Editorial policy

This page describes how the material on PCIComplianceHub is produced, what is checked before it is published, how it is dated, and what happens when it turns out to be wrong.

Authorship

Content is published by PCIComplianceHub as an organization. Individual pages do not carry a personal byline, and a named reviewer appears only where that person genuinely reviewed the page and agreed to be named.

PCIComplianceHub is not a Qualified Security Assessor and not an Approved Scanning Vendor. No page on this site is reviewed or endorsed by a QSA, an ASV or an assessment firm, and none claims to be.

What the material is derived from

The primary source is PCI DSS v4.0.1 as published by the PCI Security Standards Council. The control reference pages are generated from an extraction of the standard rather than retyped, which is what keeps the quoted requirement text and testing procedures matching the source.

Quotation and commentary are kept apart on every page. The requirement appears in a blockquote and the testing procedures in a table, both verbatim. The guidance around them is written here and is not the standard speaking.

What is checked before publication

Every claim about the standard is checked against the standard, not against what sounds right. Two worked examples, both of which were found and fixed rather than hypothetical:

Where a defect can be expressed as a rule, it becomes an automated check rather than a note to be careful. That is deliberate: the same class of error kept surviving manual review.

Dates: updated and reviewed are not the same thing

These two are easy to conflate and mean different things, so this site keeps them separate.

A change to one page establishes nothing about any other, and a review that finds no fault produces no change at all, so one cannot stand in for the other. Neither date is displayed on the site yet. They will appear once each is derived from a real record rather than asserted, and until then their absence is the honest position.

Which version applies

Everything here is written against PCI DSS v4.0.1. The standard changes, and guidance written against one version does not automatically hold for the next. Where a requirement has a future-dated effective date, the page says so rather than presenting it as already in force.

Corrections

When a page is found to state the standard wrongly, the page is corrected and, where the error came from a repeatable cause, an automated check is added so the same class of error cannot return silently. Corrections are not made quietly to save face: the defect that produced them is recorded, because a pattern of errors is more useful to fix than any single instance.

Report anything that looks wrong through the contact page.

What this site is not

The reference material is general information about PCI DSS. It is not a completed SAQ, not an Attestation of Compliance, and not advice tailored to one merchant’s environment. Scope in particular depends on facts about a specific cardholder data environment that this platform cannot see.

Tool output evidences specific requirements and asserts nothing beyond what was actually observed. Where a scan cannot reach something, the result says so rather than reporting a pass. More about the platform and its publisher is on the about page.