Skip to main content

Cybersecurity Insights & Guides

Expert insights on cybersecurity, vulnerability management, and digital defence strategies.

What is and is not PCI DSS: SSF, P2PE, 3DS, PIN — and where PA-DSS went

PCI DSS assesses your organisation. SSF, P2PE, PTS, 3DS and PIN Security assess products and other parties. Where PA-DSS went, and what a listing changes.

20 Aug 2026

Which PCI SSC document says what, and which PCI DSS version it is written against

PCI DSS v4.0.1 is the only active version: v4.0 retired 31 December 2024, v3.2.1 on 31 March 2024. Which PCI SSC document answers which question, and what version each carries.

20 Aug 2026

PCI DSS renewal is a re-scope, not a repeat

Nothing renews on the anniversary. Requirement 12.5.2 asks the entity to re-confirm scope every twelve months, and a test scoped to last year's CDE is the first mismatch an assessor sees.

20 Aug 2026

The PCI DSS evidence checklist: what twelve months of evidence actually looks like

The artefacts a PCI DSS assessment is conducted against, by requirement and by cadence — what each one has to show, and why four scan reports can still be one failed requirement.

20 Aug 2026

What actually drives PCI DSS cost: a decomposition, not a range

PCI DSS cost is five separate bills paid to five different parties. Which lines you carry, what moves each, and why the two largest are set by scope before anyone quotes.

20 Aug 2026

The bank's ATM Switch provider: PCI DSS and PCI SSF as contractual controls

RBI's 2026 Directions make a bank write PCI DSS and PCI SSF into its ATM Switch ASP contract. Which paragraph carries it, what each standard validates, and what evidence satisfies it.

20 Aug 2026

PCI DSS inside an Indian contact centre or BPO

Take card numbers on someone else's behalf and PCI DSS reaches you as a service provider: 11.4.6 every six months, a sub-requirement responsibility matrix, and recordings holding account data.

20 Aug 2026

Two clocks: why an RBI-regulated payment aggregator tests twice a year and PCI DSS asks once

PCI DSS sets a twelve-month floor for penetration testing. The RBI Payment Aggregator Directions, 2025 ask for bi-annual VAPT. A PA scoped to PCI's cadence is under-testing against its regulator.

20 Aug 2026

PCI DSS and the RBI Payment Aggregator Directions, 2025: clause by clause

The 2025 Directions name PCI DSS in four clauses. What each one obliges a payment aggregator to hold, and where the CERT-In empanelled system audit sits alongside it.

20 Aug 2026

Requirements 6.2 and 6.3.1: code review inside a PCI DSS programme

PCI DSS reviews code per release, not per year. What 6.2.3, 6.2.3.1 and 6.3.1 actually require, and the evidence a manual review has to leave behind.

20 Aug 2026

Requirement 11.4.7: what your customers may demand of you, and since when

Requirement 11.4.7 stopped being a best practice on 31 March 2025. A multi-tenant service provider now owes customers either penetration test evidence or access to test, and cannot refuse both.

20 Aug 2026

What gets a PCI penetration test report rejected

A QSA examines your penetration test report against the elements of Requirement 11.4. Eight gaps account for most of the reports that come back.

20 Aug 2026

ASV scan, internal scan, penetration test: three PCI DSS requirements, no substitutes

PCI DSS v4.0.1 separates internal scanning (11.3.1), external scanning by an ASV (11.3.2) and penetration testing (11.4). Different clocks, different testers, one exception at 11.3.2.1.

20 Aug 2026

What Requirement 11.4 demands of a penetration test — and why you searched for 11.3

Penetration testing moved from Requirement 11.3 to 11.4 in PCI DSS v4.0. The full renumbering, what each sub-requirement now demands, and why the Council's own supplement still says 11.3.

20 Aug 2026

The payment page you did not think was in scope: 6.4.3 and 11.6.1

If your checkout redirects to a gateway or embeds its form in an iframe, PCI DSS 6.4.3 and 11.6.1 apply to the page around it — and have been mandatory since 31 March 2025.

20 Aug 2026

We use a payment gateway, so PCI DSS does not apply to us

Outsourcing to a compliant gateway is the largest scope reduction PCI DSS offers, and the standard still says it does not make you compliant. Where the belief holds, and where it breaks.

20 Aug 2026

Tokenisation and card-on-file in India: what the regulator already decided

Since 1 October 2022 no Indian entity outside the card issuers and networks may store card data. What that leaves in PCI DSS scope: capture, log residue, the T+4 window, and a re-scope.

20 Aug 2026

Segmentation is a claim until Requirement 11.4.5 tests it

Segmentation reduces PCI DSS scope only if it holds. Requirement 11.4.5 is where that claim gets tested, and 11.4.6 makes it six-monthly for service providers.

20 Aug 2026

What is in your CDE, and what a scoping exercise produces

PCI DSS scope is three sets of systems, not one, and the third sits outside the CDE. What Requirement 12.5.2 asks a scoping exercise to produce, and why remediation started first is half wasted.

20 Aug 2026

Which SAQ applies to you: 14, 27, 139, or all of them

For e-commerce the SAQ is decided by where the payment form comes from: 14 requirements, 27, 139, or all of them. The eligibility table for all nine types, from PCI SSC's own guidance.

20 Aug 2026

Merchant and service provider levels: who assigns yours

Levels come from the payment brands’ rulebooks and are applied by your acquirer — PCI DSS v4.0.1 never mentions them. The Mastercard and Amex thresholds, and what a level changes.

20 Aug 2026

What an ASV does, and why Requirement 11.3.2 admits nobody else

Requirement 11.3.2 is the only requirement in PCI DSS Requirement 11 that names a credential. Requirement 11.3.2.1, the post-change external scan, deliberately does not.

20 Aug 2026

What a QSA does, what a QSA may not assess, and how to verify one

A QSA's qualification is granted per company, per region, per person and per version of the standard. Here is what that covers, what it bars, and how to check it.

20 Aug 2026

What "PCI DSS certification" actually means, and who signs it

The market says certification. What an assessed entity actually receives is a ROC plus an AOC, or an SAQ plus an AOC, and the signature block on each says something different.

20 Aug 2026

Who does what in a PCI DSS engagement

QSA, ASV, ISA, independent penetration tester, the entity, the acquirer and the payment brand: the six parties in a PCI DSS programme and the artefact each one produces.

20 Aug 2026

Have a question this did not answer?

Our team answers regulatory and testing questions directly — no discovery call required to get a straight answer.

Talk to our team