PCI
- Merchant -
An individual or business that accepts payment cards (like credit or debit cards) for goods or services. Merchants must comply with the Payment Card Industry Data Security Standard (PCI DSS) to ensure secure cardholder data handling.
- PCI DSS (Payment Card Industry Data Security Standard) -
A set of security standards developed to ensure that all organizations that store, process, or transmit credit card information maintain a secure environment.
- PCI Testing -
Security assessments required by PCI DSS to evaluate an organization’s adherence to PCI requirements. These assessments include vulnerability scans, penetration testing, and compliance audits.
- Readiness Assessment -
A preliminary evaluation conducted before a formal audit to identify gaps, prepare documentation, and determine an organization’s audit readiness. Often used for frameworks like SOC 2, CMMC, and HITRUST.
- Risk Management -
The ongoing process of identifying, analyzing, and mitigating potential threats to organizational operations, data, and systems. It helps ensure regulatory compliance and business continuity.
- Self-Assessment Questionnaire (SAQ) -
A validation tool used by merchants and service providers to demonstrate PCI DSS compliance. There are multiple SAQ types depending on how payment data is handled.








