PCI Security Standards Council Bulletin: Revised Update to FAQ 1331
PCI Security Standards Council Bulletin: Revised Update to FAQ 1331
4 August 2026
The PCI Security Standards Council (PCI SSC) has published an update to FAQ 1331: “Can SAQ
eligibility criteria be used as a guide for determining applicability of PCI DSS Requirements for merchant
assessments documented in a Report on Compliance (ROC)?”
Based on stakeholder feedback, the May 2025 version of FAQ 1331 may result in misinterpretations
related to compliance adherence responsibilities; as a result, PCI SSC has updated this guidance to
clarify that merchants should always consult with their Compliance Accepting Entities to confirm their PCI
DSS validation and reporting requirements.
Additional information is also included pointing to other related FAQs on the role of Compliance
Accepting Entities and how organizations may reach the payment brands.
FAQ 1331 is now available on the PCI SSC website.
###