What problem does it solve? Organizations handling payment card data struggle to interpret PCI DSS requirements, determine which Self-Assessment Questionnaire applies, scope their cardholder data environment, and prepare for QSA audits without deep compliance expertise. ## Core Features & Use Cases - Gap Assessments: Produces structured compliance tables across all 12 PCI DSS requirements with status, gaps, evidence needed, and remediation priorities. - SAQ Selection & CDE Scoping: Walks through decision logic to identify the correct SAQ type (A, A-EP, B, B-IP, C, C-VT, P2PE, D) and defines in-scope systems with segmentation recommendations. - v4.0 Migration Guidance: Explains changes from v3.2.1 including expanded MFA, payment page script integrity, phishing protection, and Targeted Risk Analysis requirements. - Use Case: A merchant asks "which SAQ applies to us?" and receives a guided decision-tree analysis based on their payment channels, outsourcing model, and transaction volume, plus the control scope of the recommended SAQ. ## Quick Start Ask the assistant which SAQ applies to your business and describe how you accept card payments.