PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Kaitiaki, AI PCI ISA

Meet Kaitiaki — your Internal Security Assessor

Grounded in the PCI SSC library for PCI DSS v4.0.1 — ask about scoping, SAQ eligibility, evidence or your own gaps.

Your PCI assessment workspace.

Determine the right SAQ, complete it online against PCI DSS v4.0.1, and prepare your teams for PCIP and QSA — in one guided workspace.

10 official SAQs · PCI SSC-aligned · Free forever
PCI Assessments
Content Card · Platinum
0
Questions
189 domains
0
SAQs
v4.0.1 aligned
0
Controls
across 11 SAQs
0
Courses
lessons
0
Flashcards
terminology
0
Exam Tracks
AWARENESS · DEVELOPERS · +7
Valid Thru
PCI DSS · v4.0.1
Issued By
Haumaru Whānau · QSA
10 official SAQs
All PCI DSS v4.0.1 SAQs supported verbatim.
Verified email signup
Email code verification with disposable-domain blocking.
RLS-protected data
Every assessment isolated by tenant and role.
QSA-authored content
Built by Haumaru Whānau PCI QSA professionals.
Independent practice
Preparation for official PCIP and QSA exams.
Free self-assessment
Determine, attest and complete at no cost.
Threat watch

Why compliance posture matters

Live payment-security signals curated from public industry sources. Refreshed every few hours — nothing here is a PCI Assessments Center incident.

Threattoday

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. The vast majority…

The Hacker NewsRead
Breachtoday

⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper…

The Hacker NewsRead
Threattoday

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups. According to findings from Gen Digital, WordlistLo…

The Hacker NewsRead
Threattoday

Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt

If your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time spent on routine work. The harder part is what comes after. AI can also introduce open-source packages a…

The Hacker NewsRead
Regulationtoday

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcin…

The Hacker NewsRead
Threattoday

Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor

Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent. The campaign, codenamed Operation QUICSILVER, has been found to t…

The Hacker NewsRead
Threattoday

The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk

Big security risks come in small packages. While enterprise security teams focus on policing the proliferation of employees using ChatGPT and Claude for quick drafting tasks, a more urgent threat is posed by a handful of AI super-adopters…

The Hacker NewsRead
Regulation2 days ago

TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit

The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing the company of violating child privacy laws in the country. As part of the settlement, the social…

The Hacker NewsRead
Regulation3 days ago

Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0

Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review. Four of the security vulnerabilities affect Crosswork Data Gateway, C…

The Hacker NewsRead
Threat3 days ago

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code injection that allows…

The Hacker NewsRead
Regulation3 days ago

Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution

Update: The story was updated after publication to note that the vulnerability has not been exploited. Although the security bulletin originally marked the "Exploited" field under the Exploitability Assessment table as "Yes," on August 21,…

The Hacker NewsRead
Threat3 days ago

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 thr…

The Hacker NewsRead
Threat3 days ago

Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet

Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said the end goal of the m…

The Hacker NewsRead
Threat3 days ago

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2…

The Hacker NewsRead
Threat3 days ago

Wazuh and AI For Enhanced SOC Workflows

Artificial Intelligence (AI) has become one of this decade's defining technologies. From healthcare and finance to manufacturing and education, organizations increasingly rely on AI to automate repetitive tasks, uncover patterns hidden wit…

The Hacker NewsRead
Threat4 days ago

Why "Shady AI" is Security's Next Big Governance Problem

In March 2026, an internal AI agent at Meta triggered a “Sev 1” incident after sensitive company and user data was exposed to employees who weren’t authorized to access it. The incident began when a Meta employee posted a technical questio…

The Hacker NewsRead
Threat4 days ago

CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP/3 traffic into HTTP/1.1 requests to the websites they front, amplifying a low-b…

The Hacker NewsRead
Threat4 days ago

Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices

A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions, global fintech and cryptocurre…

The Hacker NewsRead
Fraud4 days ago

ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud

Cybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with "significant enhancements," including a set of 167 remote commands and expands its targeting footprint globally. Zimperium zLabs, i…

The Hacker NewsRead
Threat4 days ago

40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets

A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products. According to the Socket Threat Research team, the extensions are part o…

The Hacker NewsRead
Regulation4 days ago

NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands

Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit, that allow an unauthenticated attacker to issue arbitrary commands to the so…

The Hacker NewsRead
Regulation4 days ago

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS sc…

The Hacker NewsRead
Regulation4 days ago

Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability. According to the cloud computing and virtualization tec…

The Hacker NewsRead
Threat4 days ago

Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska). The vulnerability in question is CVE-2026-73570 (CVSS…

The Hacker NewsRead
The path

From "which SAQ?" to "we're ready"

Every step is grounded in the PCI SSC v4.0.1 SAQ Instructions and Guidelines. No guesswork, no smaller SAQ than your scope allows.

1
Determine

Find the right assessment for your organisation.

2
Attest

Confirm official SAQ eligibility criteria.

3
Complete

Answer the correct SAQ with QSA guidance.

4
Plan with your AI PCI ISA

Turn every gap into a remediation plan and a scored risk register — free.

5
Validate

Review results online or engage a QSA to sign.

6
Train

Prepare your team for PCI certification exams with QSA-authored practice materials.

PCI DSS v4.0.1

What changed — and what you must plan for

Selected requirements the platform highlights during your assessment. Click through the deck or wait for it to rotate.

In effectReq 8.4

MFA for all access into the CDE

Multi-factor authentication is now required for all access into the Cardholder Data Environment, not just administrative access.

Offerings

Three doors, one path

Start free with a self-assessment or training. Bring in a QSA when the payment brand or acquirer asks for a signature.

Assessment
Self-Assessment

Structured PCI DSS eligibility check covering all 10 official PCI DSS v4.0.1 SAQs. Results are available online in your workspace.

  • Fail-closed eligibility mirrors PCI SSC decision tree
  • Verbatim controls with expected testing
  • Online results — no downloads
  • Per-tenant secure storage
Create a free account
Courses
PCIP & QSA readiness

Course tracks for PCIP and PCI QSA — lessons, quizzes, and readiness checklists, authored by practising QSAs.

  • PCIP fundamentals course
  • PCI QSA readiness course
  • QSA-authored lessons
  • Free for every organisation
  • Independent practice material — not official PCI SSC exams
Explore courses
QSA Services
Formal SAQ, AoC & ROC

When you need a signed SAQ, an Attestation of Compliance, or a Report on Compliance, a Haumaru Whānau QSA takes it from here.

  • Formal SAQ + Attestation of Compliance
  • ROC readiness & QSA-assisted assessments
  • Remediation sprints
  • Annual QSA retainer
Explore QSA services
Who it's for

Built for every side of PCI

FAQ

Frequently asked

Is the platform really free?

Yes. Self-assessments and every training module on PCI Assessments Center are free. There is no credit card, trial or paywall. Only formal QSA engagements — signed SAQ, Attestation of Compliance, ROC readiness, remediation, and retainers — are paid, and they are quoted individually.

Do I need to create an account?

Yes. A free account is required so your self-assessments and responses stay tied to your organisation. Each account belongs to a tenant, and row-level security ensures only members of your organisation can read your data.

Which SAQs are supported?

All 10 official PCI DSS v4.0.1 SAQs: A, A-EP, B, B-IP, C, C-VT, D-Merchant, D for Service Providers, P2PE, and SPoC. The guided selector uses the PCI SSC v4.0.1 SAQ Instructions to determine which SAQ applies to your environment, and requires you to attest the official eligibility criteria before you start.

How does PCI Assessments Center choose the right SAQ for me?

A fail-closed decision engine walks you through the PCI SSC v4.0.1 SAQ Instructions and Guidelines. Every question and eligibility check cites its source. If any short-form SAQ criterion is not met, the engine routes you to SAQ D or to a QSA — never a smaller SAQ than your scope allows.

What do I get at the end of a self-assessment?

A structured online result in your workspace: the correct SAQ for your scope, your eligibility attestation, the full selection rationale with citations, and your recorded responses. Results are online-only — there are no downloadable PDFs.

Why can't I download a PDF of my SAQ or AoC?

A downloadable SAQ or Attestation of Compliance implies formal validation. To keep that distinction clear, PCI Assessments Center only shows self-assessment results online. When you need a signed SAQ or AoC, request a formal engagement from QSA Services and a Haumaru Whānau QSA will issue it.

Can PCI Assessments Center replace a formal QSA engagement?

No. Self-assessments here are for readiness, scoping, and internal use. If your acquirer, payment brand, or a contract requires a signed SAQ, Attestation of Compliance, or Report on Compliance, request a formal engagement on the QSA Services page.

When do I need a QSA instead of a self-assessment?

You need a QSA if you are a PCI DSS Level 1 merchant or service provider, if your acquirer or brand mandates a Report on Compliance, if you have been designated for Designated Entities Supplemental Validation, or if you have had a recent card data breach. The guided selector flags these cases and routes you to QSA Services.

How much do formal QSA engagements cost?

Every engagement is scoped and quoted individually — complexity, environment size, evidence maturity, and geography all affect effort. Submit a request from QSA Services; a QSA will schedule a scoping call and follow up with a written quote.

How secure is my data?

Every table uses per-tenant row-level security, so only members of your organisation can read or write your data. Authentication runs on managed cloud infrastructure with sessions scoped per tenant.

Who is behind PCI Assessments Center?

Haumaru Whānau, a certified PCI QSA Company. Self-assessments and training remain free; formal QSA services are delivered by Haumaru Whānau QSAs and quoted separately.

Are the PCIP and QSA exams official PCI SSC exams?

No. The PCIP-style and QSA-style exams on PCI Assessments Center are independent practice and preparation exams created by Haumaru Whānau QSAs. They are not endorsed by, affiliated with, or a substitute for the official PCI Security Standards Council PCIP or QSA qualification exams.