PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Kaitiaki, AI PCI ISA

Meet Kaitiaki — your Internal Security Assessor

Grounded in the PCI SSC library for PCI DSS v4.0.1 — ask about scoping, SAQ eligibility, evidence or your own gaps.

Your PCI assessment workspace.

Determine the right SAQ, complete it online against PCI DSS v4.0.1, and prepare your teams for PCIP and QSA — in one guided workspace.

10 official SAQs · PCI SSC-aligned · Free forever
PCI Assessments
Content Card · Platinum
0
Questions
189 domains
0
SAQs
v4.0.1 aligned
0
Controls
across 11 SAQs
0
Courses
lessons
0
Flashcards
terminology
0
Exam Tracks
AWARENESS · DEVELOPERS · +7
Valid Thru
PCI DSS · v4.0.1
Issued By
Haumaru Whānau · QSA
10 official SAQs
All PCI DSS v4.0.1 SAQs supported verbatim.
Verified email signup
Email code verification with disposable-domain blocking.
RLS-protected data
Every assessment isolated by tenant and role.
QSA-authored content
Built by Haumaru Whānau PCI QSA professionals.
Independent practice
Preparation for official PCIP and QSA exams.
Free self-assessment
Determine, attest and complete at no cost.
Threat watch

Why compliance posture matters

Live payment-security signals curated from public industry sources. Refreshed every few hours — nothing here is a PCI Assessments Center incident.

Regulation1 day ago

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim's Copil…

The Hacker NewsRead
Threat1 day ago

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing m…

The Hacker NewsRead
Threat1 day ago

Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000

A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000…

The Hacker NewsRead
Threat1 day ago

16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the mo…

The Hacker NewsRead
Guidance1 day ago

2026 Asia-Pacific Community Meeting Agenda Highlights

The upcoming PCI SSC Asia-Pacific Community Meeting in Kuala Lumpur, Malaysia, 11-12 November, features a dynamic agenda packed with expert speakers, thought-provoking keynotes, valuable networking opportunities, and the latest insights on…

PCI PerspectivesRead
Threat1 day ago

AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files

Security researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next through the editable system prompt files that autonomous agent har…

The Hacker NewsRead
Threat1 day ago

TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT. "TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructu…

The Hacker NewsRead
Threat1 day ago

One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco. The act…

The Hacker NewsRead
Breach1 day ago

SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers

SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. The hardware wallet maker said all…

The Hacker NewsRead
Threat1 day ago

CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Ray is an open-source, Python-nati…

The Hacker NewsRead
Regulation2 days ago

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to ex…

The Hacker NewsRead
Regulation2 days ago

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites. The vulnerability, tracked a…

The Hacker NewsRead
Threat2 days ago

How MCP Servers Can Expose Enterprise Secrets

MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server is running. As more organizations adopt AI agents into their s…

The Hacker NewsRead
Threat2 days ago

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026-59310 (CVS…

The Hacker NewsRead
Guidance2 days ago

The AI Exchange: Innovators in Payment Security Featuring GM Sectec

Welcome to the PCI Security Standards Council’s blog series, The AI Exchange: Innovators in Payment Security. This special, ongoing feature of our PCI Perspectives blog offers a resource for payment security industry stakeholders to exchan…

PCI PerspectivesRead
Threat2 days ago

Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Russian cybersecurity company Kaspers…

The Hacker NewsRead
Threat2 days ago

Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies.…

The Hacker NewsRead
Threat2 days ago

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, with no fix from the chipset maker. The ad…

The Hacker NewsRead
Threat2 days ago

⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading farther than the origin…

The Hacker NewsRead
Regulation2 days ago

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify o…

The Hacker NewsRead
Threat4 days ago

SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch

A maximum-severity security vulnerability impacting SAP Commerce Cloud is witnessing active exploitation efforts. The vulnerability, tracked as CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It relates to an instance of insuffic…

The Hacker NewsRead
Breach4 days ago

Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner

A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyber Security Centre (NCSC-NL) has warned. The vulnerability in question is CVE-2026…

The Hacker NewsRead
Threat5 days ago

Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware

Threat actors are acquiring expired domains to inherit website traffic and reputation to redirect victims to scams and malware on a large scale. DNS threat intelligence firm Infoblox has given the name dropcatch domains to those that get a…

The Hacker NewsRead
Regulation5 days ago

IAM Compliance Requirements and Best Practices

IAM compliance is the practice of demonstrating that identity and access controls are not only documented but actually enforced across users, applications, infrastructure, and non-human identities. This guide explains what IAM compliance r…

The Hacker NewsRead
The path

From "which SAQ?" to "we're ready"

Every step is grounded in the PCI SSC v4.0.1 SAQ Instructions and Guidelines. No guesswork, no smaller SAQ than your scope allows.

1
Determine

Find the right assessment for your organisation.

2
Attest

Confirm official SAQ eligibility criteria.

3
Complete

Answer the correct SAQ with QSA guidance.

4
Plan with your AI PCI ISA

Turn every gap into a remediation plan and a scored risk register — free.

5
Validate

Review results online or engage a QSA to sign.

6
Train

Prepare your team for PCI certification exams with QSA-authored practice materials.

PCI DSS v4.0.1

What changed — and what you must plan for

Selected requirements the platform highlights during your assessment. Click through the deck or wait for it to rotate.

In effectReq 8.4

MFA for all access into the CDE

Multi-factor authentication is now required for all access into the Cardholder Data Environment, not just administrative access.

Offerings

Three doors, one path

Start free with a self-assessment or training. Bring in a QSA when the payment brand or acquirer asks for a signature.

Assessment
Self-Assessment

Structured PCI DSS eligibility check covering all 10 official PCI DSS v4.0.1 SAQs. Results are available online in your workspace.

  • Fail-closed eligibility mirrors PCI SSC decision tree
  • Verbatim controls with expected testing
  • Online results — no downloads
  • Per-tenant secure storage
Create a free account
Courses
PCIP & QSA readiness

Course tracks for PCIP and PCI QSA — lessons, quizzes, and readiness checklists, authored by practising QSAs.

  • PCIP fundamentals course
  • PCI QSA readiness course
  • QSA-authored lessons
  • Free for every organisation
  • Independent practice material — not official PCI SSC exams
Explore courses
QSA Services
Formal SAQ, AoC & ROC

When you need a signed SAQ, an Attestation of Compliance, or a Report on Compliance, a Haumaru Whānau QSA takes it from here.

  • Formal SAQ + Attestation of Compliance
  • ROC readiness & QSA-assisted assessments
  • Remediation sprints
  • Annual QSA retainer
Explore QSA services
Who it's for

Built for every side of PCI

FAQ

Frequently asked

Is the platform really free?

Yes. Self-assessments and every training module on PCI Assessments Center are free. There is no credit card, trial or paywall. Only formal QSA engagements — signed SAQ, Attestation of Compliance, ROC readiness, remediation, and retainers — are paid, and they are quoted individually.

Do I need to create an account?

Yes. A free account is required so your self-assessments and responses stay tied to your organisation. Each account belongs to a tenant, and row-level security ensures only members of your organisation can read your data.

Which SAQs are supported?

All 10 official PCI DSS v4.0.1 SAQs: A, A-EP, B, B-IP, C, C-VT, D-Merchant, D for Service Providers, P2PE, and SPoC. The guided selector uses the PCI SSC v4.0.1 SAQ Instructions to determine which SAQ applies to your environment, and requires you to attest the official eligibility criteria before you start.

How does PCI Assessments Center choose the right SAQ for me?

A fail-closed decision engine walks you through the PCI SSC v4.0.1 SAQ Instructions and Guidelines. Every question and eligibility check cites its source. If any short-form SAQ criterion is not met, the engine routes you to SAQ D or to a QSA — never a smaller SAQ than your scope allows.

What do I get at the end of a self-assessment?

A structured online result in your workspace: the correct SAQ for your scope, your eligibility attestation, the full selection rationale with citations, and your recorded responses. Results are online-only — there are no downloadable PDFs.

Why can't I download a PDF of my SAQ or AoC?

A downloadable SAQ or Attestation of Compliance implies formal validation. To keep that distinction clear, PCI Assessments Center only shows self-assessment results online. When you need a signed SAQ or AoC, request a formal engagement from QSA Services and a Haumaru Whānau QSA will issue it.

Can PCI Assessments Center replace a formal QSA engagement?

No. Self-assessments here are for readiness, scoping, and internal use. If your acquirer, payment brand, or a contract requires a signed SAQ, Attestation of Compliance, or Report on Compliance, request a formal engagement on the QSA Services page.

When do I need a QSA instead of a self-assessment?

You need a QSA if you are a PCI DSS Level 1 merchant or service provider, if your acquirer or brand mandates a Report on Compliance, if you have been designated for Designated Entities Supplemental Validation, or if you have had a recent card data breach. The guided selector flags these cases and routes you to QSA Services.

How much do formal QSA engagements cost?

Every engagement is scoped and quoted individually — complexity, environment size, evidence maturity, and geography all affect effort. Submit a request from QSA Services; a QSA will schedule a scoping call and follow up with a written quote.

How secure is my data?

Every table uses per-tenant row-level security, so only members of your organisation can read or write your data. Authentication runs on managed cloud infrastructure with sessions scoped per tenant.

Who is behind PCI Assessments Center?

Haumaru Whānau, a certified PCI QSA Company. Self-assessments and training remain free; formal QSA services are delivered by Haumaru Whānau QSAs and quoted separately.

Are the PCIP and QSA exams official PCI SSC exams?

No. The PCIP-style and QSA-style exams on PCI Assessments Center are independent practice and preparation exams created by Haumaru Whānau QSAs. They are not endorsed by, affiliated with, or a substitute for the official PCI Security Standards Council PCIP or QSA qualification exams.