Website Documents RSS
PCI SSC documents published directly to the council's website — including ones that never appear in the Document Library.
March 2021 3.0 Added Software Security Assessor options to the PA-QSA prerequisite for PA-QSA(P2PE) Assessor qualification.
February 2014 2.0 Made minor changes to this document to be consistent with v3.0 of the PCI Data Security Standards. Qualifications required for entry are more precise and include a requirement for application development experience. The PA-
February 2017 3.0 Updated ASV Company qualification requirements to more closely align with QSA Qualification Requirements v2.1 and other PCI SSC Program qualification requirements: o Updated/clarified and enhanced various terms
March 2018 4.0 Update to reflect QIR Program Expansion
May 2015 2.0 • Made various grammar improvements; aligned terminology with PCI DSS v3.1 • Increased Violation period to three (3) years • Clarified QSA Company and Employee qualification requirements • Enhanced Business Legitimacy requirements
April 2019 4.0 Updated to reflect the CPE reporting requirements for the Qualified PIN Assessors and Card Production Security Assessors – Physical. Clarification provided on the reporting of CPEs.