Skip to content
pcipentest

A sourced reference on PCI DSS testing: what is confirmed, what is behind a licence gate, and who actually decides what you validate.

Run the scope finder→
  • 01What we can prove
  • 02Scan or test
  • 03Scope finder
  • 04Who validates
  • 05PCI, DORA, NIS2
  • 06Guides
Home

About pcipentest.com

Updated 13 September 2026

pcipentest.com exists because the public writing about PCI DSS testing has a sourcing problem. The standard is free but gated, so most pages quote clause numbers copied from other pages, and the errors propagate. This site takes the opposite approach: it prints what it read, links to it, and marks the rest.

Publisher

The site is published by SEQ SIA (registration number 40203410806), Lastādijas iela 12 k-3, Riga, LV-1050, Latvia, trading as OffSeq, a penetration testing and security consulting company. Contact: support@offseq.com.

What we are not

OffSeq is not a Qualified Security Assessor company and not an Approved Scanning Vendor. It cannot perform your PCI DSS assessment, sign a Report on Compliance or an Attestation of Compliance, or produce an ASV scan report. This site is not affiliated with, endorsed by or accredited by the PCI Security Standards Council or any payment brand.

How the guidance is sourced

  • Statements about PCI DSS are sourced to a page on pcisecuritystandards.org or blog.pcisecuritystandards.org that we actually opened, and quoted where the wording is the point.
  • We could not read PCI DSS itself. The Council distributes it through a document library behind a click-through licence agreement; an automated request for the PDF returns a page reading "Agreement is required to access this document", and every archived copy we checked is a capture of that gate. We did not work around it.
  • Because of that, this site prints a requirement number only where a Council page states it. Penetration testing clause numbers in PCI DSS v4.x are not among them, and we say so on the home page rather than repeating a number we found on somebody else's website.
  • Statements about merchant and service provider levels are sourced to each card brand's own programme page, brand by brand, because their thresholds differ.
  • Statements about EU law cite the instrument on EUR-Lex, article by article.
  • The "Updated" date moves only when the text changes. An automated content-hash ledger reverts unearned bumps.

Where a claim is common online and we could not source it, it is absent. That is a deliberate cost: some questions readers arrive with are not answered here, and an unanswered question is better than a confidently wrong answer about a compliance obligation.

Authorship

SEQ SIA (OffSeq) is responsible for publishing, maintaining and updating this site. Articles carry team attribution rather than individual bylines. Every source is listed so a reader can check the basis for a statement instead of taking it on trust.

Commercial interest

We sell penetration testing, including the testing this site describes. That is a direct interest in you concluding that you need it, and it should colour how you read every recommendation here.

  • Links to OffSeq are our own service links, not a market comparison. We do not rank or score competing providers.
  • No QSA company, scanning vendor, compliance platform or card brand pays for a mention. There is no advertising and no affiliate revenue.
  • We do not receive a commission for referring you to a QSA or an ASV, and we will tell you when the thing you need is one of those rather than us.
  • Where the honest answer is that your quarterly scan is sufficient and a penetration test can wait a quarter, the site says so. That answer costs us work and it is still the right one.

Not advice

Nothing here is legal advice or an assessment. Scope, applicability, level and evidence sufficiency are decisions for you, your acquirer and your Qualified Security Assessor. Where this site and your assessor disagree, your assessor is the one holding the standard.

Corrections

Send corrections to support@offseq.com, ideally with the source. If you can show us a Council document that settles one of the masked lines on the home page, we will unmask it and credit the correction.

pcipentest

pcipentest.com is a free reference on testing under the PCI Data Security Standard: which tests the standard and the card brands actually ask for, how an ASV scan differs from a penetration test, when segmentation testing applies, and which of those statements can be sourced to a document anyone can open.

••••••••••••4242

Guides

  • ASV scan or pentest?
  • Segmentation testing
  • Levels and validation
  • PCI, DORA and NIS2

Professional help

  • Penetration testing and security audits
  • Compliance readiness
  • Define a testing scope
  • Talk to OffSeq

Information

  • About
  • Privacy policy
  • Cookies and browser storage

pcipentest.com is a free reference maintained by the OffSeq security team. OffSeq is not a Qualified Security Assessor company and not an Approved Scanning Vendor. It cannot sign a Report on Compliance, an Attestation of Compliance or an ASV scan report.

PCI DSS, PCI, SAQ, ROC, AOC, QSA and ASV are terms of the PCI Security Standards Council, LLC. Visa, Mastercard, American Express, Discover and JCB are trademarks of their respective owners. This site is independent and is not affiliated with, endorsed by or accredited by any of them.

Operated by SEQ SIA · Riga, Latvia