Recent FAQ Changes RSS

Latest changes to PCI SSC frequently asked questions.

FAQ 1537 New

Are remote assessments permitted for PCI DSS?

While onsite assessments continue to be the expected method for PCI SSC assessments, the use of remote assessment methods may provide a suitable alternative in legitimate scenarios where an onsite …

FAQ 1536 New

What is a compliance-accepting entity?

When assessment results are associated with compliance programs defined and managed by one or more payment brands, the compliance-accepting entity is the entity to which those assessment results (for example, …

FAQ 1146 Updated

What is the difference between masking and truncation?

Masking is addressed in PCI DSS Requirement 3.3, whereas truncation is one of several options specified to meet PCI DSS Requirement 3.4.

Requirement 3.3 relates to protection of PAN …