Editorial policy
This page describes how the material on PCIComplianceHub is produced, what is checked before it is published, how it is dated, and what happens when it turns out to be wrong.
Authorship
Content is published by PCIComplianceHub as an organization. Individual pages do not carry a personal byline, and a named reviewer appears only where that person genuinely reviewed the page and agreed to be named.
PCIComplianceHub is not a Qualified Security Assessor and not an Approved Scanning Vendor. No page on this site is reviewed or endorsed by a QSA, an ASV or an assessment firm, and none claims to be.
What the material is derived from
The primary source is PCI DSS v4.0.1 as published by the PCI Security Standards Council. The control reference pages are generated from an extraction of the standard rather than retyped, which is what keeps the quoted requirement text and testing procedures matching the source.
Quotation and commentary are kept apart on every page. The requirement appears in a blockquote and the testing procedures in a table, both verbatim. The guidance around them is written here and is not the standard speaking.
What is checked before publication
Every claim about the standard is checked against the standard, not against what sounds right. Two worked examples, both of which were found and fixed rather than hypothetical:
- A review of the glossary found four entries that stated PCI DSS wrongly, including one that misclassified the commonest e-commerce integration there is. Each was checked against the PCI SSC source before it was rewritten, and the SAQ questionnaire was checked for the same error.
- A check of the generated control pages found every page title was a partial quotation of the standard, cut mid-clause so that it read as complete. Titles now carry a written summary rather than an excerpt, and an automated check fails the build if a title ever becomes a truncated quotation again.
Where a defect can be expressed as a rule, it becomes an automated check rather than a note to be careful. That is deliberate: the same class of error kept surviving manual review.
Dates: updated and reviewed are not the same thing
These two are easy to conflate and mean different things, so this site keeps them separate.
- Last updated records that the page’s content changed. It is derived from the change history of the source that generates the page, never typed by hand.
- Last reviewed records that a person checked the page against the current standard and found it correct. It is written down when that happens, and is never inferred from the fact that something changed.
A change to one page establishes nothing about any other, and a review that finds no fault produces no change at all, so one cannot stand in for the other. Neither date is displayed on the site yet. They will appear once each is derived from a real record rather than asserted, and until then their absence is the honest position.
Which version applies
Everything here is written against PCI DSS v4.0.1. The standard changes, and guidance written against one version does not automatically hold for the next. Where a requirement has a future-dated effective date, the page says so rather than presenting it as already in force.
Corrections
When a page is found to state the standard wrongly, the page is corrected and, where the error came from a repeatable cause, an automated check is added so the same class of error cannot return silently. Corrections are not made quietly to save face: the defect that produced them is recorded, because a pattern of errors is more useful to fix than any single instance.
Report anything that looks wrong through the contact page.
What this site is not
The reference material is general information about PCI DSS. It is not a completed SAQ, not an Attestation of Compliance, and not advice tailored to one merchant’s environment. Scope in particular depends on facts about a specific cardholder data environment that this platform cannot see.
Tool output evidences specific requirements and asserts nothing beyond what was actually observed. Where a scan cannot reach something, the result says so rather than reporting a pass. More about the platform and its publisher is on the about page.