About PCIComplianceHub
PCIComplianceHub is a platform for merchants working through PCI DSS v4.0.1, and for the people who advise them. It publishes reference material on the standard and provides tools that produce evidence against specific requirements.
What the platform does
Four things, each tied to requirements a merchant is actually assessed against.
- Works out which SAQ applies. A channel-aware questionnaire that errs toward SAQ D until eligibility is affirmatively established, and produces a determination record a merchant can take to an acquirer.
- Scans transport configuration. A TLS scanner built on testssl.sh that returns a deterministic verdict against the standard’s own rules.
- Monitors payment pages. Script inventory and authorization for Requirement 6.4.3, and change detection on security-impacting HTTP headers for Requirement 11.6.1.
- Trains front office staff. Payment security training for people handling terminals and card-not-present orders at the counter.
Where the reference material comes from
The control pages reproduce PCI DSS v4.0.1 as published by the PCI Security Standards Council. Requirement text and testing procedures are quoted so a reader can look a control up without opening a 397-page PDF, and every page carries attribution and a link to the source. The commentary alongside each control is written here and is clearly separated from the standard’s own wording.
How that material is produced, checked and corrected is set out in the editorial policy.
What this is not
PCIComplianceHub is not a Qualified Security Assessor and not an Approved Scanning Vendor. Nothing it produces is a completed SAQ, an Attestation of Compliance, or an ASV scan report, and no output of the platform substitutes for an assessment by a QSA where one is required.
The material here is general reference on the standard. It is not advice tailored to one merchant’s environment, and scope decisions in particular turn on facts this platform cannot see.
Contact
Corrections and questions go through the contact page. If something on this site states the standard wrongly, say so and it will be fixed and recorded, which is the process described in the editorial policy.