pci-compliance

Guides PCI DSS v4.0.1 compliance assessments, SAQ selection, and CDE scoping.

Updated Jul 29, 2026
One-click install
npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill pci-compliance-fr-lyo-cys-aura
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: pci-compliance
Source: https://github.com/FR-LYO-CYS-AURA/GRC-Consultant/tree/main/extracted-skills/pci-compliance
Command: npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill pci-compliance-fr-lyo-cys-aura

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Organizations handling payment card data struggle to interpret PCI DSS requirements, determine which Self-Assessment Questionnaire applies, scope their cardholder data environment, and prepare for QSA audits without deep compliance expertise. ## Core Features & Use Cases - Gap Assessments: Produces structured compliance tables across all 12 PCI DSS requirements with status, gaps, evidence needed, and remediation priorities. - SAQ Selection & CDE Scoping: Walks through decision logic to identify the correct SAQ type (A, A-EP, B, B-IP, C, C-VT, P2PE, D) and defines in-scope systems with segmentation recommendations. - v4.0 Migration Guidance: Explains changes from v3.2.1 including expanded MFA, payment page script integrity, phishing protection, and Targeted Risk Analysis requirements. - Use Case: A merchant asks "which SAQ applies to us?" and receives a guided decision-tree analysis based on their payment channels, outsourcing model, and transaction volume, plus the control scope of the recommended SAQ. ## Quick Start Ask the assistant which SAQ applies to your business and describe how you accept card payments.

Frequently Asked Questions about pci-compliance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I determine which PCI DSS SAQ applies to my business?

SAQ selection depends on your payment channels and outsourcing model. Fully outsourced card-not-present merchants use SAQ A, e-commerce merchants controlling redirects use SAQ A-EP, and merchants with internet-connected payment applications use SAQ C or D.

What changed in PCI DSS v4.0 compared to v3.2.1?

PCI DSS v4.0 introduced the Customised Approach with Targeted Risk Analysis, extended MFA to all CDE access, raised minimum password length to 12 characters, and added requirements for phishing protection, payment page script integrity, and automated log review.

How do I scope my cardholder data environment for PCI DSS?

CDE scoping identifies all systems that store, process, or transmit cardholder data plus connected systems that could impact their security. Tokenisation, P2PE, and network segmentation can reduce scope by isolating the CDE from other networks.

When is a ROC required instead of an SAQ?

A Report on Compliance is required for Level 1 merchants processing over 6 million transactions annually and Level 1 service providers over 300,000 transactions. A Qualified Security Assessor must perform the on-site ROC assessment.

Can sensitive authentication data be stored after authorization?

No, sensitive authentication data such as full magnetic stripe data, CVV/CVC codes, and PINs must never be stored after authorization under PCI DSS Requirement 3.3. This is one of the most critical compliance violations assessors check.