PCI DSS: PCI Council Releases SAQs for Version 4.0.1

18. October 2024

This week, the PCI Security Standards Council (PCI SSC) announced that it published the Self-Assessment Questionnaires (SAQs) for PCI DSS v4.0.1. [See the PCI SSC Bulletin]

With the help of SAQs, eligible merchants and service providers can prove their compliance with PCI DSS by means of a self-assessment. The SAQs according to PCI DSS v4.0.1 are valid exclusively from January 1, 2025. Until then, companies can decide for themselves whether they wish to complete their self-assessment with an SAQ according to PCI DSS v4.0 or v4.0.1.  

The update of the SAQs according to PCI DSS v4.0.1 reflects changes to the requirements of PCI DSS v4.0.1 on the one hand and also implements feedback from the industry:

  • Aligning requirement content with PCI DSS v4.0.1
  • Clarifying SAQ Eligibility Criteria in SAQs A, A-EP, and C-VT
  • Adding a requirement to SAQ A and removing a requirement from SAQ C
  • Updating SAQ Completion Guidance in SAQs A and A-EP

The SAQ Instructions and Guidelines document has also been published to align with the SAQ updates for PCI DSS v4.0.1. This document provides information on all PCI DSS v4.0.1 SAQs, including an explanation of the intent of the SAQs, the eligibility criteria for the SAQs, and how to complete an SAQ. The PCI DSS v4.0.1 SAQs and the document “PCI DSS v4.0.1 SAQ Instructions and Guidelines” can be found using the “SAQ” filter in the PCI SSC Document Library on the PCI SSC website.


Do you need help preparing for or implementing PCI DSS v4.0.1 in your company? Get in touch - our experts are happy to help.

Also interesting:

Red Teaming: 5 Questions Every IT Leader Wants Answered

Red Teaming: 5 Questions Every IT Leader Wants Answered

Many companies invest in firewalls, endpoint protection, and awareness training, assuming that this puts them in a strong position. But the reality is different: attackers do not think in terms of tools, but in terms of targets. They combine technical vulnerabilities...

Stronger Together: usd AG Joins Security Network Munich

Stronger Together: usd AG Joins Security Network Munich

We are convinced that real progress in cyber security can only be achieved through open knowledge sharing and collaboration. That is why we contribute our expertise to international committees, promote dialogue within the security community and maintain close...

Categories

Categories