Compass IT Compliance Blog / PCI Compliance

What Is a PCI DSS Gap Analysis & What Should You Expect to Find?

What Is a PCI DSS Gap Analysis & What Should You Expect to Find?

Before an organization commits to a full PCI DSS assessment, most experienced QSAs recommend starting with a gap analysis. It is a lower-pressure, exploratory step that tells you where you actually stand before the clock starts on a formal engagement. Here is what a PCI gap analysis i …

Read Story

Do You Need a QSA? How to Choose the Right Assessor for Your Firm

Do You Need a QSA How to Choose the Right Assessor for Your Firm

If your business stores, processes, or transmits cardholder data, you have almost certainly come across the term QSA. But whether you actually need to hire one, and how to pick a good one if you do, is not always clear. This guide breaks down what a Qualified Security Assessor does, w …

Read Story

SAQ A, Requirements 6.4.3 & 11.6.1: What the Eligibility Change Means

SAQ A, Requirements 6.4.3 & 11.6.1: What the Eligibility Change Means

A question has been coming up recently among people who work with e-commerce merchants, and it can be a real head-scratcher the first time you hit it. A small merchant qualifies for SAQ A and notices that Requirements 6.4.3 and 11.6.1 are simply gone from the form. A larger merchant w …

Read Story

How to Define Your Cardholder Data Environment (CDE) Under PCI DSS

How to Define Your Cardholder Data Environment (CDE) Under PCI DSS

Before an organization can implement Payment Card Industry Data Security Standard (PCI DSS) controls, it must answer a foundational question: what is in scope? The answer lies in the definition of the Cardholder Data Environment (CDE). Get it wrong, and everything built on top of it i …

Read Story

When to Hire a PCI Compliance Consultant (and What They Actually Do)

When to Hire a PCI Compliance Consultant (and What They Actually Do)

If your business stores, processes, or transmits cardholder data, PCI DSS compliance isn't optional. But knowing that you need to comply is a very different thing from knowing how to actually get there. Somewhere between your first self-assessment questionnaire and your first failed s …

Read Story

PCI DSS Compensating Controls: When & How to Use Them

PCI DSS Compensating Controls - When and How to Use Them

Every organization that stores, processes, or transmits payment card data eventually runs into the same wall. The Payment Card Industry Data Security Standard (PCI DSS) sets a clear bar, but a legacy system, a vendor limitation, or a business reality can make a specific requirement im …

Read Story

Subscribe by email