Cybersecurity Insights & Guides
Expert insights on cybersecurity, vulnerability management, and digital defence strategies.
What is and is not PCI DSS: SSF, P2PE, 3DS, PIN — and where PA-DSS went
PCI DSS assesses your organisation. SSF, P2PE, PTS, 3DS and PIN Security assess products and other parties. Where PA-DSS went, and what a listing changes.
Which PCI SSC document says what, and which PCI DSS version it is written against
PCI DSS v4.0.1 is the only active version: v4.0 retired 31 December 2024, v3.2.1 on 31 March 2024. Which PCI SSC document answers which question, and what version each carries.
PCI DSS renewal is a re-scope, not a repeat
Nothing renews on the anniversary. Requirement 12.5.2 asks the entity to re-confirm scope every twelve months, and a test scoped to last year's CDE is the first mismatch an assessor sees.
The PCI DSS evidence checklist: what twelve months of evidence actually looks like
The artefacts a PCI DSS assessment is conducted against, by requirement and by cadence — what each one has to show, and why four scan reports can still be one failed requirement.
What actually drives PCI DSS cost: a decomposition, not a range
PCI DSS cost is five separate bills paid to five different parties. Which lines you carry, what moves each, and why the two largest are set by scope before anyone quotes.
The bank's ATM Switch provider: PCI DSS and PCI SSF as contractual controls
RBI's 2026 Directions make a bank write PCI DSS and PCI SSF into its ATM Switch ASP contract. Which paragraph carries it, what each standard validates, and what evidence satisfies it.
PCI DSS inside an Indian contact centre or BPO
Take card numbers on someone else's behalf and PCI DSS reaches you as a service provider: 11.4.6 every six months, a sub-requirement responsibility matrix, and recordings holding account data.
Two clocks: why an RBI-regulated payment aggregator tests twice a year and PCI DSS asks once
PCI DSS sets a twelve-month floor for penetration testing. The RBI Payment Aggregator Directions, 2025 ask for bi-annual VAPT. A PA scoped to PCI's cadence is under-testing against its regulator.
PCI DSS and the RBI Payment Aggregator Directions, 2025: clause by clause
The 2025 Directions name PCI DSS in four clauses. What each one obliges a payment aggregator to hold, and where the CERT-In empanelled system audit sits alongside it.
Requirements 6.2 and 6.3.1: code review inside a PCI DSS programme
PCI DSS reviews code per release, not per year. What 6.2.3, 6.2.3.1 and 6.3.1 actually require, and the evidence a manual review has to leave behind.
Requirement 11.4.7: what your customers may demand of you, and since when
Requirement 11.4.7 stopped being a best practice on 31 March 2025. A multi-tenant service provider now owes customers either penetration test evidence or access to test, and cannot refuse both.
What gets a PCI penetration test report rejected
A QSA examines your penetration test report against the elements of Requirement 11.4. Eight gaps account for most of the reports that come back.
ASV scan, internal scan, penetration test: three PCI DSS requirements, no substitutes
PCI DSS v4.0.1 separates internal scanning (11.3.1), external scanning by an ASV (11.3.2) and penetration testing (11.4). Different clocks, different testers, one exception at 11.3.2.1.
What Requirement 11.4 demands of a penetration test — and why you searched for 11.3
Penetration testing moved from Requirement 11.3 to 11.4 in PCI DSS v4.0. The full renumbering, what each sub-requirement now demands, and why the Council's own supplement still says 11.3.
The payment page you did not think was in scope: 6.4.3 and 11.6.1
If your checkout redirects to a gateway or embeds its form in an iframe, PCI DSS 6.4.3 and 11.6.1 apply to the page around it — and have been mandatory since 31 March 2025.
We use a payment gateway, so PCI DSS does not apply to us
Outsourcing to a compliant gateway is the largest scope reduction PCI DSS offers, and the standard still says it does not make you compliant. Where the belief holds, and where it breaks.
Tokenisation and card-on-file in India: what the regulator already decided
Since 1 October 2022 no Indian entity outside the card issuers and networks may store card data. What that leaves in PCI DSS scope: capture, log residue, the T+4 window, and a re-scope.
Segmentation is a claim until Requirement 11.4.5 tests it
Segmentation reduces PCI DSS scope only if it holds. Requirement 11.4.5 is where that claim gets tested, and 11.4.6 makes it six-monthly for service providers.
What is in your CDE, and what a scoping exercise produces
PCI DSS scope is three sets of systems, not one, and the third sits outside the CDE. What Requirement 12.5.2 asks a scoping exercise to produce, and why remediation started first is half wasted.
Which SAQ applies to you: 14, 27, 139, or all of them
For e-commerce the SAQ is decided by where the payment form comes from: 14 requirements, 27, 139, or all of them. The eligibility table for all nine types, from PCI SSC's own guidance.
Merchant and service provider levels: who assigns yours
Levels come from the payment brands’ rulebooks and are applied by your acquirer — PCI DSS v4.0.1 never mentions them. The Mastercard and Amex thresholds, and what a level changes.
What an ASV does, and why Requirement 11.3.2 admits nobody else
Requirement 11.3.2 is the only requirement in PCI DSS Requirement 11 that names a credential. Requirement 11.3.2.1, the post-change external scan, deliberately does not.
What a QSA does, what a QSA may not assess, and how to verify one
A QSA's qualification is granted per company, per region, per person and per version of the standard. Here is what that covers, what it bars, and how to check it.
What "PCI DSS certification" actually means, and who signs it
The market says certification. What an assessed entity actually receives is a ROC plus an AOC, or an SAQ plus an AOC, and the signature block on each says something different.
Who does what in a PCI DSS engagement
QSA, ASV, ISA, independent penetration tester, the entity, the acquirer and the payment brand: the six parties in a PCI DSS programme and the artefact each one produces.
Have a question this did not answer?
Our team answers regulatory and testing questions directly — no discovery call required to get a straight answer.
Talk to our team