PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Kaitiaki, AI PCI ISA

Meet Kaitiaki — your Internal Security Assessor

Grounded in the PCI SSC library for PCI DSS v4.0.1 — ask about scoping, SAQ eligibility, evidence or your own gaps.

Your PCI assessment workspace.

Determine the right SAQ, complete it online against PCI DSS v4.0.1, and prepare your teams for PCIP and QSA — in one guided workspace.

10 official SAQs · PCI SSC-aligned · Free forever
PCI Assessments
Content Card · Platinum
0
Questions
189 domains
0
SAQs
v4.0.1 aligned
0
Controls
across 11 SAQs
0
Courses
lessons
0
Flashcards
terminology
0
Exam Tracks
AWARENESS · DEVELOPERS · +7
Valid Thru
PCI DSS · v4.0.1
Issued By
Haumaru Whānau · QSA
10 official SAQs
All PCI DSS v4.0.1 SAQs supported verbatim.
Verified email signup
Email code verification with disposable-domain blocking.
RLS-protected data
Every assessment isolated by tenant and role.
QSA-authored content
Built by Haumaru Whānau PCI QSA professionals.
Independent practice
Preparation for official PCIP and QSA exams.
Free self-assessment
Determine, attest and complete at no cost.
Threat watch

Why compliance posture matters

Live payment-security signals curated from public industry sources. Refreshed every few hours — nothing here is a PCI Assessments Center incident.

Breach1 day ago

Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second

Cybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker in the production environment at up to 12 bits per second, 360 times the rat…

The Hacker NewsRead
Threat1 day ago

OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior

OpenAI on Tuesday revealed that it paused reinforcement learning (RL) training for its latest artificial intelligence (AI) models for two weeks while it shored up additional defenses and increased the scope of its monitoring to avert anoth…

The Hacker NewsRead
Threat1 day ago

Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management (PLM) software, according to n…

The Hacker NewsRead
Threat1 day ago

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. The shortcomings added to t…

The Hacker NewsRead
Threat1 day ago

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity…

The Hacker NewsRead
Threat1 day ago

SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs

A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia. The intrusion set makes use of seven remote access tool (RAT) families, five of which have never been prev…

The Hacker NewsRead
Threat1 day ago

Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-…

The Hacker NewsRead
Threat1 day ago

Phishing 3.0: The Fight Moves to Agent Versus Agent

Most email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat in the payload, a bad link or an attachment. It stopped working when the danger moved int…

The Hacker NewsRead
Threat1 day ago

Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure

Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring endpoint and network behaviors across changing infrastructure, tracing the malware from pa…

The Hacker NewsRead
Regulation2 days ago

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim's Copil…

The Hacker NewsRead
Threat2 days ago

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing m…

The Hacker NewsRead
Threat2 days ago

Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000

A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000…

The Hacker NewsRead
Threat2 days ago

16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the mo…

The Hacker NewsRead
Guidance2 days ago

2026 Asia-Pacific Community Meeting Agenda Highlights

The upcoming PCI SSC Asia-Pacific Community Meeting in Kuala Lumpur, Malaysia, 11-12 November, features a dynamic agenda packed with expert speakers, thought-provoking keynotes, valuable networking opportunities, and the latest insights on…

PCI PerspectivesRead
Threat2 days ago

AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files

Security researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next through the editable system prompt files that autonomous agent har…

The Hacker NewsRead
Threat2 days ago

TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT. "TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructu…

The Hacker NewsRead
Threat2 days ago

One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco. The act…

The Hacker NewsRead
Breach2 days ago

SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers

SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. The hardware wallet maker said all…

The Hacker NewsRead
Threat2 days ago

CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Ray is an open-source, Python-nati…

The Hacker NewsRead
Regulation3 days ago

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to ex…

The Hacker NewsRead
Threat3 days ago

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026-59310 (CVS…

The Hacker NewsRead
Threat3 days ago

How MCP Servers Can Expose Enterprise Secrets

MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server is running. As more organizations adopt AI agents into their s…

The Hacker NewsRead
Regulation3 days ago

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites. The vulnerability, tracked a…

The Hacker NewsRead
Threat3 days ago

Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Russian cybersecurity company Kaspers…

The Hacker NewsRead
The path

From "which SAQ?" to "we're ready"

Every step is grounded in the PCI SSC v4.0.1 SAQ Instructions and Guidelines. No guesswork, no smaller SAQ than your scope allows.

1
Determine

Find the right assessment for your organisation.

2
Attest

Confirm official SAQ eligibility criteria.

3
Complete

Answer the correct SAQ with QSA guidance.

4
Plan with your AI PCI ISA

Turn every gap into a remediation plan and a scored risk register — free.

5
Validate

Review results online or engage a QSA to sign.

6
Train

Prepare your team for PCI certification exams with QSA-authored practice materials.

PCI DSS v4.0.1

What changed — and what you must plan for

Selected requirements the platform highlights during your assessment. Click through the deck or wait for it to rotate.

In effectReq 8.4

MFA for all access into the CDE

Multi-factor authentication is now required for all access into the Cardholder Data Environment, not just administrative access.

Offerings

Three doors, one path

Start free with a self-assessment or training. Bring in a QSA when the payment brand or acquirer asks for a signature.

Assessment
Self-Assessment

Structured PCI DSS eligibility check covering all 10 official PCI DSS v4.0.1 SAQs. Results are available online in your workspace.

  • Fail-closed eligibility mirrors PCI SSC decision tree
  • Verbatim controls with expected testing
  • Online results — no downloads
  • Per-tenant secure storage
Create a free account
Courses
PCIP & QSA readiness

Course tracks for PCIP and PCI QSA — lessons, quizzes, and readiness checklists, authored by practising QSAs.

  • PCIP fundamentals course
  • PCI QSA readiness course
  • QSA-authored lessons
  • Free for every organisation
  • Independent practice material — not official PCI SSC exams
Explore courses
QSA Services
Formal SAQ, AoC & ROC

When you need a signed SAQ, an Attestation of Compliance, or a Report on Compliance, a Haumaru Whānau QSA takes it from here.

  • Formal SAQ + Attestation of Compliance
  • ROC readiness & QSA-assisted assessments
  • Remediation sprints
  • Annual QSA retainer
Explore QSA services
Who it's for

Built for every side of PCI

FAQ

Frequently asked

Is the platform really free?

Yes. Self-assessments and every training module on PCI Assessments Center are free. There is no credit card, trial or paywall. Only formal QSA engagements — signed SAQ, Attestation of Compliance, ROC readiness, remediation, and retainers — are paid, and they are quoted individually.

Do I need to create an account?

Yes. A free account is required so your self-assessments and responses stay tied to your organisation. Each account belongs to a tenant, and row-level security ensures only members of your organisation can read your data.

Which SAQs are supported?

All 10 official PCI DSS v4.0.1 SAQs: A, A-EP, B, B-IP, C, C-VT, D-Merchant, D for Service Providers, P2PE, and SPoC. The guided selector uses the PCI SSC v4.0.1 SAQ Instructions to determine which SAQ applies to your environment, and requires you to attest the official eligibility criteria before you start.

How does PCI Assessments Center choose the right SAQ for me?

A fail-closed decision engine walks you through the PCI SSC v4.0.1 SAQ Instructions and Guidelines. Every question and eligibility check cites its source. If any short-form SAQ criterion is not met, the engine routes you to SAQ D or to a QSA — never a smaller SAQ than your scope allows.

What do I get at the end of a self-assessment?

A structured online result in your workspace: the correct SAQ for your scope, your eligibility attestation, the full selection rationale with citations, and your recorded responses. Results are online-only — there are no downloadable PDFs.

Why can't I download a PDF of my SAQ or AoC?

A downloadable SAQ or Attestation of Compliance implies formal validation. To keep that distinction clear, PCI Assessments Center only shows self-assessment results online. When you need a signed SAQ or AoC, request a formal engagement from QSA Services and a Haumaru Whānau QSA will issue it.

Can PCI Assessments Center replace a formal QSA engagement?

No. Self-assessments here are for readiness, scoping, and internal use. If your acquirer, payment brand, or a contract requires a signed SAQ, Attestation of Compliance, or Report on Compliance, request a formal engagement on the QSA Services page.

When do I need a QSA instead of a self-assessment?

You need a QSA if you are a PCI DSS Level 1 merchant or service provider, if your acquirer or brand mandates a Report on Compliance, if you have been designated for Designated Entities Supplemental Validation, or if you have had a recent card data breach. The guided selector flags these cases and routes you to QSA Services.

How much do formal QSA engagements cost?

Every engagement is scoped and quoted individually — complexity, environment size, evidence maturity, and geography all affect effort. Submit a request from QSA Services; a QSA will schedule a scoping call and follow up with a written quote.

How secure is my data?

Every table uses per-tenant row-level security, so only members of your organisation can read or write your data. Authentication runs on managed cloud infrastructure with sessions scoped per tenant.

Who is behind PCI Assessments Center?

Haumaru Whānau, a certified PCI QSA Company. Self-assessments and training remain free; formal QSA services are delivered by Haumaru Whānau QSAs and quoted separately.

Are the PCIP and QSA exams official PCI SSC exams?

No. The PCIP-style and QSA-style exams on PCI Assessments Center are independent practice and preparation exams created by Haumaru Whānau QSAs. They are not endorsed by, affiliated with, or a substitute for the official PCI Security Standards Council PCIP or QSA qualification exams.