PCI Assessments Center
Loading your workspace…
PCI DSS is enforced contractually, not by statute. Non-compliance is handled by your acquirer under its agreement with the payment brands, and consequences escalate from remediation deadlines and monthly non-compliance charges through to higher transaction costs and, in severe or repeated cases, loss of the ability to accept cards. A breach adds forensic investigation and liability for fraud and reissuance costs.
The free SAQ selector walks the official PCI SSC v4.0.1 decision flow, records every answer and re-derives the recommendation server-side with a confidence score.
Written by Haumaru Whānau QSAs. PCI DSS content paraphrased from PCI DSS v4.0.1 and PCI SSC published guidance; payment brand programmes are set by the brands and your acquirer. Independent summary; not endorsed by PCI SSC.