Frequently Asked Question

Can I combine sections from different versions of the PA-DSS?
No. When validating payment application compliance through a Report on Validation (ROV) you may not 'combine' requirements from multiple versions of the standard – your assessment must be to one version in its entirety. Please also note that PA-DSS validations must follow the instructions in the corresponding Program Guide. For example, applications validated under PA-DSS version 2 must use version 2.x of the PA-DSS Program Guide, and version 3.x validations must use PA-DSS Program Guide version 3.x.
June 2015
Article Number: 1271
Related
-
How do PCI standards apply to organizations that develop software that runs on a consumer’s device (for example, a smartphone, tablet, or laptop) and is used to accept payment card data?
-
Which version of PCI DSS should an entity use?
-
Does a P2PE validated application also need to be validated against PA-DSS?