. Encryption: Which Reduces PCI Scope More?
Tokenization vs. encryption for PCI scope: why encrypted PAN usually stays in scope, when token-only systems fall out, and where P2PE fits in the picture.
November 8, 2022 · 8 min readRead →
PCI DSS
ROC, SAQ, and AOC: Making Sense of PCI Compliance Documents
ROC, SAQ and AOC explained: what each PCI compliance document is, who completes and signs it, how merchant levels apply, and where ASV scan reports fit.
October 18, 2022 · 7 min readRead →
PCI DSS
Scoping and Segmentation: How to Shrink Your Cardholder Data Environment
How PCI DSS scoping works, which systems fall into your cardholder data environment, and how network segmentation can shrink scope and assessment effort.
September 20, 2022 · 9 min readRead →
PCI DSS
ASV Scans Explained: How to Pass Your Quarterly External Scan
ASV scans explained: what PCI DSS requires for your quarterly external scan, what counts as a pass, and how to handle scope, disputes and false positives.
August 9, 2022 · 9 min readRead →
PCI DSS
Understanding the Customized Approach in PCI DSS 4.0
The customized approach in PCI DSS 4.0 lets you meet a requirement's objective with your own control. Here's how it works, what it demands and who it suits.
June 7, 2022 · 8 min readRead →
PCI DSS
PCI DSS 4.0 Is Here: What Changed From 3.2.1
PCI DSS 4.0 was published on March 31, 2022. Here's what changed from 3.2.1, which new requirements are future-dated, and how to plan your transition.
April 12, 2022 · 9 min readRead →