About pcipentest.com
pcipentest.com exists because the public writing about PCI DSS testing has a sourcing problem. The standard is free but gated, so most pages quote clause numbers copied from other pages, and the errors propagate. This site takes the opposite approach: it prints what it read, links to it, and marks the rest.
Publisher
The site is published by SEQ SIA (registration number 40203410806), Lastādijas iela 12 k-3, Riga, LV-1050, Latvia, trading as OffSeq, a penetration testing and security consulting company. Contact: support@offseq.com.
How the guidance is sourced
- Statements about PCI DSS are sourced to a page on pcisecuritystandards.org or blog.pcisecuritystandards.org that we actually opened, and quoted where the wording is the point.
- We could not read PCI DSS itself. The Council distributes it through a document library behind a click-through licence agreement; an automated request for the PDF returns a page reading "Agreement is required to access this document", and every archived copy we checked is a capture of that gate. We did not work around it.
- Because of that, this site prints a requirement number only where a Council page states it. Penetration testing clause numbers in PCI DSS v4.x are not among them, and we say so on the home page rather than repeating a number we found on somebody else's website.
- Statements about merchant and service provider levels are sourced to each card brand's own programme page, brand by brand, because their thresholds differ.
- Statements about EU law cite the instrument on EUR-Lex, article by article.
- The "Updated" date moves only when the text changes. An automated content-hash ledger reverts unearned bumps.
Where a claim is common online and we could not source it, it is absent. That is a deliberate cost: some questions readers arrive with are not answered here, and an unanswered question is better than a confidently wrong answer about a compliance obligation.
Authorship
SEQ SIA (OffSeq) is responsible for publishing, maintaining and updating this site. Articles carry team attribution rather than individual bylines. Every source is listed so a reader can check the basis for a statement instead of taking it on trust.
Commercial interest
We sell penetration testing, including the testing this site describes. That is a direct interest in you concluding that you need it, and it should colour how you read every recommendation here.
- Links to OffSeq are our own service links, not a market comparison. We do not rank or score competing providers.
- No QSA company, scanning vendor, compliance platform or card brand pays for a mention. There is no advertising and no affiliate revenue.
- We do not receive a commission for referring you to a QSA or an ASV, and we will tell you when the thing you need is one of those rather than us.
- Where the honest answer is that your quarterly scan is sufficient and a penetration test can wait a quarter, the site says so. That answer costs us work and it is still the right one.
Not advice
Nothing here is legal advice or an assessment. Scope, applicability, level and evidence sufficiency are decisions for you, your acquirer and your Qualified Security Assessor. Where this site and your assessor disagree, your assessor is the one holding the standard.
Corrections
Send corrections to support@offseq.com, ideally with the source. If you can show us a Council document that settles one of the masked lines on the home page, we will unmask it and credit the correction.