Recent FAQ Changes RSS

Latest changes to PCI SSC frequently asked questions.

FAQ 1602 New

Should entities with enterprise or internal service providers, used to provide internal services to other corporate entities, conduct separate PCI DSS assessments of these service providers or include them as part of each corporate entity’s PCI DSS assessment?

Assessed entities have the discretion to either have enterprise functions assessed separately as an internal service provider or include those functions in each individual corporate entity’s PCI DSS assessment. Regardless …

FAQ 1223 Deleted

Does PCI DSS, PA-DSS, or PTS apply to ATMs?

PCI DSS applies to entities involved in payment card processing or that otherwise store, process, or transmit cardholder data; the Payment Application Data Security Standard (PA-DSS) applies to payment applications …

FAQ 1435 Updated

What is the Council's guidance on the use of SHA-1?

For more information about strong cryptography, refer to the Information Supplement: PCI Cryptography Guidance, available under Guidance Document in the PCI SSC Document Library. Our document library can be …

FAQ 1078 Updated

In what circumstances is multi-factor authentication required?

For more information about multi-factor authentication, refer to the Information Supplement: Authentication Guidance, available under Guidance Document in the PCI SSC Document Library. Our document library can be accessed …

FAQ 1449 Updated

Is two-step authentication acceptable for PCI DSS Requirement 8.4?

For more information about multi-factor authentication, refer to the Information Supplement: Authentication Guidance, available under Guidance Document in the PCI SSC Document Library. Our document library can be accessed …