Answer yes if your organisation’s relevant services or environments have been validated through either: (1) a Self Assessment Questionnaire (SAQ), or (2) a Report on Compliance (RoC) if performed by a Qualified Security Assessor (QSA) or Internal Security Assessor (ISA). Upload the Attestation of Compliance (AOC) and the Shared Responsibility Matrix.
PCI DSS v4.0 is the current global standard designed to ensure that organisations that process, store, or transmit credit card information maintain a secure environment. Validation is typically via a Self-Assessment Questionnaire (SAQ), or for larger organisations or those with higher transaction volumes, a more rigorous Report on Compliance (RoC) is required, conducted by either an ISA or a QSA. Regardless of the assessment type, an Attestation of Compliance (AoC) is used to demonstrate your compliance. Please provide the AoC and associated the Shared Responsibility Matrix.
Please visit the PCI Security Standards Council’s website for more information on whether your organisation may need to comply with the PCI DSS.
If you would like to contribute to this article or provide feedback, please email knowledge@riskledger.com. Contributors will be recognised on our contributors page.