Recent Updates RSS
The latest changes across all tracked PCI resources.
Organizations that participate in data preparation, manufacturing, personalizing, and/or embossing for plastic cards are considered Card Production Vendors and are typically required to adhere to the Card Production and Provisioning …
The 2024 PCI SSC Global Content Library is now available! The PCI SSC Global Content Library is home to hours of video content from PCI SSC’s Community Meetings. Learn directly …
Collaboration is at the heart of the PCI Security Standards Council’s mission to help secure payment data globally. As a global forum, the Council brings together payments industry stakeholders to …
Yes, a PFI Final Report is required. The expectation is that the PFI must complete the merchant?s PFI Investigation and produce the PFI Final Report, with details of adequate evidence …
Yes, a PFI Final Report is required. The expectation is that the PFI must complete the merchant’s PFI Investigation and produce the Final PFI Report, with details of adequate evidence …
When completing the spreadsheet referenced within the Final PFI Report under Appendix C: Impacted Entities, an account is considered ?at risk? if evidence indicates the account number was exposed (i.e. …
To address stakeholder feedback and questions received since PCI DSS v4.0 was published in March 2022, PCI SSC is planning a limited revision of the standard. Proposed changes include correcting …
Yes. PCI SSC considers the guidance provided from many different standards organizations when updating our standards, balancing the guidance against the unique needs and challenges of the payments industry.There may …
Yes. PCI SSC considers the guidance provided from many different standards organizations when updating our standards, balancing the guidance against the unique needs and challenges of the payments industry.
…
Yes, a PFI Final Report is required. The expectation is that the PFI must complete the merchant’s PFI Investigation and produce the Final PFI Report, with details of adequate evidence …
Yes, a PFI Final Report is required. The expectation is that the PFI must complete the merchant?s PFI Investigation and produce the PFI Final Report, with details of adequate evidence …
From 6 December to 19 January 2024, eligible stakeholders are invited to review and provide feedback on the draft PCI 3DS Core Security Standard v2.0 and draft PCI 3DS Data …
Risk analysis is a foundational tool to help organizations identify and prioritize potential threats and vulnerabilities within their environment. PCI DSS v4.0 introduced the concept of targeted risk analysis (TRA) …