Calloway & Reyes LLP · ENG-2026-0418

Assessor workbench

Meridian Health Plan · PCI DSS 4.0.1 · Fieldwork · adjudication in progress

38/46

evidence items adjudicated

87%

accepted, in whole or with conditions

29 accepted · 4 with conditions · 5 rejected

8 awaiting verdict · 15 procedures

Engagement record

Opened 2026-07-06 · report due 2026-10-15

Client and assessed scope

Meridian Health PlanCardholder data environment · member payment services

Framework and version

PCI DSS 4.0.115 procedures bound to 15 requirements

Period of coverage

2025-10-012026-09-3012 months, operating effectiveness

Assessor firm and lead

Calloway & Reyes LLPQualified Security Assessor Company · lead QSA-04412 · testers QSA-04412, QSA-07731, SA-2210

Engagement status

Fieldwork · adjudication in progressPrior period assessed by Northgate Assurance

Independence posture

Referral and tooling onlyNo revenue share between the firm and the platform, so assessor independence rules are unaffected.

Evidence in period

46 capture occurrencesEach one signed at capture, each one adjudicated separately.

Adjudication authority

The firm, not the platformModel output is advisory and recorded as such; the verdict of record is the assessor’s.

Period of coverage

2025-10-01 to 2026-09-30 · 46 captures

OCTNOVDECJANFEBMARAPRMAYJUNJULAUGSEPOCTPERIOD2025-10-012026-09-30CAPTURES2026-01-14 · cr-pci-1-2-8-nsc-ruleset-review · accepted2026-07-09 · cr-pci-1-2-8-nsc-ruleset-review · accepted2026-06-18 · cr-pci-3-5-1-2-pan-storage-encryption · accepted-with-conditions2025-11-04 · cr-pci-6-3-3-patch-sla-conformance · rejected2025-12-03 · cr-pci-6-3-3-patch-sla-conformance · rejected2026-01-06 · cr-pci-6-3-3-patch-sla-conformance · rejected2026-02-04 · cr-pci-6-3-3-patch-sla-conformance · accepted-with-conditions2026-03-04 · cr-pci-6-3-3-patch-sla-conformance · accepted2026-04-07 · cr-pci-6-3-3-patch-sla-conformance · accepted2026-05-05 · cr-pci-6-3-3-patch-sla-conformance · accepted2026-06-03 · cr-pci-6-3-3-patch-sla-conformance · awaiting verdict2025-12-19 · cr-pci-7-2-4-privileged-access-review · accepted2026-03-20 · cr-pci-7-2-4-privileged-access-review · accepted2026-06-19 · cr-pci-7-2-4-privileged-access-review · rejected2026-07-02 · cr-pci-7-2-4-privileged-access-review · accepted2026-07-24 · cr-pci-7-2-4-privileged-access-review · awaiting verdict2026-01-09 · cr-pci-8-2-4-account-lifecycle · accepted2026-04-08 · cr-pci-8-2-4-account-lifecycle · accepted2026-07-08 · cr-pci-8-2-4-account-lifecycle · accepted-with-conditions2026-07-08 · cr-pci-8-2-4-account-lifecycle · accepted2026-07-10 · cf-pci-8-3-6-auth-parameters · accepted2026-07-10 · cf-pci-8-3-6-auth-parameters · accepted2026-07-11 · cr-pci-8-4-2-mfa-all-cde-access · accepted2026-07-11 · cr-pci-8-4-2-mfa-all-cde-access · accepted2026-07-13 · cr-pci-8-4-2-mfa-all-cde-access · awaiting verdict2026-01-22 · cr-pci-9-4-1-media-inventory · accepted2026-01-23 · cr-pci-9-4-1-media-inventory · accepted2026-07-21 · cr-pci-9-4-1-media-inventory · awaiting verdict2026-07-22 · cr-pci-9-4-1-media-inventory · awaiting verdict2025-12-30 · cr-pci-10-2-1-1-audit-log-coverage · accepted2026-03-31 · cr-pci-10-2-1-1-audit-log-coverage · accepted2026-06-30 · cr-pci-10-2-1-1-audit-log-coverage · rejected2026-07-17 · cr-pci-10-2-1-1-audit-log-coverage · accepted2026-06-25 · cf-pci-10-4-1-daily-log-review · accepted2026-06-25 · cf-pci-10-4-1-daily-log-review · accepted2026-07-15 · cr-pci-10-7-2-log-failure-detection · accepted2026-07-15 · cr-pci-10-7-2-log-failure-detection · accepted2026-04-30 · cf-pci-11-6-1-change-detection · accepted2026-07-28 · cf-pci-11-6-1-change-detection · awaiting verdict2025-12-22 · cr-pci-11-3-1-1-internal-scan-cadence · accepted2026-03-23 · cr-pci-11-3-1-1-internal-scan-cadence · accepted2026-06-22 · cr-pci-11-3-1-1-internal-scan-cadence · accepted2026-07-27 · cr-pci-11-3-1-1-internal-scan-cadence · awaiting verdict2026-05-21 · cr-pci-12-5-2-scope-validation · accepted2026-05-21 · cr-pci-12-5-2-scope-validation · accepted-with-conditions2026-04-30 · cf-pci-12-10-1-ir-plan-currency · awaiting verdictFIELDWORKTODAYREPORT DUE

Largest interval with no capture inside the period

34 days2025-10-012025-11-04

Fieldwork opened

2026-07-06

Report due

2026-10-15

An operating-effectiveness conclusion is a statement about a period, not about a day. Each tick is one capture positioned by its capture date; a run of blank axis is the shape of an evidence gap, and it is a number the assessor can re-derive.

Adjudication queue

8 awaiting verdict · 46 evidence items in period

1.2.8

2026-01-14

Configuration files for NSCs are secured and kept consistent with active network configurations

cr-pci-1-2-8-nsc-ruleset-review@3.2.0

config-export

88

AcceptedPopulation reconciled

QSA-04412 · 2026-07-14 09:12Z

1.2.8

2026-07-09

Configuration files for NSCs are secured and kept consistent with active network configurations

cr-pci-1-2-8-nsc-ruleset-review@3.2.0

config-export

88

AcceptedPopulation reconciled

QSA-04412 · 2026-07-14 09:26Z

3.5.1.2

2026-06-18

Disk-level encryption is only used on removable media, or is combined with another mechanism

cr-pci-3-5-1-2-pan-storage-encryption@1.4.1

screen-capture

single instance

Accepted with conditionsManagement response pending

Column-level protection is evidenced in the console, but the key-management procedure document it relies on is not referenced from the artifact.

QSA-07731 · 2026-07-15 14:05Z

6.3.3

2025-11-04

All system components are protected from known vulnerabilities by installing applicable security patches

cr-pci-6-3-3-patch-sla-conformance@2.0.3

query-resultnot enumerated
RejectedNo independent corroboration

Dashboard tile count is not corroborated through an independent path and no record-ID list was captured.

QSA-04412 · 2026-07-16 10:41Z

6.3.3

2025-12-03

All system components are protected from known vulnerabilities by installing applicable security patches

cr-pci-6-3-3-patch-sla-conformance@2.0.3

query-resultnot enumerated
RejectedNo independent corroboration

Same defect as the October window. Re-collection requested with an enumerated finding list.

QSA-04412 · 2026-07-16 10:44Z

6.3.3

2026-01-06

All system components are protected from known vulnerabilities by installing applicable security patches

cr-pci-6-3-3-patch-sla-conformance@2.0.3

query-resultnot enumerated
RejectedInsufficient population

The artifact shows a filtered view, not the complete set of critical findings for the window.

QSA-04412 · 2026-07-16 10:52Z

6.3.3

2026-02-04

All system components are protected from known vulnerabilities by installing applicable security patches

cr-pci-6-3-3-patch-sla-conformance@2.0.3

query-resultnot enumerated
Accepted with conditionsSample extension required

Accepted on the strength of the exception register; the selection method for the reviewed items is not reproducible.

QSA-07731 · 2026-07-17 08:30Z

6.3.3

2026-03-04

All system components are protected from known vulnerabilities by installing applicable security patches

cr-pci-6-3-3-patch-sla-conformance@2.0.3

query-resultnot enumerated
AcceptedCorroborated, second source

QSA-07731 · 2026-07-17 08:41Z

6.3.3

2026-04-07

All system components are protected from known vulnerabilities by installing applicable security patches

cr-pci-6-3-3-patch-sla-conformance@2.0.3

query-resultnot enumerated
AcceptedCorroborated, second source

QSA-07731 · 2026-07-17 08:49Z

6.3.3

2026-05-05

All system components are protected from known vulnerabilities by installing applicable security patches

cr-pci-6-3-3-patch-sla-conformance@2.0.3

query-resultnot enumerated
AcceptedCorroborated, second source

QSA-07731 · 2026-07-17 08:55Z

6.3.3

2026-06-03

All system components are protected from known vulnerabilities by installing applicable security patches

cr-pci-6-3-3-patch-sla-conformance@2.0.3

query-resultnot enumerated

7.2.4

2025-12-19

All user accounts and related access privileges are reviewed at least once every six months

cr-pci-7-2-4-privileged-access-review@4.1.0

screen-capture

41225

AcceptedPopulation reconciled

QSA-04412 · 2026-07-20 11:02Z

7.2.4

2026-03-20

All user accounts and related access privileges are reviewed at least once every six months

cr-pci-7-2-4-privileged-access-review@4.1.0

screen-capture

41225

AcceptedPopulation reconciled

QSA-04412 · 2026-07-20 11:19Z

7.2.4

2026-06-19

All user accounts and related access privileges are reviewed at least once every six months

cr-pci-7-2-4-privileged-access-review@4.1.0

screen-capture

41225

RejectedStale evidence

Reviewer decisions carry timestamps nine days after the campaign close date recorded in the artifact.

QSA-04412 · 2026-07-20 11:33Z

7.2.4

2026-07-02

All user accounts and related access privileges are reviewed at least once every six months

cr-pci-7-2-4-privileged-access-review@4.1.0

screen-capture

41225

AcceptedIndependently re-performed

QSA-04412 · 2026-07-24 15:10Z

7.2.4

2026-07-24

All user accounts and related access privileges are reviewed at least once every six months

cr-pci-7-2-4-privileged-access-review@4.1.0

screen-capture

41225

8.2.4

2026-01-09

Addition, deletion, and modification of user IDs is managed through a formal process

cr-pci-8-2-4-account-lifecycle@2.2.0

query-result

9615

AcceptedPopulation reconciled

SA-2210 · 2026-07-21 09:40Z

8.2.4

2026-04-08

Addition, deletion, and modification of user IDs is managed through a formal process

cr-pci-8-2-4-account-lifecycle@2.2.0

query-result

9615

AcceptedPopulation reconciled

SA-2210 · 2026-07-21 09:52Z

8.2.4

2026-07-08

Addition, deletion, and modification of user IDs is managed through a formal process

cr-pci-8-2-4-account-lifecycle@2.2.0

query-result

9615

Accepted with conditionsSample extension required

The delta of one against the HR register is explained in writing and approved; the corroboration path remains single-source.

QSA-07731 · 2026-07-21 10:15Z

8.2.4

2026-07-08

Addition, deletion, and modification of user IDs is managed through a formal process

cr-pci-8-2-4-account-lifecycle@2.2.0

query-result

9615

AcceptedPopulation reconciled

SA-2210 · 2026-07-21 10:28Z

8.3.6

2026-07-10

Minimum password/passphrase strength for in-scope accounts

cf-pci-8-3-6-auth-parameters@1.4.0

config-export

22

AcceptedAccepted as designed

QSA-04412 · 2026-07-22 13:04Z

8.3.6

2026-07-10

Minimum password/passphrase strength for in-scope accounts

cf-pci-8-3-6-auth-parameters@1.4.0

config-export

22

AcceptedAccepted as designed

QSA-04412 · 2026-07-22 13:11Z

8.4.2

2026-07-11

MFA is implemented for all access into the cardholder data environment

cr-pci-8-4-2-mfa-all-cde-access@3.0.1

screen-capture

33

AcceptedIndependently re-performed

QSA-04412 · 2026-07-22 13:40Z

8.4.2

2026-07-11

MFA is implemented for all access into the cardholder data environment

cr-pci-8-4-2-mfa-all-cde-access@3.0.1

screen-capture

33

AcceptedIndependently re-performed

QSA-04412 · 2026-07-22 13:48Z

8.4.2

2026-07-13

MFA is implemented for all access into the cardholder data environment

cr-pci-8-4-2-mfa-all-cde-access@3.0.1

screen-capture

33

9.4.1

2026-01-22

All media with cardholder data is physically secured and inventoried

cr-pci-9-4-1-media-inventory@1.2.0

session-recording

3410

AcceptedIndependently re-performed

QSA-07731 · 2026-07-30 15:05Z

9.4.1

2026-01-23

All media with cardholder data is physically secured and inventoried

cr-pci-9-4-1-media-inventory@1.2.0

session-recording

3410

AcceptedCorroborated, second source

QSA-07731 · 2026-07-30 15:22Z

9.4.1

2026-07-21

All media with cardholder data is physically secured and inventoried

cr-pci-9-4-1-media-inventory@1.2.0

session-recording

3410

9.4.1

2026-07-22

All media with cardholder data is physically secured and inventoried

cr-pci-9-4-1-media-inventory@1.2.0

session-recording

3410

10.2.1.1

2025-12-30

Audit logs capture all individual user access to cardholder data

cr-pci-10-2-1-1-audit-log-coverage@1.9.0

query-result

6112

AcceptedPopulation reconciled

SA-2210 · 2026-07-23 09:05Z

10.2.1.1

2026-03-31

Audit logs capture all individual user access to cardholder data

cr-pci-10-2-1-1-audit-log-coverage@1.9.0

query-result

6112

AcceptedPopulation reconciled

SA-2210 · 2026-07-23 09:17Z

10.2.1.1

2026-06-30

Audit logs capture all individual user access to cardholder data

cr-pci-10-2-1-1-audit-log-coverage@1.9.0

query-result

6112

RejectedInsufficient population

Two in-scope hosts show no events for 41 days inside the period; the assertion is made against a filtered view rather than the enumerated component list.

QSA-04412 · 2026-07-23 09:44Z

10.2.1.1

2026-07-17

Audit logs capture all individual user access to cardholder data

cr-pci-10-2-1-1-audit-log-coverage@1.9.0

query-result

6112

AcceptedPopulation reconciled

QSA-04412 · 2026-07-28 10:02Z

10.4.1

2026-06-25

Audit logs are reviewed at least once daily

cf-pci-10-4-1-daily-log-review@2.1.0

query-result

3434

AcceptedAccepted as designed

SA-2210 · 2026-07-24 14:20Z

10.4.1

2026-06-25

Audit logs are reviewed at least once daily

cf-pci-10-4-1-daily-log-review@2.1.0

query-result

3434

AcceptedAccepted as designed

SA-2210 · 2026-07-24 14:29Z

10.7.2

2026-07-15

Failures of critical security control systems are detected, alerted, and addressed promptly

cr-pci-10-7-2-log-failure-detection@1.1.2

screen-capture

single instance

AcceptedIndependently re-performed

QSA-07731 · 2026-07-27 11:15Z

10.7.2

2026-07-15

Failures of critical security control systems are detected, alerted, and addressed promptly

cr-pci-10-7-2-log-failure-detection@1.1.2

screen-capture

single instance

AcceptedIndependently re-performed

QSA-07731 · 2026-07-27 11:31Z

11.6.1

2026-04-30

Change- and tamper-detection mechanism on payment pages

cf-pci-11-6-1-change-detection@1.2.0

screen-capture

66

AcceptedPopulation reconciled

SA-2210 · 2026-07-29 14:02Z

11.6.1

2026-07-28

Change- and tamper-detection mechanism on payment pages

cf-pci-11-6-1-change-detection@1.2.0

screen-capture

66

11.3.1.1

2025-12-22

All other applicable vulnerabilities are managed and rescans are performed as needed

cr-pci-11-3-1-1-internal-scan-cadence@2.5.0

document-review

44

AcceptedCorroborated, second source

SA-2210 · 2026-07-28 13:02Z

11.3.1.1

2026-03-23

All other applicable vulnerabilities are managed and rescans are performed as needed

cr-pci-11-3-1-1-internal-scan-cadence@2.5.0

document-review

44

AcceptedCorroborated, second source

SA-2210 · 2026-07-28 13:09Z

11.3.1.1

2026-06-22

All other applicable vulnerabilities are managed and rescans are performed as needed

cr-pci-11-3-1-1-internal-scan-cadence@2.5.0

document-review

44

AcceptedCorroborated, second source

SA-2210 · 2026-07-28 13:16Z

11.3.1.1

2026-07-27

All other applicable vulnerabilities are managed and rescans are performed as needed

cr-pci-11-3-1-1-internal-scan-cadence@2.5.0

document-review

44

12.5.2

2026-05-21

PCI DSS scope is documented and confirmed at least once every 12 months

cr-pci-12-5-2-scope-validation@1.3.0

session-recording

single instance

AcceptedIndependently re-performed

QSA-04412 · 2026-07-29 09:30Z

12.5.2

2026-05-21

PCI DSS scope is documented and confirmed at least once every 12 months

cr-pci-12-5-2-scope-validation@1.3.0

session-recording

single instance

Accepted with conditionsScope narrowed by note

The walkthrough confirms the diagram, but one connected settlement service is described as out of scope without a segmentation test reference.

QSA-04412 · 2026-07-29 09:52Z

12.10.1

2026-04-30

Incident response plan exists and is ready to be activated

cf-pci-12-10-1-ir-plan-currency@1.0.0

document-review

1919

Workpaper export

38 of 46 rows carry a verdict

The deliverable leaves in the firm’s shape, not the platform’s: a workpaper index of control, procedure at version, evidence reference, verdict, reason code, tester, and date — sealed with a digest computed over the index itself.

8 items still awaiting a verdict will appear in the index as open.

Open workpaper index