PCI Assessments Center
Loading your workspace…
PCI DSS is a prescriptive payment-security standard mandated by the payment brands for anyone handling card data; SOC 2 is an attestation performed by a CPA firm against the AICPA Trust Services Criteria, with controls the organisation itself defines. They overlap in evidence but not in authority — a SOC 2 report does not demonstrate PCI DSS compliance, and vice versa.
The free SAQ selector walks the official PCI SSC v4.0.1 decision flow, records every answer and re-derives the recommendation server-side with a confidence score.
Written by Haumaru Whānau QSAs. PCI DSS content paraphrased from PCI DSS v4.0.1 and PCI SSC published guidance; payment brand programmes are set by the brands and your acquirer. Independent summary; not endorsed by PCI SSC.