PCI Assessments Center
Loading your workspace…
PCI DSS compliance follows the same order every time: confirm how you accept payments, define scope, establish whether you may self-assess, select the correct SAQ or engage a QSA, implement and evidence each applicable requirement, then validate with your acquirer. Everything else is detail hanging off those six steps.
Scope follows account data. Before anything else, list every channel and every system that touches it.
For each applicable requirement, evidence is what the assessment turns on — not intent.
The free SAQ selector walks the official PCI SSC v4.0.1 decision flow, records every answer and re-derives the recommendation server-side with a confidence score.
Written by Haumaru Whānau QSAs. PCI DSS content paraphrased from PCI DSS v4.0.1 and PCI SSC published guidance; payment brand programmes are set by the brands and your acquirer. Independent summary; not endorsed by PCI SSC.