Recent FAQ Changes RSS

Latest changes to PCI SSC frequently asked questions.

FAQ 1265 New

Can I combine sections from PCI DSS version 2.0 and 3.0?

When validating compliance, either through a Report on Compliance (ROC) or a self-assessment questionnaire (SAQ), requirements should not be ?combined? from the two versions of the standard ? validation will …

FAQ 1275 New

What are the PA-DSS Expiry Dates?

The Expiry Date for PA-DSS Validated Payment Applications is the date by which a vendor must have the application reassessed against the current PA-DSS requirements in order for the application …

FAQ 1271 New

Can I combine sections from PA-DSS 2.0 and 3.0?

No. When validating payment application compliance through a Report on Validation (ROV) you may not ‘combine’ requirements from the two versions of the standard ? your assessment must be to …

FAQ 1269 New

When can I start using version 3.0 of the SAQs?

Version 3 of the self-assessment questionnaires (SAQs) are used to validate compliance against PCI DSS version 3, which is effective from January 1st, 2014. The PCI SSC strongly …

FAQ 1268 New

When does PCI DSS version 2.0 expire?

PCI DSS version 2.0 expires on December 31st, 2014, and any PCI DSS 2.0 validations must be completed prior to this date. PCI DSS version 3.0 is effective …

FAQ 1142 Updated

How do I contact the payment card brands?

Contact details for the payment brands are provided below:

American Express

  • Website: www.americanexpress.com/datasecurity
  • Email: AmericanExpressCompliance@trustwave.com

Discover - Website: http://www.discovernetwork.com/merchants/data-security/index.html -

FAQ 1142 Updated

How do I contact the payment card brands?

Contact details for the payment brands are provided below:

American Express

  • Website: www.americanexpress.com/datasecurity
  • Email: AmericanExpressCompliance@trustwave.com

Discover - Website: http://www.discovernetwork.com/merchants/data-security/index.html -