What problem does it solve? Organizations that store, process, or transmit cardholder data must comply with PCI DSS v4.0.1, but determining scope, choosing the correct Self-Assessment Questionnaire, and mapping the 12 requirements to actual controls is complex and error-prone. ## Core Features & Use Cases - SAQ Selection Guidance: Decision logic for SAQ-A, SAQ-A-EP, and SAQ-B-IP based on how card data is accepted and processed. - CDE Scoping and Segmentation: Defines the cardholder data environment, connected systems, and scope reduction via tokenization and P2PE. - v4.0 Change Coverage: Explains new requirements like payment page script integrity (6.4.3), tamper detection (11.6.1), expanded MFA, and the customized approach. - Use Case: An e-commerce merchant embedding a JavaScript payment form asks which SAQ applies; the skill identifies SAQ-A-EP and lists the required WAF, ASV scans, penetration tests, and script integrity controls. ## Quick Start Ask the assistant to help determine which PCI DSS SAQ applies to your payment setup and what controls you need to implement.