Recent FAQ Changes RSS

Latest changes to PCI SSC frequently asked questions.

FAQ 1569 Updated

Is sampling allowed in PCI DSS v4.x?

Yes. Assessors have two options when performing PCI DSS testing procedures; they can either: 1) test a representative sample of the population according to the assessor's defined sampling methodology, or …

FAQ 1300 Updated

How does PCI DSS apply to payment terminals?

Payment terminals (sometimes referred to as point-of-sales systems, point-of-interaction devices, or payment devices) are physical devices that capture payment card data to process transactions. Because these devices are directly involved …

FAQ 1086 Updated

How does encrypted cardholder data impact PCI DSS scope?

Encryption of cardholder data with strong cryptography is an acceptable method of rendering the data unreadable according to PCI DSS Requirement 3.5.1. However, encryption alone is insufficient to render the …