Guides

PCI DSS guides & explainers

Practical, source-backed guides to PCI costs, scoping, SAQ selection, QSA selection, and v4.x readiness -- written for the person who has to get it done.

Fundamentals

PCI SAQ Types Explained: A, A-EP, B, B-IP, C, C-VT, D, and P2PE

Which Self-Assessment Questionnaire applies to your business -- eligibility rules for every SAQ type, in plain English.

September 2026
Fundamentals

ROC vs SAQ: Which PCI Validation Path Do You Actually Need?

When a QSA-led Report on Compliance is mandatory, when self-assessment suffices, and the cost difference between the two.

September 2026
Assessors

How to Choose a PCI QSA Firm: 9 Questions to Ask

The vetting checklist we recommend: listing verification, team, fees, sampling, and the red flags that signal a bad fit.

September 2026
Standards

PCI DSS v4.0.1: What's Actually New (and Now Enforced)

The 47 future-dated requirements that became mandatory March 31, 2025 -- scripts, MFA, tamper detection, and risk analyses explained.

September 2026
Preparation

PCI Scoping: How to Shrink Your Cardholder Data Environment (Legitimately)

Scoping is the biggest cost lever in PCI. How segmentation, P2PE, and outsourcing reduce what the assessor has to test.

September 2026
Testing

PCI Penetration Testing Requirements (11.4): What Assessors Expect

Annual network and application pen testing, segmentation validation, and what the formal report must contain.

September 2026

Reading is step one. Quotes are step two.

When you're ready, get scoped quotes from QSA firms matched to your environment.

Get a free quote