QSA · PCI Qualified Security Assessors
PCI-DSS Compliance Consulting
If your company takes credit cards or debit cards as forms of payment, your company is required to adhere to the Payment Card Industry Data Security Standard (PCI-DSS). This is true even if you process only one transaction the entire year! Depending on your business, your reporting and compliance requirements may be different. That is where we come in as PCI-SSC Certified Qualified Security Assessors (QSAs), to help you navigate the intricacies of PCI-DSS and make compliance easy!
Let’s get your business PCI-DSS Compliant - without the headache or high costs.
QSA
Listed on the PCI SSC website
v4.0.1
Current PCI DSS version
10
SAQ types under v4.0.1
ROC
Report on Compliance and AOC
The standard
What is PCI-DSS?
PCI DSS stands for Payment Card Industry Data Security Standard. It is a set of security standards designed to ensure that all companies that accept, process, store or transmit credit card information maintain a secure environment. The standards were created by the major credit card companies, including Visa, Mastercard, American Express, Discover and JCB, and are intended to protect the sensitive information of credit cardholders.
The PCI DSS standards apply to any organization, regardless of size, that accepts credit cards as payment. Compliance is mandatory for all organizations that store, process, or transmit cardholder data. The standard consists of 12 requirements, which are grouped into six goals: build and maintain a secure network and systems, protect account data, maintain a vulnerability management program, implement strong access control measures, regularly monitor and test networks, and maintain an information security policy. The current version is PCI DSS v4.0.1, and its future-dated requirements became mandatory on March 31, 2025. Failure to comply with PCI DSS standards can result in significant fines and legal liability, as well as damage to a company's reputation.
Requirements
What are the 12 PCI-DSS Requirements?
These are the 12 requirements as named in PCI DSS v4.0.1.
01
Install and Maintain Network Security Controls
Network security controls, such as firewalls, must be defined, implemented and maintained to control traffic into and out of the cardholder data environment.
02
Apply Secure Configurations to All System Components
Vendor default passwords and settings must be changed, and every system component must be configured to a secure, documented standard.
03
Protect Stored Account Data
Keep account data storage to a minimum, never store sensitive authentication data after authorization, and render stored PANs unreadable with strong cryptography.
04
Protect Cardholder Data with Strong Cryptography During Transmission Over Open, Public Networks
Use strong cryptography and trusted certificates to protect PANs whenever they are sent over open, public networks.
05
Protect All Systems and Networks from Malicious Software
Deploy and maintain anti-malware protection on systems at risk, and protect personnel against phishing attacks.
06
Develop and Maintain Secure Systems and Software
Build and maintain systems and software securely, protect public-facing web applications, and patch critical vulnerabilities promptly.
07
Restrict Access to System Components and Cardholder Data by Business Need to Know
Grant access on a least-privilege, need-to-know basis, and review user accounts and access privileges regularly.
08
Identify Users and Authenticate Access to System Components
Give every user a unique ID, use strong authentication, and require multi-factor authentication for access into the cardholder data environment.
09
Restrict Physical Access to Cardholder Data
Control physical access to facilities, systems and media with cardholder data, and protect payment terminals from tampering.
10
Log and Monitor All Access to System Components and Cardholder Data
Log all access to system components and cardholder data, review logs to spot anomalies, and protect and retain audit trails.
11
Test Security of Systems and Networks Regularly
Test security regularly with vulnerability scans, penetration tests, intrusion detection, and change and tamper detection, including on payment pages.
12
Support Information Security with Organizational Policies and Programs
Maintain an information security policy and program, including targeted risk analyses, security awareness training, third-party service provider management and incident response.
Questionnaires & reports
SAQs, ROC and AOC
What are Self Assessment Questionnaires (SAQs) and Which Do I need to Complete?
SAQ, or Self-Assessment Questionnaire, is a tool developed by the Payment Card Industry Security Standards Council (PCI SSC) to help merchants and service providers determine their level of compliance with the Payment Card Industry Data Security Standard (PCI DSS). There are several types of SAQs, each designed for a specific type of business and payment processing scenario. For example, SAQ A is designed for e-commerce merchants who outsource all their payment processing to a third-party provider, while SAQ D is for merchants who store cardholder data on their own systems.
Under PCI DSS v4.0.1 there are 10 types of SAQs:
1. SAQ A: Card-not-present merchants (e-commerce or mail/telephone order) that fully outsource all account data functions to PCI DSS compliant third parties.
2. SAQ A-EP: E-commerce merchants that partially outsource payment processing, where the merchant’s website doesn’t receive account data but can affect the security of the payment transaction.
3. SAQ B: Merchants that use only imprint machines or standalone, dial-out payment terminals, with no electronic storage of account data.
4. SAQ B-IP: Merchants that use only standalone, PCI-approved payment terminals with an IP connection to the payment processor, with no electronic storage of account data.
5. SAQ C-VT: Merchants that manually enter one transaction at a time into an internet-based virtual terminal hosted by a PCI DSS validated third party, with no electronic storage of account data.
6. SAQ C: Merchants with payment application systems connected to the internet, with no electronic storage of account data.
7. SAQ P2PE: Merchants that use only payment terminals managed through a PCI-listed, validated point-to-point encryption (P2PE) solution.
8. SAQ SPoC: Merchants that accept payments on a commercial off-the-shelf phone or tablet with a secure card reader that is part of a PCI-listed SPoC solution.
9. SAQ D for Merchants: All merchants that aren’t eligible for any other SAQ type.
10. SAQ D for Service Providers: Service providers that a payment brand has defined as eligible to complete an SAQ.
At Anthony Timbers LLC, we can help businesses determine which SAQ they need to complete and guide them through the process to ensure they achieve PCI-DSS compliance. While completing the SAQ can be done internally, it's highly recommended that a QSA be engaged to assist with the process to ensure an accurate completion of the assessment. Engaging a QSA can also help identify gaps in an organization's security posture and recommend steps for remediation, ultimately leading to a more secure payment environment.
What is ROC and AOC and How Do I Complete Them?
ROC stands for Report on Compliance, and AOC stands for Attestation of Compliance. These are two critical documents in the PCI-DSS compliance process that help organizations prove their compliance to their acquiring banks or payment brands. The ROC is a comprehensive report that details an organization's adherence to all PCI-DSS requirements, while the AOC is a shorter document that provides an executive summary of the ROC's findings.
To ensure the accuracy and completeness of the ROC and AOC, a Qualified Security Assessor (QSA) must perform an independent assessment of an organization's PCI-DSS compliance. A QSA is a professional who has been certified by the PCI Security Standards Council to assess an organization's compliance with the PCI-DSS requirements. When your acquirer or the payment brands require a ROC, a QSA like Anthony Timbers LLC performs the assessment and signs off on the ROC and its AOC.
How we help
How Anthony Timbers LLC Can Help with PCI-DSS Compliance
If you're looking to protect your customers' sensitive payment card data, you need to comply with the Payment Card Industry Data Security Standards (PCI-DSS). At Anthony Timbers LLC, we understand that achieving PCI-DSS compliance can be a daunting task, which is why we offer expert guidance and support to help you navigate the complex requirements. Our team of experienced professionals will work with you to assess your current security posture and identify any areas of weakness that need to be addressed to meet the PCI-DSS standards. We'll then develop a comprehensive strategy to help you achieve compliance and maintain it over time. From securing your networks and systems to training your employees on best practices, we provide a range of services to help you meet all 12 PCI-DSS requirements. With our help, you can protect your customers' payment card data, avoid costly fines, and safeguard your business's reputation. Contact us today to learn more about how we can help your business achieve PCI-DSS compliance.
Ready to start your journey into PCI-DSS?
How can we help?
Whether you need immediate help with an IT issue or want to discuss your long-term IT strategy, our team is here to help.
Call us at +1 804-596-0596 or complete the form below and we'll help in any way we can.
One firm. Four authorizations.
MSSP
CMMC Level 2 Certified MSSP
24/7 security monitoring and incident response for small to mid-sized businesses and DoD contractors.
C3PAO
Authorized CMMC C3PAO
Official CMMC Level 2 certification assessments, authorized by the Cyber AB.
3PAO
FedRAMP 3PAO
FedRAMP Rev5 and 20x assessments as a FedRAMP Recognized independent assessor, accredited to ISO/IEC 17020.
QSA
PCI Qualified Security Assessors
PCI DSS assessments and consulting, listed as QSAs on the PCI SSC website.
Team credentials




ISO/IEC 17020 accredited
