PCiPCI Assessments Center
Kaitiaki, AI PCI ISA

Meet Kaitiaki — your Internal Security Assessor

Grounded in the PCI SSC library for PCI DSS v4.0.1 — ask about scoping, SAQ eligibility, evidence or your own gaps.

Your PCI assessment workspace.

Determine the right SAQ, complete it online against PCI DSS v4.0.1, and prepare your teams for PCIP and QSA — in one guided workspace.

10 official SAQs · PCI SSC-aligned · Free forever
PCI Assessments
Content Card · Platinum
0
Questions
189 domains
0
SAQs
v4.0.1 aligned
0
Controls
across 10 SAQs
0
Courses
lessons
0
Flashcards
terminology
0
Exam Tracks
AWARENESS · DEVELOPERS · +7
Valid Thru
PCI DSS · v4.0.1
Issued By
Haumaru Whānau · QSA
10 official SAQs
All PCI DSS v4.0.1 SAQs supported verbatim.
Verified email signup
Email code verification with disposable-domain blocking.
RLS-protected data
Every assessment isolated by tenant and role.
QSA-authored content
Built by Haumaru Whānau PCI QSA professionals.
Independent practice
Preparation for official PCIP and QSA exams.
Free self-assessment
Determine, attest and complete at no cost.
Threat watch

Why compliance posture matters

Live payment-security signals curated from public industry sources. Refreshed every few hours — nothing here is a PCI Assessments Center incident.

Regulationtoday

Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup

An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No login, no repository write access. A public repository and crafted Org-mode markup a…

The Hacker NewsRead
Breachtoday

Leaked n8n API Tokens Exposed Live Instances to Credential Theft

GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploiting a software vul…

The Hacker NewsRead
Threattoday

Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed. The "evil twin" ext…

The Hacker NewsRead
Threattoday

Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself

An agent running Anthropic's Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber evaluation by the UK's AI Security Institute. When a bystander publicly warned that the code…

The Hacker NewsRead
Threattoday

CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The list of vulnerabilities is…

The Hacker NewsRead
Threattoday

QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer

Cybersecurity researchers have disclosed what has been described as a "long-standing supply chain attack" on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users. According to Fortinet…

The Hacker NewsRead
Guidancetoday

Join Us at the Payment Industry Events of the Year

Registration is now open for the PCI Security Standards Council's 2026 Community Meetings! Join payments industry professionals from around the world for inspiring keynotes, valuable networking opportunities, expert-led sessions, hands-on…

PCI PerspectivesRead
Threattoday

Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms. One such service, Poison Claude, c…

The Hacker NewsRead
Regulationtoday

Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports

Two security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importin…

The Hacker NewsRead
Regulationtoday

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The three most serious: An unauthenticated flaw in Veeam's console that hands ove…

The Hacker NewsRead
Threattoday

Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain

Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer.…

The Hacker NewsRead
Regulationtoday

New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch

A memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built records for roughly 800 kernel bui…

The Hacker NewsRead
Threattoday

Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk

Kali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft's real authentication page. Once access and…

The Hacker NewsRead
Threat1 day ago

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorizat…

The Hacker NewsRead
Threat1 day ago

Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks

A credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026. SafeDep verified 353 poisoned versions across 79 pa…

The Hacker NewsRead
Threat1 day ago

Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access

Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthi…

The Hacker NewsRead
Threat1 day ago

When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted

The cybersecurity industry has spent decades assuming that offensive capability scales with technical expertise. That assumption is starting to break. Security teams have long estimated risk by ranking attacker sophistication. Nation-state…

The Hacker NewsRead
Threat1 day ago

Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent

Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing agent. The researche…

The Hacker NewsRead
Regulation1 day ago

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cPanel account and the server's administrative database identity. It shipped in a ta…

The Hacker NewsRead
Threat1 day ago

DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT

A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims' browser cache and ultimately deliver CountLoader and a previously undocumented remote access…

The Hacker NewsRead
Threat1 day ago

CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the…

The Hacker NewsRead
Threat2 days ago

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim's screen. Unit 42 detailed three attack paths against Chr…

The Hacker NewsRead
Threat2 days ago

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. In a report published over the weekend, Resecurity…

The Hacker NewsRead
Threat2 days ago

⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks

This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended. Some o…

The Hacker NewsRead
The path

From "which SAQ?" to "we're ready"

Every step is grounded in the PCI SSC v4.0.1 SAQ Instructions and Guidelines. No guesswork, no smaller SAQ than your scope allows.

1
Determine

Find the right assessment for your organisation.

2
Attest

Confirm official SAQ eligibility criteria.

3
Complete

Answer the correct SAQ with QSA guidance.

4
Plan with your AI PCI ISA

Turn every gap into a remediation plan and a scored risk register — free.

5
Validate

Review results online or engage a QSA to sign.

6
Train

Prepare your team for PCI certification exams with QSA-authored practice materials.

PCI DSS v4.0.1

What changed — and what you must plan for

Selected requirements the platform highlights during your assessment. Click through the deck or wait for it to rotate.

In effectReq 8.4

MFA for all access into the CDE

Multi-factor authentication is now required for all access into the Cardholder Data Environment, not just administrative access.

Offerings

Three doors, one path

Start free with a self-assessment or training. Bring in a QSA when the payment brand or acquirer asks for a signature.

Assessment
Self-Assessment

Structured PCI DSS eligibility check covering all 10 official PCI DSS v4.0.1 SAQs. Results are available online in your workspace.

  • Fail-closed eligibility mirrors PCI SSC decision tree
  • Verbatim controls with expected testing
  • Online results — no downloads
  • Per-tenant secure storage
Create a free account
Courses
PCIP & QSA readiness

Course tracks for PCIP and PCI QSA — lessons, quizzes, and readiness checklists, authored by practising QSAs.

  • PCIP fundamentals course
  • PCI QSA readiness course
  • QSA-authored lessons
  • Free for every organisation
  • Independent practice material — not official PCI SSC exams
Explore courses
QSA Services
Formal SAQ, AoC & ROC

When you need a signed SAQ, an Attestation of Compliance, or a Report on Compliance, a Haumaru Whānau QSA takes it from here.

  • Formal SAQ + Attestation of Compliance
  • ROC readiness & QSA-assisted assessments
  • Remediation sprints
  • Annual QSA retainer
Explore QSA services
Who it's for

Built for every side of PCI

FAQ

Frequently asked

Is the platform really free?

Yes. Self-assessments and every training module on PCI Assessments Center are free. There is no credit card, trial or paywall. Only formal QSA engagements — signed SAQ, Attestation of Compliance, ROC readiness, remediation, and retainers — are paid, and they are quoted individually.

Do I need to create an account?

Yes. A free account is required so your self-assessments and responses stay tied to your organisation. Each account belongs to a tenant, and row-level security ensures only members of your organisation can read your data.

Which SAQs are supported?

All 10 official PCI DSS v4.0.1 SAQs: A, A-EP, B, B-IP, C, C-VT, D-Merchant, D for Service Providers, P2PE, and SPoC. The guided selector uses the PCI SSC v4.0.1 SAQ Instructions to determine which SAQ applies to your environment, and requires you to attest the official eligibility criteria before you start.

How does PCI Assessments Center choose the right SAQ for me?

A fail-closed decision engine walks you through the PCI SSC v4.0.1 SAQ Instructions and Guidelines. Every question and eligibility check cites its source. If any short-form SAQ criterion is not met, the engine routes you to SAQ D or to a QSA — never a smaller SAQ than your scope allows.

What do I get at the end of a self-assessment?

A structured online result in your workspace: the correct SAQ for your scope, your eligibility attestation, the full selection rationale with citations, and your recorded responses. Results are online-only — there are no downloadable PDFs.

Why can't I download a PDF of my SAQ or AoC?

A downloadable SAQ or Attestation of Compliance implies formal validation. To keep that distinction clear, PCI Assessments Center only shows self-assessment results online. When you need a signed SAQ or AoC, request a formal engagement from QSA Services and a Haumaru Whānau QSA will issue it.

Can PCI Assessments Center replace a formal QSA engagement?

No. Self-assessments here are for readiness, scoping, and internal use. If your acquirer, payment brand, or a contract requires a signed SAQ, Attestation of Compliance, or Report on Compliance, request a formal engagement on the QSA Services page.

When do I need a QSA instead of a self-assessment?

You need a QSA if you are a PCI DSS Level 1 merchant or service provider, if your acquirer or brand mandates a Report on Compliance, if you have been designated for Designated Entities Supplemental Validation, or if you have had a recent card data breach. The guided selector flags these cases and routes you to QSA Services.

How much do formal QSA engagements cost?

Every engagement is scoped and quoted individually — complexity, environment size, evidence maturity, and geography all affect effort. Submit a request from QSA Services; a QSA will schedule a scoping call and follow up with a written quote.

How secure is my data?

Every table uses per-tenant row-level security, so only members of your organisation can read or write your data. Authentication runs on managed cloud infrastructure with sessions scoped per tenant.

Who is behind PCI Assessments Center?

Haumaru Whānau, a certified PCI QSA Company. Self-assessments and training remain free; formal QSA services are delivered by Haumaru Whānau QSAs and quoted separately.

Are the PCIP and QSA exams official PCI SSC exams?

No. The PCIP-style and QSA-style exams on PCI Assessments Center are independent practice and preparation exams created by Haumaru Whānau QSAs. They are not endorsed by, affiliated with, or a substitute for the official PCI Security Standards Council PCIP or QSA qualification exams.