PCI DSS Compliance
PCI DSS for Indian merchants and service providers: what it requires, who produces which artefact, and what Requirement 11 asks of testing and evidence.
25 guides. Published by Security Brigade. Last reviewed .
Buying one
What it costs, who is qualified to do it, and what you receive at the end.
What is and is not PCI DSS: SSF, P2PE, 3DS, PIN — and where PA-DSS went
PCI DSS assesses your organisation. SSF, P2PE, PTS, 3DS and PIN Security assess products and other parties. Where PA-DSS went, and what a listing…
Which PCI SSC document says what, and which PCI DSS version it is written against
PCI DSS v4.0.1 is the only active version: v4.0 retired 31 December 2024, v3.2.1 on 31 March 2024. Which PCI SSC document answers which question,…
The PCI DSS evidence checklist: what twelve months of evidence actually looks like
The artefacts a PCI DSS assessment is conducted against, by requirement and by cadence — what each one has to show, and why four scan reports can…
What actually drives PCI DSS cost: a decomposition, not a range
PCI DSS cost is five separate bills paid to five different parties. Which lines you carry, what moves each, and why the two largest are set by sc…
The bank's ATM Switch provider: PCI DSS and PCI SSF as contractual controls
RBI's 2026 Directions make a bank write PCI DSS and PCI SSF into its ATM Switch ASP contract. Which paragraph carries it, what each standard vali…
PCI DSS inside an Indian contact centre or BPO
Take card numbers on someone else's behalf and PCI DSS reaches you as a service provider: 11.4.6 every six months, a sub-requirement responsibili…
Two clocks: why an RBI-regulated payment aggregator tests twice a year and PCI DSS asks once
PCI DSS sets a twelve-month floor for penetration testing. The RBI Payment Aggregator Directions, 2025 ask for bi-annual VAPT. A PA scoped to PCI…
PCI DSS and the RBI Payment Aggregator Directions, 2025: clause by clause
The 2025 Directions name PCI DSS in four clauses. What each one obliges a payment aggregator to hold, and where the CERT-In empanelled system aud…
Requirements 6.2 and 6.3.1: code review inside a PCI DSS programme
PCI DSS reviews code per release, not per year. What 6.2.3, 6.2.3.1 and 6.3.1 actually require, and the evidence a manual review has to leave beh…
Requirement 11.4.7: what your customers may demand of you, and since when
Requirement 11.4.7 stopped being a best practice on 31 March 2025. A multi-tenant service provider now owes customers either penetration test evi…
What gets a PCI penetration test report rejected
A QSA examines your penetration test report against the elements of Requirement 11.4. Eight gaps account for most of the reports that come back.
ASV scan, internal scan, penetration test: three PCI DSS requirements, no substitutes
PCI DSS v4.0.1 separates internal scanning (11.3.1), external scanning by an ASV (11.3.2) and penetration testing (11.4). Different clocks, diffe…
What Requirement 11.4 demands of a penetration test — and why you searched for 11.3
Penetration testing moved from Requirement 11.3 to 11.4 in PCI DSS v4.0. The full renumbering, what each sub-requirement now demands, and why the…
The payment page you did not think was in scope: 6.4.3 and 11.6.1
If your checkout redirects to a gateway or embeds its form in an iframe, PCI DSS 6.4.3 and 11.6.1 apply to the page around it — and have been man…
Tokenisation and card-on-file in India: what the regulator already decided
Since 1 October 2022 no Indian entity outside the card issuers and networks may store card data. What that leaves in PCI DSS scope: capture, log…
Segmentation is a claim until Requirement 11.4.5 tests it
Segmentation reduces PCI DSS scope only if it holds. Requirement 11.4.5 is where that claim gets tested, and 11.4.6 makes it six-monthly for serv…
Merchant and service provider levels: who assigns yours
Levels come from the payment brands’ rulebooks and are applied by your acquirer — PCI DSS v4.0.1 never mentions them. The Mastercard and Amex thr…
What an ASV does, and why Requirement 11.3.2 admits nobody else
Requirement 11.3.2 is the only requirement in PCI DSS Requirement 11 that names a credential. Requirement 11.3.2.1, the post-change external scan…
What a QSA does, what a QSA may not assess, and how to verify one
A QSA's qualification is granted per company, per region, per person and per version of the standard. Here is what that covers, what it bars, and…
What "PCI DSS certification" actually means, and who signs it
The market says certification. What an assessed entity actually receives is a ROC plus an AOC, or an SAQ plus an AOC, and the signature block on…
Who does what in a PCI DSS engagement
QSA, ASV, ISA, independent penetration tester, the entity, the acquirer and the payment brand: the six parties in a PCI DSS programme and the art…
Scope and preparation
What to have ready, what can and cannot be tested, and how the boundary gets drawn.
PCI DSS renewal is a re-scope, not a repeat
Nothing renews on the anniversary. Requirement 12.5.2 asks the entity to re-confirm scope every twelve months, and a test scoped to last year's C…
We use a payment gateway, so PCI DSS does not apply to us
Outsourcing to a compliant gateway is the largest scope reduction PCI DSS offers, and the standard still says it does not make you compliant. Whe…
What is in your CDE, and what a scoping exercise produces
PCI DSS scope is three sets of systems, not one, and the third sits outside the CDE. What Requirement 12.5.2 asks a scoping exercise to produce,…
Which SAQ applies to you: 14, 27, 139, or all of them
For e-commerce the SAQ is decided by where the payment form comes from: 14 requirements, 27, 139, or all of them. The eligibility table for all n…
The testing half of the programme
Produce Requirement 11 evidence your QSA will accept.
Your QSA validates the assessment. The testing that produces the evidence is a separate engagement: segmentation testing under 11.4.5, internal and external penetration testing under 11.4, and a report written in the form a reviewer expects. Tell us your CDE boundary and your validation date. Security Brigade is CERT-In empanelled and publishes this site.