PCIP Compliance Reporting 3 — Questions and Answers
Question 1: Which SAQ type applies to merchants who only use payment terminals connected to a payment processor via IP with no electronic cardholder data storage?
- SAQ A
- SAQ B
- SAQ B-IP (Correct answer)
- SAQ C
Correct answer: SAQ B-IP
SAQ B-IP applies to merchants using standalone IP-connected payment terminals that do not store electronic cardholder data.
Question 2: What is the compliance reporting obligation for a newly identified service provider that stores cardholder data?
- They have 180 days before reporting is required
- They must immediately submit an AOC to the card brands
- They must begin working toward compliance immediately and report by the acquirer's deadline (Correct answer)
- No reporting is required until their first data breach
Correct answer: They must begin working toward compliance immediately and report by the acquirer's deadline
Newly identified service providers must begin PCI DSS compliance efforts immediately and meet reporting deadlines set by their acquiring bank or card brand.
Question 3: When a QSA marks a requirement as 'Not Applicable' in the ROC, what must also be documented?
- A compensating control worksheet
- The justification explaining why the requirement does not apply (Correct answer)
- Approval from the card brand
- An alternative technical control
Correct answer: The justification explaining why the requirement does not apply
When a requirement is marked Not Applicable, the QSA must document the specific justification for why the requirement does not apply to the assessed environment.
Question 4: A merchant discovers they are out of compliance after completing their annual SAQ. What is the correct first step?
- Notify law enforcement immediately
- Inform their acquiring bank and develop a remediation plan (Correct answer)
- Stop accepting card payments until fully compliant
- Conduct an internal investigation and self-certify compliance
Correct answer: Inform their acquiring bank and develop a remediation plan
Upon discovering non-compliance, merchants must notify their acquirer and work with them to develop an acceptable remediation plan with defined timelines.
Question 5: Which card brand requires all Level 1 service providers to be listed on its public registry of compliant service providers?
- Only Visa
- Only Mastercard
- Both Visa and Mastercard (Correct answer)
- No card brand maintains such a registry
Correct answer: Both Visa and Mastercard
Both Visa and Mastercard maintain public registries of compliant service providers, and Level 1 service providers must be listed to demonstrate compliance.
Question 6: What is the typical timeframe a QSA has to complete and submit a ROC after concluding an on-site assessment?
- 30 days
- 60 days
- 90 days
- There is no mandated timeframe (Correct answer)
Correct answer: There is no mandated timeframe
PCI DSS does not specify a mandatory timeframe for ROC submission after an assessment; deadlines are set by the acquiring bank or card brand.
Question 7: Under PCI DSS, what must happen to a service provider's compliance status if they fail to validate compliance by the required date?
- Automatic suspension of their merchant ID
- The acquirer may notify the card brand and the provider may be removed from compliant registries (Correct answer)
- A $10,000 fine is automatically assessed
- Nothing until a breach occurs
Correct answer: The acquirer may notify the card brand and the provider may be removed from compliant registries
Failure to validate compliance can result in the acquiring bank notifying the card brand, which may remove the service provider from compliance registries and impose fines.
Which SAQ type applies to merchants who only use payment terminals connected to a payment processor via IP with no electronic cardholder data storage?