The assessment starts before testing

The assessor first needs to understand the entity, its payment channels, connected systems, locations, people and service providers. Scope is foundational. If the boundary is wrong, a technically detailed assessment can still reach the wrong conclusion.

That means following payment data, confirming segmentation where it is used and understanding systems that may not hold card data but can affect its security.

Evidence has to show design and operation

A policy can show intent. It cannot, by itself, show that a control operates. Assessors therefore look for a combination of documented requirements, configurations, records, interviews and observation.

Sampling is used where examining every item is impractical. A sample must represent the population and support a conclusion. It is not a shortcut around weak evidence.

What the QSA is responsible for

The QSA plans and performs the assessment, records the testing completed and reaches conclusions supported by evidence.

  • Confirming scope and assessment boundaries
  • Testing applicable PCI DSS requirements
  • Documenting evidence and observations
  • Identifying requirements not in place
  • Preparing the relevant compliance report

What remains with the organisation

Management remains responsible for the environment, the accuracy of information provided and the operation of controls. Service providers also need active oversight. An Attestation of Compliance is not a substitute for understanding what the provider does and what remains with the customer.

The best assessor relationship is clear and independent. It helps the organisation understand the standard without confusing assessment with ownership.