While the PCI SSC expects SAQs to adhere to the same testing procedures as assessments performed by external assessors, many organizations have typically relied on inquiries to complete their self-assessments. Alternatively, they may indicate that controls are implemented based on what they perceive to be accurate, often without additional testing beyond anecdotal experience.
The inconsistencies and inaccuracies in self-assessment methodologies were permitted due to two main factors:
Here an example control from the current version of the DSS within SAQ D is presented below. Notably, the responses are limited to checkboxes.
Now, here is an example of a similar control in the upcoming v4.0 SAQ D template for service providers:
You will notice two significant changes that are crucial to service providing organizations:
Service providers performing insufficient testing or none at all may have difficulty moving forward under the new v4.0 SAQ D template. In this scenario, they could benefit from enlisting an internal audit team, compliance team, or PCI practitioner to perform and draft the PCI SAQ on their behalf. An internal general security or executive team member may need more time or expertise to properly complete the assessment and subsequent report.
Without these internal resources, organizations will likely need to engage contractors, consultants, or opt for their SAQ to be performed by a PCI QSA in a facilitated or attested format.
If you have any questions regarding the v4.0 SAQ D update, please don’t hesitate to contact us and speak with one of our PCI experts.