FAQ #1319 Reinstated Are merchants allowed to request card-verification codes/values from cardholders? Deleted: 2026-03-31T09:00:10.878811+00:00 → Reinstated: 2026-03-31T10:03:15.566253+00:00
FAQ #1324 Reinstated What changes are PFI companies allowed to make to the PFI Reporting Templates? Deleted: 2026-03-31T09:00:10.878811+00:00 → Reinstated: 2026-03-31T10:03:15.566253+00:00
FAQ #1591 Reinstated Why do requirements 8.3.9 and 8.3.10.1 focus on passwords/passphrases used for single-factor authentication, when multi-factor authentication is required for all access into the CDE? Deleted: 2026-03-31T09:00:10.878811+00:00 → Reinstated: 2026-03-31T10:03:15.566253+00:00
FAQ #1080 Reinstated Are administrators allowed to share passwords? Deleted: 2026-03-31T09:00:10.878811+00:00 → Reinstated: 2026-03-31T10:03:15.566253+00:00
FAQ #1281 Reinstated Are point-of-sale devices required to be physically secured (e.g. with a cable or tether) to prevent removal or substitution in order to meet PCI DSS Requirement 9.9? Deleted: 2026-03-31T09:00:10.878811+00:00 → Reinstated: 2026-03-31T10:03:15.566253+00:00
FAQ #1124 Reinstated PCI DSS provides a common data security standard across all payment brands. Are there any plans to provide a common structure of penalties and/or fines for non-compliance to this standard? Deleted: 2026-03-31T09:00:10.878811+00:00 → Reinstated: 2026-03-31T10:03:15.566253+00:00
FAQ #1092 Reinstated Does PCI DSS apply to merchants who outsource all payment processing operations and never store, process or transmit cardholder data? Deleted: 2026-03-31T09:00:10.878811+00:00 → Reinstated: 2026-03-31T10:03:15.566253+00:00
FAQ #1157 Reinstated What should a merchant do if cardholder data is accidentally received via an unintended channel? Deleted: 2026-03-31T09:00:10.878811+00:00 → Reinstated: 2026-03-31T10:03:15.566253+00:00