Recent FAQ Changes RSS

Latest changes to PCI SSC frequently asked questions.

FAQ 1485 New

What is the meaning of ?initial assessment? in PCI DSS?

An initial assessment is an entity?s first formal PCI DSS assessment that results in the submission of a compliance validation document. Examples of validation documents include an Attestation of Compliance …

FAQ 1247 Updated

Who can use SAQ P2PE?

SAQ P2PE is intended for SAQ-eligible merchants or merchant environments (as determined by the individual payment card brands), that process cardholder data only via a validated PCI-listed P2PE solution. Whether …

FAQ 1142 Updated

How do I contact the payment card brands?

Contact the payment brands and/or acquirer (merchant bank) for more information about PCI compliance programs.

Contact details for the payment brands are provided below:

| American Express | …

FAQ 1480 New

Which P2PE Program Guide version do I use?

P2PE v2 Program Guide:  Used for the assessment and management of P2PE v2 solutions, applications, and components.P2PE v3 Program Guide:  Used for the assessment and management of P2PE v3 …