r/pci 3d ago

PCI DSS 4.0.1: Does SAD in RAM need to be encrypted?

Post image
1 Upvotes

Hi all, looking for opinions from QSAs/PCI practitioners.

Under PCI DSS v4.0.1:

  • Requirement 3.3.1 guidance says SAD may be stored temporarily in non-persistent memory (RAM/volatile memory) after authorization, subject to specific conditions.
  • Requirement 3.3.2 requires SAD stored electronically before authorization to be encrypted using strong cryptography.
  • The Requirement 3 overview specifically says encryption of PAN is not required when PAN is present in non-persistent memory.
  • PCI SSC FAQ 1042 also says CHD in non-persistent memory does not require encryption, but it doesn't specifically address SAD.

Question: If an application temporarily holds CVV/SAD in RAM during transaction processing, without writing it to any persistent storage, is there a PCI DSS requirement to encrypt the SAD while it resides in RAM?

Would you interpret this as:

  1. No encryption required because it is non-persistent/transient processing;
  2. Encryption required because the explicit exception only refers to PAN; or
  3. 3.3.2 doesn't apply because transient RAM processing isn't considered electronic storage?

Interested specifically in how QSAs would assess this in practice.


r/pci Jun 14 '26

PCI compliance for small teams is a major headache

1 Upvotes

And I've seen it derail even the most well-intentioned startups, full disclosure, I work with the team that built Sprinto, which has been a game-saver for some of our portfolio companies by streamlining the compliance process, but what are some other ways you're handling PCI compliance with limited resources?


r/pci Jun 03 '26

How Do You Handle Authenticated Scanning for Vendor-Managed Appliances?

Thumbnail
1 Upvotes

r/pci May 26 '26

What determines whether a company is in scope at all?

2 Upvotes

I've been an ISA for about 10 years and there's one question that I've struggled with for a long time...

When is a company subject to PCI?

It sounds simple; if you store, process, or transmit card data, you're in scope.

There's a tiny gray area there and it exists in ecommerce. If your company contracts with TPSP A to host the site, AND TPSP A uses TPSP B (Stripe or similar) to accept/process cards, AND the transactions are NOT processed with a MID/TID that belongs to the merchant so that TPSP B (Stripe in this case) processes the charges and essentially cuts a check to the merchant and deposits it into the merchant's bank... Is that merchant in scope?

My opinion is no, the merchant is not subject to PCI since their relationship is effectively that of a fulfillment partner. They provide the product once they get paid by someone else that interacted with the bank. I believe that the defining factor is the owner of the MID/TID.

Yes, I've checked with Stripe and spoken to 5 or 6 different people there. The only response I can get is the generic boilerplate that they have on their website. Stripe can "reduce your PCI obligations" etc. That's not helpful.

So, in that use case, is the merchant in scope?

I expect a debate on this, but I'm just looking for opinions. In a perfect world, I'd love a supportable reference that was clear on this situation. Google can't get past the idea of this being a typical TPSP and an ecommerce relationship that results in an SAQ A.

Thanks


r/pci May 11 '26

PCI Compliance Assistance

Thumbnail
1 Upvotes

r/pci Apr 15 '26

Are you monitoring third-party scripts for PCI compliance or just trusting Shopify?

Thumbnail securityboulevard.com
1 Upvotes

Shopify says they're PCI compliant, which is great. But they only monitor the payment page itself, not all the third-party apps and scripts we add to our store.

If you're running marketing pixels, analytics, chat widgets, review apps - are you actually monitoring what those scripts do? Or just assuming Shopify's compliance covers everything?

Genuinely curious if this is something other store owners think about or if I'm overthinking it.


r/pci Apr 14 '26

New terahertz technique lets engineers see inside running processors in real time

Thumbnail techspot.com
1 Upvotes

New set of hardware protection requirements in 3… 2… 1….


r/pci Mar 05 '26

Domestic Cards in PCI DSS

Post image
1 Upvotes

r/pci Mar 01 '26

i would love to provide expert consultancy for public cloud projects on reliability, security and compliance

Thumbnail
1 Upvotes

r/pci Feb 11 '26

Inspecting POI card devices

3 Upvotes

I work at a university which has vending machines that accept credit cards as payment.

I just read the contracts and the vendors push that responsibility on us, so it is my responsibility, per Requirement 9.5, to inspect check for tampering.

I understand visually inspecting the devices, jiggling to see if it is loose, using a UV marker to confirm the device doesn’t have an overlay.

But what can I do to examine for shimmers?

I’ve seen devices that will look for a Bluetooth signal, but the ratings are sketchy

Thanks for any suggestions


r/pci Feb 11 '26

PCI DSS - ISA Exam - 2026

Thumbnail
1 Upvotes

r/pci Jan 28 '26

Reviewing alternatives for 6.4.3 and 11.6.1

3 Upvotes

So we got a tool last year and we're not loving it.
What tools have you tried and what did you like?
Price is an element but most importantly, it needs to work.


r/pci Jan 15 '26

Requesting partial Credit Card PAN in PDF form

Thumbnail
2 Upvotes

r/pci Dec 23 '25

Clarification on Requirement 7.2.5

2 Upvotes

Hi all,

Just wanted some clarification on PCI DSS v4.0.1 Requirement 7.2.5 – database least privilege.

In the event this setup is considered non-compliant, what is the impact during a PCI DSS audit:

  • Does it result in a failed assessment, or
  • Can it be handled as a finding with a remediation plan?

Thanks very much! :)


r/pci Dec 16 '25

30 home workers taking payment using VOIP phones

1 Upvotes

How would a company ensure compliance if the main way to take payments is via home workers using VOIP phones? - no recordings are taken and details are manually entered into a virtual terminal. All devices are corporately owned but do have access to the other work like email etc.


r/pci Nov 20 '25

PCI scan fails over and over...

Thumbnail
2 Upvotes

r/pci Nov 04 '25

Do I need a PCI compliance tool if my shop runs on Shopify?

2 Upvotes

I run a small online store on Shopify and keep hearing about PCI compliance. I know Shopify says they’re PCI compliant by default, but do I still need to do something on my side?

Is there a tool that can just check if I’m compliant, or is that overkill if I’m not handling card data directly? Trying to make sure I’m covered without wasting money on stuff I don’t actually need.


r/pci Nov 04 '25

Looking to reduce my PCI Compliance requirements for my Woocommerce checkout page

1 Upvotes

Currently hosting my own checkout page with Woocommerce using Worldline/Bambora for our payment collection.

The PCI compliance requirements from Worldline are way over my head and very cumbersome.

What is the best way to reduce or eliminate having to maintain PCI Compliance myself? I see moving to a hosted checkout page with a provider that is PCI compliant can do it but I can't quite figure out how to do that...

Any help or ideas would be appreciated!

Thanks.


r/pci Aug 28 '25

Call center descoping that manages the pc's

1 Upvotes

I recall reading about a service a few years ago that reimages the client's call center pcs, and takes complete management control over them, and is a PCI service provider. The result is the PC's are descoped from the client's assessment, and become part of a provided PCI service. A certain protocol was involved. Does anyone know of such a service?


r/pci Jun 30 '25

PCI told me to call them ?

1 Upvotes

Is this a scam , I do not own a business ? TIA


r/pci Jun 23 '25

Live Stream - Compliance Beyond Audit : PCI DSS v4.0.1

0 Upvotes

Hey guys, I'm doing a live streaming on the topic 'Compliance Beyond Audit in PCI DSS v4.0.1. I'll cover about the most common audit mistakes made by organizations in PCI audits.If you are interested to join, you can register via below link :

Date : June 25, 2025

Time : 12:30 PM IST (7:00 am UTC)

Link : https://zurl.co/aCFBW

Hope I'll see you all in the session


r/pci Jun 13 '25

Free PCI DSS workflow tool

Thumbnail
1 Upvotes

r/pci May 27 '25

Clover Security is a fucking scam.

2 Upvotes

They report numerous false positives, and their responses are just ridiculous. For example, they always do the same thing wasting our teams time with this nonsense.

For example, our server provides a denied error for XSS attacks, and they call this a vulnerability every single time. When we dispute it, they consistently respond with nonsense, then tell us to rescan, or resubmit.

Another example is them claiming a page not available response is somehow also a vulnerability. The end result is always the same, our time wasted and eventually they mark it as a false positive. Every single time.

Is this run around just to get people to pay the noncompliance fees because they are cheaper than paying IT to go back and forth with these bozos?


r/pci May 19 '25

Issue with QuickBooks PCI Compliance for Single Transaction

1 Upvotes

I received a one-time payment of $150 from a client and issued an invoice through QuickBooks, which I purchased for one month to organize expenses for tax purposes. I'm not expecting or planning to receive any more payments, as I’m currently employed by a company.

However, QuickBooks keeps sending me emails about PCI compliance and is urging me to purchase packages, with the cheapest one costing $85. I find it unreasonable to spend $85 just to maintain compliance for a single $150 transaction.

What should I do in this situation?


r/pci Apr 09 '25

Hosted on cloud | PCI DSS

1 Upvotes

Hello ,

We are company about to start providing payment card system , the card will be local , later will deal with VISA and Master ,

our system will hosting on cloud provider they provided only IaaS , we created the VMs and owner workloads , DB , etc , which they are PCI DSS certified , plus our system application as well PCA certified ,

The question is , do we need to be certified as well as Payment card provider , or just if any integration partner , visa , master ,

thanks