Significant Change

PCIComplianceHubLast updated

A change to an environment substantial enough to require PCI DSS activities to be repeated. The standard deliberately avoids fixing a single definition, leaving each organization to define it for its own environment and document the reasoning. It commonly covers new or replaced hardware and software in the cardholder data environment, changes to network topology or firewall rules, changes to system components, and anything that alters scope. When one occurs, internal and external vulnerability scans must be repeated, penetration testing scope reconsidered, and applicable requirements confirmed as still in place. Service providers must also review scope after a significant change.