PCI DSS v4.0.1
PCI Security Standards Council
Payment Card Industry Data Security Standard, service provider
Programme in progress — scope design
The first compliance target, covering the Mirage Gateway services and systems that would store, process or transmit payment account data, or affect the security of systems that do. The validation route — SAQ D for Service Providers versus a QSA-led Report on Compliance — is not ours to assume. It depends on the service model, volumes and what the compliance-accepting entity requires, and it is confirmed with a Qualified Security Assessor before launch, not decided in advance.
What it requires
- QSA scoping engagement
- Cardholder data flow diagrams
- Formal CDE scope statement and system inventory
- Gap assessment and remediation
- Penetration testing and, where applicable, ASV scanning
- Service Provider Attestation of Compliance naming the assessed services