Recent FAQ Changes

FAQ #1146 New

What is the difference between masking and truncation?

Masking is addressed in PCI DSS Requirement 3.3, whereas truncation is one of several options specified to meet PCI DSS Requirement 3.4. Masking and truncation are both methods of rendering …

FAQ #1229 New

What is SAQ C-VT?

SAQ C-VT is a self-assessment questionnaire designed for brick-and-mortar (card-present) or mail/telephone-order (card-not-present) merchants that process cardholder data via virtual terminals on personal computers connected to the Internet, and that …

FAQ #1063 New

Does SAQ C-VT replace SAQ C?

SAQ C-VT does not replace SAQ C. Each SAQ is designed to support a different type of cardholder data environment. At a high level, SAQ C is intended for merchants …

FAQ #1064 New

What is a VT or Virtual Terminal?

A virtual terminal is web browser-based access to an acquirer, processor or third party service provider website to authorize payment card transactions over the Internet, where the merchant manually enters …

FAQ #1178 New

How do I reduce the scope of a PCI DSS assessment?

Network segmentation of, or isolating (segmenting), the cardholder data environment from the remainder of an entity?s network is strongly recommended as a method that may reduce the scope of a …