PCI Assessments Center
Loading your workspace…
Requirement 12.10.1 requires an incident response plan that exists and is ready to be activated the moment a security incident is suspected or confirmed. It must set out roles and communication paths — including notification of payment brands and acquirers — containment and mitigation procedures, business recovery, data backup, legal reporting analysis and coverage of all critical system components.Timing: Applies in PCI DSS v4.0.1 and is assessed at every annual assessment.
Paraphrased from PCI DSS v4.0.1. Read the standard itself for the authoritative wording and testing procedures.
Which requirements you must answer depends on the SAQ that applies to your environment. The free SAQ selector walks the official PCI SSC decision flow, records every answer and re-derives the recommendation server-side with a confidence score.
Paraphrased from PCI DSS v4.0.1 (PCI Security Standards Council). Independent summary; not endorsed by PCI SSC. Refer to the PCI SSC Document Library for the authoritative standard.