Everything at length, with the sources attached
Four guides on testing under PCI DSS. Every quotation carries the document it came from, and every gap in the sourcing is marked rather than filled in.
The full set
-
ASV scan or penetration test? Which one PCI actually asks for
They are bought from different suppliers, they answer different questions, and only one of them has a published pass mark. Here is each one, sourced.
Read -
Segmentation testing: proving the boundary you claimed
Segmentation is the only lever that makes a PCI programme smaller. It also creates the one claim you have to demonstrate rather than assert.
Read -
Merchant levels and validation: who decides what you file
PCI SSC writes the standard and enforces nothing. Five brands set five sets of thresholds, and your acquirer administers all of them at once.
Read -
PCI DSS, DORA and NIS2: three testing regimes, one payment firm
A European payment institution can be inside all three at once. They have different scopes, different testers and different enforcers, and one test does not discharge another.
Read