Kaitiaki, AI PCI ISA

Meet Kaitiaki — your Internal Security Assessor

Grounded in the PCI SSC library for PCI DSS v4.0.1 — ask about scoping, SAQ eligibility, evidence or your own gaps.

Your PCI assessment workspace.

Determine the right SAQ, complete it online against PCI DSS v4.0.1, and prepare your teams for PCIP and QSA — in one guided workspace.

10 official SAQs · PCI SSC-aligned · Free forever
PCI Assessments
Content Card · Platinum
0
Questions
189 domains
0
SAQs
v4.0.1 aligned
0
Controls
across 10 SAQs
0
Courses
lessons
0
Flashcards
terminology
0
Exam Tracks
AWARENESS · DEVELOPERS · +7
Valid Thru
PCI DSS · v4.0.1
Issued By
Haumaru Whānau · QSA
10 official SAQs
All PCI DSS v4.0.1 SAQs supported verbatim.
Verified email signup
Email code verification with disposable-domain blocking.
RLS-protected data
Every assessment isolated by tenant and role.
QSA-authored content
Built by Haumaru Whānau PCI QSA professionals.
Independent practice
Preparation for official PCIP and QSA exams.
Free self-assessment
Determine, attest and complete at no cost.
Threat watch

Why compliance posture matters

Live payment-security signals curated from public industry sources. Refreshed every few hours — nothing here is a PCI Assessments Center incident.

Talk to a QSA
Regulation1 day ago

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet…

The Hacker News
Threat1 day ago

Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites

Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses. Adform detected the incident on July 27, 2026, removed the malicious c…

The Hacker News
Regulation1 day ago

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as C…

The Hacker News
Threat1 day ago

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report. Researchers trac…

The Hacker News
Threat2 days ago

Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk

A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syria…

The Hacker News
Threat2 days ago

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According to Blackpoint Cyber, the intrusion sequence begins with a…

The Hacker News
The path

From "which SAQ?" to "we're ready"

Every step is grounded in the PCI SSC v4.0.1 SAQ Instructions and Guidelines. No guesswork, no smaller SAQ than your scope allows.

1
Determine

Find the right assessment for your organisation.

2
Attest

Confirm official SAQ eligibility criteria.

3
Complete

Answer the correct SAQ with QSA guidance.

4
Plan with your AI PCI ISA

Turn every gap into a remediation plan and a scored risk register — free.

5
Validate

Review results online or engage a QSA to sign.

6
Train

Prepare your team for PCI certification exams with QSA-authored practice materials.

PCI DSS v4.0.1

What changed — and what you must plan for

Selected requirements the platform highlights during your assessment. Click through the deck or wait for it to rotate.

In effectReq 8.4

MFA for all access into the CDE

Multi-factor authentication is now required for all access into the Cardholder Data Environment, not just administrative access.

Offerings

Three doors, one path

Start free with a self-assessment or training. Bring in a QSA when the payment brand or acquirer asks for a signature.

Assessment
Self-Assessment

Structured PCI DSS eligibility check covering all 10 official PCI DSS v4.0.1 SAQs. Results are available online in your workspace.

  • Fail-closed eligibility mirrors PCI SSC decision tree
  • Verbatim controls with expected testing
  • Online results — no downloads
  • Per-tenant secure storage
Create a free account
Courses
PCIP & QSA readiness

Course tracks for PCIP and PCI QSA — lessons, quizzes, and readiness checklists, authored by practising QSAs.

  • PCIP fundamentals course
  • PCI QSA readiness course
  • QSA-authored lessons
  • Free for every organisation
  • Independent practice material — not official PCI SSC exams
Explore courses
QSA Services
Formal SAQ, AoC & ROC

When you need a signed SAQ, an Attestation of Compliance, or a Report on Compliance, a Haumaru Whānau QSA takes it from here.

  • Formal SAQ + Attestation of Compliance
  • ROC readiness & QSA-assisted assessments
  • Remediation sprints
  • Annual QSA retainer
Explore QSA services
Who it's for

Built for every side of PCI

FAQ

Frequently asked

Is the platform really free?

Yes. Self-assessments and every training module on PCI Assessments Center are free. There is no credit card, trial or paywall. Only formal QSA engagements — signed SAQ, Attestation of Compliance, ROC readiness, remediation, and retainers — are paid, and they are quoted individually.

Do I need to create an account?

Yes. A free account is required so your self-assessments and responses stay tied to your organisation. Each account belongs to a tenant, and row-level security ensures only members of your organisation can read your data.

Which SAQs are supported?

All 10 official PCI DSS v4.0.1 SAQs: A, A-EP, B, B-IP, C, C-VT, D-Merchant, D for Service Providers, P2PE, and SPoC. The guided selector uses the PCI SSC v4.0.1 SAQ Instructions to determine which SAQ applies to your environment, and requires you to attest the official eligibility criteria before you start.

How does PCI Assessments Center choose the right SAQ for me?

A fail-closed decision engine walks you through the PCI SSC v4.0.1 SAQ Instructions and Guidelines. Every question and eligibility check cites its source. If any short-form SAQ criterion is not met, the engine routes you to SAQ D or to a QSA — never a smaller SAQ than your scope allows.

What do I get at the end of a self-assessment?

A structured online result in your workspace: the correct SAQ for your scope, your eligibility attestation, the full selection rationale with citations, and your recorded responses. Results are online-only — there are no downloadable PDFs.

Why can't I download a PDF of my SAQ or AoC?

A downloadable SAQ or Attestation of Compliance implies formal validation. To keep that distinction clear, PCI Assessments Center only shows self-assessment results online. When you need a signed SAQ or AoC, request a formal engagement from QSA Services and a Haumaru Whānau QSA will issue it.

Can PCI Assessments Center replace a formal QSA engagement?

No. Self-assessments here are for readiness, scoping, and internal use. If your acquirer, payment brand, or a contract requires a signed SAQ, Attestation of Compliance, or Report on Compliance, request a formal engagement on the QSA Services page.

When do I need a QSA instead of a self-assessment?

You need a QSA if you are a PCI DSS Level 1 merchant or service provider, if your acquirer or brand mandates a Report on Compliance, if you have been designated for Designated Entities Supplemental Validation, or if you have had a recent card data breach. The guided selector flags these cases and routes you to QSA Services.

How much do formal QSA engagements cost?

Every engagement is scoped and quoted individually — complexity, environment size, evidence maturity, and geography all affect effort. Submit a request from QSA Services; a QSA will schedule a scoping call and follow up with a written quote.

How secure is my data?

Every table uses per-tenant row-level security, so only members of your organisation can read or write your data. Authentication runs on managed cloud infrastructure with sessions scoped per tenant.

Who is behind PCI Assessments Center?

Haumaru Whānau, a certified PCI QSA Company. Self-assessments and training remain free; formal QSA services are delivered by Haumaru Whānau QSAs and quoted separately.

Are the PCIP and QSA exams official PCI SSC exams?

No. The PCIP-style and QSA-style exams on PCI Assessments Center are independent practice and preparation exams created by Haumaru Whānau QSAs. They are not endorsed by, affiliated with, or a substitute for the official PCI Security Standards Council PCIP or QSA qualification exams.