PCI DSS Compliance and Security

  1. Validation and Assessment Methods
    1. Self-Assessment Questionnaires (SAQs)
      1. SAQ Types and Eligibility
        1. SAQ A: Card-Not-Present Merchants
          1. SAQ A-EP: E-commerce Merchants
            1. SAQ B: Imprint-Only Merchants
              1. SAQ B-IP: Standalone IP-Connected POS
                1. SAQ C: Merchant with Payment Application Systems
                  1. SAQ C-VT: Web-Based Virtual Terminal
                    1. SAQ D: All Other Merchants
                      1. SAQ P2PE: Point-to-Point Encryption
                      2. SAQ Completion Process
                        1. Eligibility Verification
                          1. Question Response
                            1. Evidence Collection
                              1. Remediation Planning
                              2. SAQ Validation
                                1. Internal Review Procedures
                                  1. QSA Review Requirements
                                    1. Submission Process
                                  2. Report on Compliance (ROC)
                                    1. ROC Requirements
                                      1. Level 1 Merchant Requirements
                                        1. Service Provider Requirements
                                          1. Assessment Scope Definition
                                          2. QSA Assessment Process
                                            1. Pre-Assessment Activities
                                              1. Onsite Assessment Procedures
                                                1. Evidence Collection
                                                  1. Interview Processes
                                                    1. Testing Procedures
                                                    2. ROC Documentation
                                                      1. Executive Summary
                                                        1. Assessment Details
                                                          1. Findings and Observations
                                                            1. Remediation Requirements
                                                          2. Attestation Documents
                                                            1. Attestation of Compliance (AOC)
                                                              1. AOC for Merchants
                                                                1. AOC for Service Providers
                                                                  1. Signature Requirements
                                                                    1. Submission Deadlines
                                                                    2. ASV Scan Attestation
                                                                      1. Scan Report Requirements
                                                                        1. Compliance Verification
                                                                          1. Remediation Evidence
                                                                        2. Assessment Quality and Standards
                                                                          1. QSA Qualifications
                                                                            1. Certification Requirements
                                                                              1. Training and Education
                                                                                1. Experience Requirements
                                                                                  1. Ongoing Education
                                                                                  2. Assessment Standards
                                                                                    1. Testing Procedures
                                                                                      1. Evidence Requirements
                                                                                        1. Documentation Standards
                                                                                          1. Quality Assurance