Frequently Asked Questions
 
															Featured FAQ Articles
Featured
- 
									
										How does an e-commerce merchant meet the SAQ A eligibility criteria for scripts?									
									
 
- 
									
										Do PCI DSS requirements for keyed cryptographic hashing apply to previously hashed PANs?									
									
 
- 
									
										Is the PCI DSS Attestation of Compliance intended to be shared?									
									
 
- 
									
										How does an entity report the results of a PCI DSS assessment for new requirements that are noted in PCI DSS as best practices until a future date?									
									
 
- 
									
										Where do I direct questions about complying with PCI standards?									
									
 
- 
									
										Can SAQ eligibility criteria be used as a guide for determining applicability of PCI DSS requirements for merchant assessments documented in a Report on Compliance?									
									
 
Most Popular
- 
									
										Can a partial PCI DSS assessment be documented in a Report on Compliance (ROC)?									
									
 
- 
									
										Is phishing-resistant authentication alone acceptable as multi-factor authentication for PCI DSS Requirements 8.4.1 and 8.4.3?									
									
 
- 
									
										Can sensitive information be redacted from the PCI DSS Attestation of Compliance before it is shared with other entities?									
									
 
- 
									
										What are the expectations for entities when assigning risk rankings to vulnerabilities and resolving or addressing those vulnerabilities?									
									
 
- 
									
										Can service providers use eligibility criteria from a merchant Self-Assessment Questionnaire (SAQ) to determine applicable PCI DSS requirements for the service provider’s assessment?									
									
 
Most Recently Updated
- 
									
										Can unencrypted PANs be sent over e-mail, instant messaging, SMS, or chat?									
									
 
- 
									
										Are entities allowed to request that cardholder data be provided over end-user messaging technologies?									
									
 
- 
									
										Does PCI DSS allow faxing of payment card numbers?									
									
 
- 
									
										What is the maximum period of time that cardholder data can be stored?									
									
 
- 
									
										To which devices does PCI DSS Requirement 10.4.2 apply?									
									
 
Featured FAQ Articles
Featured
- 
									
										Are Approved Scanning Vendors and Qualified Security Assessors considered third-party service providers for PCI DSS Requirements 12.8 and 12.9?									
									
 
- 
									
										What are the expectations for entities when assigning risk rankings to vulnerabilities and resolving or addressing those vulnerabilities?									
									
 
- 
									
										Is phishing-resistant authentication alone acceptable as multi-factor authentication for PCI DSS Requirements 8.4.1 and 8.4.3?									
									
 
- 
									
										Are passkeys synced across devices, implemented according to the FIDO2 requirements, acceptable for use as phishing-resistant authentication to meet PCI DSS Requirement 8.4.2?									
									
 
- 
									
										How should PCI DSS v4.x requirements noted as superseded by another requirement be reported after 31 March 2025?									
									
 
Most Popular
- 
									
										Are Approved Scanning Vendors and Qualified Security Assessors considered third-party service providers for PCI DSS Requirements 12.8 and 12.9?									
									
 
- 
									
										What are the expectations for entities when assigning risk rankings to vulnerabilities and resolving or addressing those vulnerabilities?									
									
 
- 
									
										Is phishing-resistant authentication alone acceptable as multi-factor authentication for PCI DSS Requirements 8.4.1 and 8.4.3?									
									
 
- 
									
										Are passkeys synced across devices, implemented according to the FIDO2 requirements, acceptable for use as phishing-resistant authentication to meet PCI DSS Requirement 8.4.2?									
									
 
- 
									
										How should PCI DSS v4.x requirements noted as superseded by another requirement be reported after 31 March 2025?