- What they do
- Enterprise multi-framework
- Who they help
- Tevora is an enterprise multi-framework based in Irvine, CA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Framework Information Security & Privacy
PCI DSS
The Payment Card Industry Data Security Standard is the card brands' baseline for any organization that stores, processes or transmits cardholder data or can affect its security. The current version is PCI DSS v4.0.1, published June 11, 2024; v4.0 was retired on December 31, 2024, and the requirements that were future-dated in v4.0 became mandatory on March 31, 2025.
The standard has twelve requirements covering network security, secure configuration, protection of stored account data, encryption in transit, malware protection, secure development, access control, authentication, physical security, logging, testing and information security policy, plus a customized approach for organizations that want to meet objectives differently.
PCI DSS is documentation-intensive. It expects a maintained cardholder data environment scope and data flow diagrams, an information security policy reviewed annually, targeted risk analyses for frequency-based controls, documented roles and responsibilities for every requirement, an incident response plan, third-party service provider inventories and responsibility matrices, and an annual Report on Compliance (ROC) or Self-Assessment Questionnaire (SAQ) with an Attestation of Compliance.
Which validation path applies (QSA ROC or a specific SAQ) is decided by the acquirer and card brand programs based on merchant or service provider level.
Who has to comply
Merchants, service providers, acquirers, issuers and any other entity that stores, processes or transmits cardholder data or sensitive authentication data, or that could affect its security. Validation level depends on annual transaction volume and the brand program: Level 1 merchants and most service providers need a QSA ROC; smaller merchants complete an SAQ.
What the assessor asks to see
CDE scope, network and data flow diagrams; asset inventory; information security policy and procedures per requirement; firewall and configuration standards; encryption and key management documentation; vulnerability scan and penetration test reports; access control lists and MFA evidence; log samples and daily review records; change control records; secure development evidence; physical security records; awareness training; incident response plan and test; third-party service provider list and responsibility matrix; prior ROC, SAQ and AOC.
Where the requirement sits: 12.1.1 policy reviewed annually; 12.6.3 awareness training at hire and annually with acknowledgment; 12.10 IR plan. Technical: 5, 10 (logging), 11 (scanning)
Self-Assessment Questionnaires under v4.0.1
Ten SAQs exist: SAQ A (card-not-present, fully outsourced payment page), SAQ A-EP (e-commerce where the merchant site affects the payment page), SAQ B (imprint or standalone dial-out terminals), SAQ B-IP (standalone PTS-approved IP-connected terminals), SAQ C (payment application systems connected to the internet), SAQ C-VT (virtual terminal on a single computer), SAQ P2PE (validated P2PE solution only), SAQ SPoC (software-based PIN entry on COTS), SAQ D for Merchants (all other merchants) and SAQ D for Service Providers (the only SAQ for eligible service providers).
Eligibility is set by the SAQ instructions and the acquirer.
Version timeline
PCI DSS v3.2.1 was retired March 31, 2024. v4.0.1 was published June 11, 2024 as a limited revision correcting v4.0, which was retired December 31, 2024. The 51 requirements that were best practice under v4.0 became mandatory on March 31, 2025.
Check the PCI SSC document library for any later revision.
What AllyMatter does here
The Requirement 12 policy and annual-acknowledgment layer of PCI DSS.
AllyMatter publishes this site.
Assessors
Who assesses PCI DSS
A PCI SSC qualified Qualified Security Assessor (QSA) company with certified QSA employees performs the ROC. Certified Internal Security Assessors (ISAs) can support internal assessments where the acquirer permits. Approved Scanning Vendors (ASVs) perform quarterly external vulnerability scans.
Small merchants self-assess on an SAQ. Accredited by PCI Security Standards Council qualifies QSA, ISA and ASV companies and individuals; there is no national accreditation body.
Public register of assessors: https://www.pcisecuritystandards.org/assessors_and_solutions/qualified_security_assessors/
No firm has claimed a PCI DSS assessor listing yet. Claim yours →
Consultants
Who helps with PCI DSS
A very large ecosystem: QSA companies selling readiness and gap assessments, PCI consultancies, managed security providers, ASV scanning vendors and compliance platforms. Engagements range from SAQ assistance to multi-month ROC readiness projects. The readiness consultant and the signing QSA may be the same firm subject to independence rules.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
- What they do
- Full-service GRC + vCISO
- Who they help
- Truvantis is a full-service GRC + vCISO based in San Francisco, CA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Software
Tools for PCI DSS
Tools that name this framework in their own material.
Related reading
- PCI DSS v4.0.1 unveiled: what's new and what it means for youA QSA company goes through the v4.0.1 clarifications and the future-dated requirements that became mandatory in March 2025.Schellman
- Targeted risk assessments in PCI DSS 4.0.1Explains the targeted risk analysis documents assessors now expect, and how they set your own control frequencies.Frazier & Deeter
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for PCI DSS
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Run the Policy Side of PCI DSS in AllyMatter
Approve the policies PCI DSS asks for, keep every version, and record a named acknowledgment from each person who has to read them.