What problem does it solve?
This Skill eliminates inconsistent, incomplete PCI DSS guidance by guiding an end-to-end, evidence-oriented compliance review mapped to PCI DSS v4.0 requirement numbering.
Core Features & Use Cases
- Assessor-verifiable requirement coverage: Reviews all 12 PCI DSS v4.0 requirements with sub-requirements and flags gaps using strict requirement ID validation (no fabricated IDs).
- Practical scope and validation support: Helps determine CHD presence, define CDE boundaries, and evaluate scope reduction strategies, including ROC vs SAQ determination.
- v4.0-specific emphasis: Covers customized approach and targeted risk analysis requirements, plus new v4.0 items (e.g., enhanced MFA and automated log review).
- Compensating controls workflow: Provides a compensating controls evaluation process suitable for ROC documentation.
Quick Start
Use the pci-dss-review skill to produce a structured PCI DSS v4.0 compliance review report for a payment-card environment and focus the scope on the details provided by your arguments.