1.2.8
2026-01-14
Configuration files for NSCs are secured and kept consistent with active network configurations
cr-pci-1-2-8-nsc-ruleset-review@3.2.0
8→8
QSA-04412 · 2026-07-14 09:12Z
Calloway & Reyes LLP · ENG-2026-0418
Meridian Health Plan · PCI DSS 4.0.1 · Fieldwork · adjudication in progress
38/46
evidence items adjudicated
87%
accepted, in whole or with conditions
29 accepted · 4 with conditions · 5 rejected
8 awaiting verdict · 15 procedures
Opened 2026-07-06 · report due 2026-10-15
Client and assessed scope
Framework and version
Period of coverage
Assessor firm and lead
Engagement status
Independence posture
Evidence in period
Adjudication authority
2025-10-01 to 2026-09-30 · 46 captures
Largest interval with no capture inside the period
Fieldwork opened
Report due
An operating-effectiveness conclusion is a statement about a period, not about a day. Each tick is one capture positioned by its capture date; a run of blank axis is the shape of an evidence gap, and it is a number the assessor can re-derive.
8 awaiting verdict · 46 evidence items in period
| Control | Procedure | Evidence | Captured | Population / sample | Verdict |
|---|---|---|---|---|---|
1.2.8 Configuration files for NSCs are secured and kept consistent with active network configurations | cr-pci-1-2-8-nsc-ruleset-review@3.2.0 plan 790698f49c80ea85 authored for this engagement | config-export Palo Alto Panorama · CDE perimeter H1 FY26 · ruleset export | 2026-01-14 754349f0e6a9 signed at capture | 8→8 corroborated independently | AcceptedPopulation reconciled QSA-04412 · 2026-07-14 09:12Z |
1.2.8 Configuration files for NSCs are secured and kept consistent with active network configurations | cr-pci-1-2-8-nsc-ruleset-review@3.2.0 plan 790698f49c80ea85 authored for this engagement | config-export Palo Alto Panorama · CDE perimeter H2 FY26 · ruleset export | 2026-07-09 6ae494fd035e signed at capture | 8→8 corroborated independently | AcceptedPopulation reconciled QSA-04412 · 2026-07-14 09:26Z |
3.5.1.2 Disk-level encryption is only used on removable media, or is combined with another mechanism | cr-pci-3-5-1-2-pan-storage-encryption@1.4.1 plan 322f76c38fe4bb66 authored for this engagement | screen-capture Aurora PostgreSQL · pay-svc-prod cluster FY26 annual attestation | 2026-06-18 365f551b50f2 signed at capture | single instance | Accepted with conditionsManagement response pending Column-level protection is evidenced in the console, but the key-management procedure document it relies on is not referenced from the artifact. QSA-07731 · 2026-07-15 14:05Z |
6.3.3 All system components are protected from known vulnerabilities by installing applicable security patches | cr-pci-6-3-3-patch-sla-conformance@2.0.3 plan 0effc17ab4ce1e42 authored for this engagement | query-result Vulnerability management platform · CDE asset group Oct 2025 remediation window | 2025-11-04 69a2def43392 signed at capture | not enumerated | RejectedNo independent corroboration Dashboard tile count is not corroborated through an independent path and no record-ID list was captured. QSA-04412 · 2026-07-16 10:41Z |
6.3.3 All system components are protected from known vulnerabilities by installing applicable security patches | cr-pci-6-3-3-patch-sla-conformance@2.0.3 plan 0effc17ab4ce1e42 authored for this engagement | query-result Vulnerability management platform · CDE asset group Nov 2025 remediation window | 2025-12-03 97f95595d117 signed at capture | not enumerated | RejectedNo independent corroboration Same defect as the October window. Re-collection requested with an enumerated finding list. QSA-04412 · 2026-07-16 10:44Z |
6.3.3 All system components are protected from known vulnerabilities by installing applicable security patches | cr-pci-6-3-3-patch-sla-conformance@2.0.3 plan 0effc17ab4ce1e42 authored for this engagement | query-result Vulnerability management platform · CDE asset group Dec 2025 remediation window | 2026-01-06 f8bee1bde9a0 signed at capture | not enumerated | RejectedInsufficient population The artifact shows a filtered view, not the complete set of critical findings for the window. QSA-04412 · 2026-07-16 10:52Z |
6.3.3 All system components are protected from known vulnerabilities by installing applicable security patches | cr-pci-6-3-3-patch-sla-conformance@2.0.3 plan 0effc17ab4ce1e42 authored for this engagement | query-result Vulnerability management platform · CDE asset group Jan 2026 remediation window | 2026-02-04 10c35ed364ec signed at capture | not enumerated | Accepted with conditionsSample extension required Accepted on the strength of the exception register; the selection method for the reviewed items is not reproducible. QSA-07731 · 2026-07-17 08:30Z |
6.3.3 All system components are protected from known vulnerabilities by installing applicable security patches | cr-pci-6-3-3-patch-sla-conformance@2.0.3 plan 0effc17ab4ce1e42 authored for this engagement | query-result Vulnerability management platform · CDE asset group Feb 2026 remediation window | 2026-03-04 3892e4de85d8 signed at capture | not enumerated | AcceptedCorroborated, second source QSA-07731 · 2026-07-17 08:41Z |
6.3.3 All system components are protected from known vulnerabilities by installing applicable security patches | cr-pci-6-3-3-patch-sla-conformance@2.0.3 plan 0effc17ab4ce1e42 authored for this engagement | query-result Vulnerability management platform · CDE asset group Mar 2026 remediation window | 2026-04-07 e48823323db5 signed at capture | not enumerated | AcceptedCorroborated, second source QSA-07731 · 2026-07-17 08:49Z |
6.3.3 All system components are protected from known vulnerabilities by installing applicable security patches | cr-pci-6-3-3-patch-sla-conformance@2.0.3 plan 0effc17ab4ce1e42 authored for this engagement | query-result Vulnerability management platform · CDE asset group Apr 2026 remediation window | 2026-05-05 ef37999e80c2 signed at capture | not enumerated | AcceptedCorroborated, second source QSA-07731 · 2026-07-17 08:55Z |
6.3.3 All system components are protected from known vulnerabilities by installing applicable security patches | cr-pci-6-3-3-patch-sla-conformance@2.0.3 plan 0effc17ab4ce1e42 authored for this engagement | query-result Vulnerability management platform · CDE asset group May 2026 remediation window | 2026-06-03 e73b200084ae signed at capture | not enumerated | |
7.2.4 All user accounts and related access privileges are reviewed at least once every six months | cr-pci-7-2-4-privileged-access-review@4.1.0 plan d94250ab90fd8521 authored for this engagement | screen-capture Identity provider · six CDE administrator groups Q1 FY26 · Dec 2025 review | 2025-12-19 a80ebe9fd5f2 signed at capture | 412→25 corroborated independently | AcceptedPopulation reconciled QSA-04412 · 2026-07-20 11:02Z |
7.2.4 All user accounts and related access privileges are reviewed at least once every six months | cr-pci-7-2-4-privileged-access-review@4.1.0 plan d94250ab90fd8521 authored for this engagement | screen-capture Identity provider · six CDE administrator groups Q2 FY26 · Mar 2026 review | 2026-03-20 7eb4ddb3521c signed at capture | 412→25 corroborated independently | AcceptedPopulation reconciled QSA-04412 · 2026-07-20 11:19Z |
7.2.4 All user accounts and related access privileges are reviewed at least once every six months | cr-pci-7-2-4-privileged-access-review@4.1.0 plan d94250ab90fd8521 authored for this engagement | screen-capture Identity provider · six CDE administrator groups Q3 FY26 · Jun 2026 review | 2026-06-19 2679b5cffc87 signed at capture | 412→25 corroborated independently | RejectedStale evidence Reviewer decisions carry timestamps nine days after the campaign close date recorded in the artifact. QSA-04412 · 2026-07-20 11:33Z |
7.2.4 All user accounts and related access privileges are reviewed at least once every six months | cr-pci-7-2-4-privileged-access-review@4.1.0 plan d94250ab90fd8521 authored for this engagement | screen-capture Identity provider · six CDE administrator groups Q3 FY26 · remediation re-test | 2026-07-02 9cd29f898c26 signed at capture | 412→25 corroborated independently | AcceptedIndependently re-performed QSA-04412 · 2026-07-24 15:10Z |
7.2.4 All user accounts and related access privileges are reviewed at least once every six months | cr-pci-7-2-4-privileged-access-review@4.1.0 plan d94250ab90fd8521 authored for this engagement | screen-capture Identity provider · six CDE administrator groups Q4 FY26 · Jul 2026 interim | 2026-07-24 838f79f720be signed at capture | 412→25 corroborated independently | |
8.2.4 Addition, deletion, and modification of user IDs is managed through a formal process | cr-pci-8-2-4-account-lifecycle@2.2.0 plan 731548f4bcd73451 authored for this engagement | query-result Identity provider system log · joiner-mover-leaver events Q1 FY26 · leaver cohort | 2026-01-09 a6c0ce161210 signed at capture | 96→15 corroborated independently | AcceptedPopulation reconciled SA-2210 · 2026-07-21 09:40Z |
8.2.4 Addition, deletion, and modification of user IDs is managed through a formal process | cr-pci-8-2-4-account-lifecycle@2.2.0 plan 731548f4bcd73451 authored for this engagement | query-result Identity provider system log · joiner-mover-leaver events Q2 FY26 · leaver cohort | 2026-04-08 4b5e5e64d9c7 signed at capture | 96→15 corroborated independently | AcceptedPopulation reconciled SA-2210 · 2026-07-21 09:52Z |
8.2.4 Addition, deletion, and modification of user IDs is managed through a formal process | cr-pci-8-2-4-account-lifecycle@2.2.0 plan 731548f4bcd73451 authored for this engagement | query-result Identity provider system log · joiner-mover-leaver events Q3 FY26 · leaver cohort | 2026-07-08 078f3afdea8a signed at capture | 96→15 corroborated independently | Accepted with conditionsSample extension required The delta of one against the HR register is explained in writing and approved; the corroboration path remains single-source. QSA-07731 · 2026-07-21 10:15Z |
8.2.4 Addition, deletion, and modification of user IDs is managed through a formal process | cr-pci-8-2-4-account-lifecycle@2.2.0 plan 731548f4bcd73451 authored for this engagement | query-result Identity provider system log · joiner-mover-leaver events Q3 FY26 · joiner cohort | 2026-07-08 86572ce369f7 signed at capture | 96→15 corroborated independently | AcceptedPopulation reconciled SA-2210 · 2026-07-21 10:28Z |
8.3.6 Minimum password/passphrase strength for in-scope accounts | cf-pci-8-3-6-auth-parameters@1.4.0 plan 5d0f70b14cafda38 published in the registry | config-export Identity provider · CDE sign-on policy and break-glass realm Primary identity provider realm | 2026-07-10 eee7628db1be signed at capture | 2→2 corroborated independently | AcceptedAccepted as designed QSA-04412 · 2026-07-22 13:04Z |
8.3.6 Minimum password/passphrase strength for in-scope accounts | cf-pci-8-3-6-auth-parameters@1.4.0 plan 5d0f70b14cafda38 published in the registry | config-export Identity provider · CDE sign-on policy and break-glass realm Break-glass local realm · bastion | 2026-07-10 c9c36221fadb signed at capture | 2→2 corroborated independently | AcceptedAccepted as designed QSA-04412 · 2026-07-22 13:11Z |
8.4.2 MFA is implemented for all access into the cardholder data environment | cr-pci-8-4-2-mfa-all-cde-access@3.0.1 plan dc4cc5256ff79265 authored for this engagement | screen-capture Sign-on policies · VPN, SSH bastion, cloud console Access path · VPN | 2026-07-11 5913d22f60f7 signed at capture | 3→3 corroborated independently | AcceptedIndependently re-performed QSA-04412 · 2026-07-22 13:40Z |
8.4.2 MFA is implemented for all access into the cardholder data environment | cr-pci-8-4-2-mfa-all-cde-access@3.0.1 plan dc4cc5256ff79265 authored for this engagement | screen-capture Sign-on policies · VPN, SSH bastion, cloud console Access path · SSH bastion | 2026-07-11 65881fa79a19 signed at capture | 3→3 corroborated independently | AcceptedIndependently re-performed QSA-04412 · 2026-07-22 13:48Z |
8.4.2 MFA is implemented for all access into the cardholder data environment | cr-pci-8-4-2-mfa-all-cde-access@3.0.1 plan dc4cc5256ff79265 authored for this engagement | screen-capture Sign-on policies · VPN, SSH bastion, cloud console Access path · cloud console | 2026-07-13 19804a5cc1b6 signed at capture | 3→3 corroborated independently | |
9.4.1 All media with cardholder data is physically secured and inventoried | cr-pci-9-4-1-media-inventory@1.2.0 plan bccd43d9b1f453a2 authored for this engagement | session-recording Secure media room · primary data center H1 FY26 · media room walk | 2026-01-22 e35548f1e32f signed at capture | 34→10 corroborated independently | AcceptedIndependently re-performed QSA-07731 · 2026-07-30 15:05Z |
9.4.1 All media with cardholder data is physically secured and inventoried | cr-pci-9-4-1-media-inventory@1.2.0 plan bccd43d9b1f453a2 authored for this engagement | session-recording Secure media room · primary data center H1 FY26 · vault reconciliation | 2026-01-23 e03ca953d166 signed at capture | 34→10 corroborated independently | AcceptedCorroborated, second source QSA-07731 · 2026-07-30 15:22Z |
9.4.1 All media with cardholder data is physically secured and inventoried | cr-pci-9-4-1-media-inventory@1.2.0 plan bccd43d9b1f453a2 authored for this engagement | session-recording Secure media room · primary data center H2 FY26 · media room walk | 2026-07-21 7ab148671e7f signed at capture | 34→10 corroborated independently | |
9.4.1 All media with cardholder data is physically secured and inventoried | cr-pci-9-4-1-media-inventory@1.2.0 plan bccd43d9b1f453a2 authored for this engagement | session-recording Secure media room · primary data center H2 FY26 · vault reconciliation | 2026-07-22 719cb3171648 signed at capture | 34→10 corroborated independently | |
10.2.1.1 Audit logs capture all individual user access to cardholder data | cr-pci-10-2-1-1-audit-log-coverage@1.9.0 plan cf4b3493a67ffebc authored for this engagement | query-result Log platform · cardholder data index Q1 FY26 coverage check | 2025-12-30 db350ba6cc6d signed at capture | 61→12 corroborated independently | AcceptedPopulation reconciled SA-2210 · 2026-07-23 09:05Z |
10.2.1.1 Audit logs capture all individual user access to cardholder data | cr-pci-10-2-1-1-audit-log-coverage@1.9.0 plan cf4b3493a67ffebc authored for this engagement | query-result Log platform · cardholder data index Q2 FY26 coverage check | 2026-03-31 1fe87c25bd44 signed at capture | 61→12 corroborated independently | AcceptedPopulation reconciled SA-2210 · 2026-07-23 09:17Z |
10.2.1.1 Audit logs capture all individual user access to cardholder data | cr-pci-10-2-1-1-audit-log-coverage@1.9.0 plan cf4b3493a67ffebc authored for this engagement | query-result Log platform · cardholder data index Q3 FY26 coverage check | 2026-06-30 e54ef9dc219f signed at capture | 61→12 corroborated independently | RejectedInsufficient population Two in-scope hosts show no events for 41 days inside the period; the assertion is made against a filtered view rather than the enumerated component list. QSA-04412 · 2026-07-23 09:44Z |
10.2.1.1 Audit logs capture all individual user access to cardholder data | cr-pci-10-2-1-1-audit-log-coverage@1.9.0 plan cf4b3493a67ffebc authored for this engagement | query-result Log platform · cardholder data index Q3 FY26 gap re-test | 2026-07-17 4728d9a9832a signed at capture | 61→12 corroborated independently | AcceptedPopulation reconciled QSA-04412 · 2026-07-28 10:02Z |
10.4.1 Audit logs are reviewed at least once daily | cf-pci-10-4-1-daily-log-review@2.1.0 plan d10a945ff9d5f53a published in the registry | query-result Log platform · correlation searches and notable-event routing Correlation search inventory | 2026-06-25 9651f6c82e91 signed at capture | 34→34 corroborated independently | AcceptedAccepted as designed SA-2210 · 2026-07-24 14:20Z |
10.4.1 Audit logs are reviewed at least once daily | cf-pci-10-4-1-daily-log-review@2.1.0 plan d10a945ff9d5f53a published in the registry | query-result Log platform · correlation searches and notable-event routing Notable-event routing configuration | 2026-06-25 6ec6d33e5086 signed at capture | 34→34 corroborated independently | AcceptedAccepted as designed SA-2210 · 2026-07-24 14:29Z |
10.7.2 Failures of critical security control systems are detected, alerted, and addressed promptly | cr-pci-10-7-2-log-failure-detection@1.1.2 plan 73be709f1aee1e07 authored for this engagement | screen-capture Log platform · forwarder monitoring console Alert configuration | 2026-07-15 85ae08706b86 signed at capture | single instance | AcceptedIndependently re-performed QSA-07731 · 2026-07-27 11:15Z |
10.7.2 Failures of critical security control systems are detected, alerted, and addressed promptly | cr-pci-10-7-2-log-failure-detection@1.1.2 plan 73be709f1aee1e07 authored for this engagement | screen-capture Log platform · forwarder monitoring console Induced failure test | 2026-07-15 48ad3a3228e9 signed at capture | single instance | AcceptedIndependently re-performed QSA-07731 · 2026-07-27 11:31Z |
11.6.1 Change- and tamper-detection mechanism on payment pages | cf-pci-11-6-1-change-detection@1.2.0 plan fa6c14222a531b65 published in the registry | screen-capture Payment page · member checkout flow Q2 FY26 payment page baseline | 2026-04-30 28db0b41aa0c signed at capture | 6→6 corroborated independently | AcceptedPopulation reconciled SA-2210 · 2026-07-29 14:02Z |
11.6.1 Change- and tamper-detection mechanism on payment pages | cf-pci-11-6-1-change-detection@1.2.0 plan fa6c14222a531b65 published in the registry | screen-capture Payment page · member checkout flow Q3 FY26 payment page baseline | 2026-07-28 d953e12d60bd signed at capture | 6→6 corroborated independently | |
11.3.1.1 All other applicable vulnerabilities are managed and rescans are performed as needed | cr-pci-11-3-1-1-internal-scan-cadence@2.5.0 plan 8cb43c088c2a6b24 authored for this engagement | document-review Vulnerability management platform · quarterly internal scans Q1 FY26 scan and rescan | 2025-12-22 8ab6dd52c5af signed at capture | 4→4 corroborated independently | AcceptedCorroborated, second source SA-2210 · 2026-07-28 13:02Z |
11.3.1.1 All other applicable vulnerabilities are managed and rescans are performed as needed | cr-pci-11-3-1-1-internal-scan-cadence@2.5.0 plan 8cb43c088c2a6b24 authored for this engagement | document-review Vulnerability management platform · quarterly internal scans Q2 FY26 scan and rescan | 2026-03-23 cb4d550b0581 signed at capture | 4→4 corroborated independently | AcceptedCorroborated, second source SA-2210 · 2026-07-28 13:09Z |
11.3.1.1 All other applicable vulnerabilities are managed and rescans are performed as needed | cr-pci-11-3-1-1-internal-scan-cadence@2.5.0 plan 8cb43c088c2a6b24 authored for this engagement | document-review Vulnerability management platform · quarterly internal scans Q3 FY26 scan and rescan | 2026-06-22 00fd27bb4e8b signed at capture | 4→4 corroborated independently | AcceptedCorroborated, second source SA-2210 · 2026-07-28 13:16Z |
11.3.1.1 All other applicable vulnerabilities are managed and rescans are performed as needed | cr-pci-11-3-1-1-internal-scan-cadence@2.5.0 plan 8cb43c088c2a6b24 authored for this engagement | document-review Vulnerability management platform · quarterly internal scans Q4 FY26 scan · interim | 2026-07-27 7f72d88fba39 signed at capture | 4→4 corroborated independently | |
12.5.2 PCI DSS scope is documented and confirmed at least once every 12 months | cr-pci-12-5-2-scope-validation@1.3.0 plan 44caed821ce0aedc authored for this engagement | session-recording Scope validation working session · supervised capture Data-flow walkthrough | 2026-05-21 051a621c2277 signed at capture | single instance | AcceptedIndependently re-performed QSA-04412 · 2026-07-29 09:30Z |
12.5.2 PCI DSS scope is documented and confirmed at least once every 12 months | cr-pci-12-5-2-scope-validation@1.3.0 plan 44caed821ce0aedc authored for this engagement | session-recording Scope validation working session · supervised capture Segmentation confirmation walkthrough | 2026-05-21 ade461c17038 signed at capture | single instance | Accepted with conditionsScope narrowed by note The walkthrough confirms the diagram, but one connected settlement service is described as out of scope without a segmentation test reference. QSA-04412 · 2026-07-29 09:52Z |
12.10.1 Incident response plan exists and is ready to be activated | cf-pci-12-10-1-ir-plan-currency@1.0.0 plan 55afe88a7f5304b6 published in the registry | document-review Incident response plan · responder cohort of 19 FY26 responder cohort completion | 2026-04-30 f25a01120580 signed at capture | 19→19 corroborated independently |
1.2.8
2026-01-14
Configuration files for NSCs are secured and kept consistent with active network configurations
cr-pci-1-2-8-nsc-ruleset-review@3.2.0
8→8
QSA-04412 · 2026-07-14 09:12Z
1.2.8
2026-07-09
Configuration files for NSCs are secured and kept consistent with active network configurations
cr-pci-1-2-8-nsc-ruleset-review@3.2.0
8→8
QSA-04412 · 2026-07-14 09:26Z
3.5.1.2
2026-06-18
Disk-level encryption is only used on removable media, or is combined with another mechanism
cr-pci-3-5-1-2-pan-storage-encryption@1.4.1
single instance
Column-level protection is evidenced in the console, but the key-management procedure document it relies on is not referenced from the artifact.
QSA-07731 · 2026-07-15 14:05Z
6.3.3
2025-11-04
All system components are protected from known vulnerabilities by installing applicable security patches
cr-pci-6-3-3-patch-sla-conformance@2.0.3
Dashboard tile count is not corroborated through an independent path and no record-ID list was captured.
QSA-04412 · 2026-07-16 10:41Z
6.3.3
2025-12-03
All system components are protected from known vulnerabilities by installing applicable security patches
cr-pci-6-3-3-patch-sla-conformance@2.0.3
Same defect as the October window. Re-collection requested with an enumerated finding list.
QSA-04412 · 2026-07-16 10:44Z
6.3.3
2026-01-06
All system components are protected from known vulnerabilities by installing applicable security patches
cr-pci-6-3-3-patch-sla-conformance@2.0.3
The artifact shows a filtered view, not the complete set of critical findings for the window.
QSA-04412 · 2026-07-16 10:52Z
6.3.3
2026-02-04
All system components are protected from known vulnerabilities by installing applicable security patches
cr-pci-6-3-3-patch-sla-conformance@2.0.3
Accepted on the strength of the exception register; the selection method for the reviewed items is not reproducible.
QSA-07731 · 2026-07-17 08:30Z
6.3.3
2026-03-04
All system components are protected from known vulnerabilities by installing applicable security patches
cr-pci-6-3-3-patch-sla-conformance@2.0.3
QSA-07731 · 2026-07-17 08:41Z
6.3.3
2026-04-07
All system components are protected from known vulnerabilities by installing applicable security patches
cr-pci-6-3-3-patch-sla-conformance@2.0.3
QSA-07731 · 2026-07-17 08:49Z
6.3.3
2026-05-05
All system components are protected from known vulnerabilities by installing applicable security patches
cr-pci-6-3-3-patch-sla-conformance@2.0.3
QSA-07731 · 2026-07-17 08:55Z
6.3.3
2026-06-03
All system components are protected from known vulnerabilities by installing applicable security patches
cr-pci-6-3-3-patch-sla-conformance@2.0.3
7.2.4
2025-12-19
All user accounts and related access privileges are reviewed at least once every six months
cr-pci-7-2-4-privileged-access-review@4.1.0
412→25
QSA-04412 · 2026-07-20 11:02Z
7.2.4
2026-03-20
All user accounts and related access privileges are reviewed at least once every six months
cr-pci-7-2-4-privileged-access-review@4.1.0
412→25
QSA-04412 · 2026-07-20 11:19Z
7.2.4
2026-06-19
All user accounts and related access privileges are reviewed at least once every six months
cr-pci-7-2-4-privileged-access-review@4.1.0
412→25
Reviewer decisions carry timestamps nine days after the campaign close date recorded in the artifact.
QSA-04412 · 2026-07-20 11:33Z
7.2.4
2026-07-02
All user accounts and related access privileges are reviewed at least once every six months
cr-pci-7-2-4-privileged-access-review@4.1.0
412→25
QSA-04412 · 2026-07-24 15:10Z
7.2.4
2026-07-24
All user accounts and related access privileges are reviewed at least once every six months
cr-pci-7-2-4-privileged-access-review@4.1.0
412→25
8.2.4
2026-01-09
Addition, deletion, and modification of user IDs is managed through a formal process
cr-pci-8-2-4-account-lifecycle@2.2.0
96→15
SA-2210 · 2026-07-21 09:40Z
8.2.4
2026-04-08
Addition, deletion, and modification of user IDs is managed through a formal process
cr-pci-8-2-4-account-lifecycle@2.2.0
96→15
SA-2210 · 2026-07-21 09:52Z
8.2.4
2026-07-08
Addition, deletion, and modification of user IDs is managed through a formal process
cr-pci-8-2-4-account-lifecycle@2.2.0
96→15
The delta of one against the HR register is explained in writing and approved; the corroboration path remains single-source.
QSA-07731 · 2026-07-21 10:15Z
8.2.4
2026-07-08
Addition, deletion, and modification of user IDs is managed through a formal process
cr-pci-8-2-4-account-lifecycle@2.2.0
96→15
SA-2210 · 2026-07-21 10:28Z
8.3.6
2026-07-10
Minimum password/passphrase strength for in-scope accounts
cf-pci-8-3-6-auth-parameters@1.4.0
2→2
QSA-04412 · 2026-07-22 13:04Z
8.3.6
2026-07-10
Minimum password/passphrase strength for in-scope accounts
cf-pci-8-3-6-auth-parameters@1.4.0
2→2
QSA-04412 · 2026-07-22 13:11Z
8.4.2
2026-07-11
MFA is implemented for all access into the cardholder data environment
cr-pci-8-4-2-mfa-all-cde-access@3.0.1
3→3
QSA-04412 · 2026-07-22 13:40Z
8.4.2
2026-07-11
MFA is implemented for all access into the cardholder data environment
cr-pci-8-4-2-mfa-all-cde-access@3.0.1
3→3
QSA-04412 · 2026-07-22 13:48Z
8.4.2
2026-07-13
MFA is implemented for all access into the cardholder data environment
cr-pci-8-4-2-mfa-all-cde-access@3.0.1
3→3
9.4.1
2026-01-22
All media with cardholder data is physically secured and inventoried
cr-pci-9-4-1-media-inventory@1.2.0
34→10
QSA-07731 · 2026-07-30 15:05Z
9.4.1
2026-01-23
All media with cardholder data is physically secured and inventoried
cr-pci-9-4-1-media-inventory@1.2.0
34→10
QSA-07731 · 2026-07-30 15:22Z
9.4.1
2026-07-21
All media with cardholder data is physically secured and inventoried
cr-pci-9-4-1-media-inventory@1.2.0
34→10
9.4.1
2026-07-22
All media with cardholder data is physically secured and inventoried
cr-pci-9-4-1-media-inventory@1.2.0
34→10
10.2.1.1
2025-12-30
Audit logs capture all individual user access to cardholder data
cr-pci-10-2-1-1-audit-log-coverage@1.9.0
61→12
SA-2210 · 2026-07-23 09:05Z
10.2.1.1
2026-03-31
Audit logs capture all individual user access to cardholder data
cr-pci-10-2-1-1-audit-log-coverage@1.9.0
61→12
SA-2210 · 2026-07-23 09:17Z
10.2.1.1
2026-06-30
Audit logs capture all individual user access to cardholder data
cr-pci-10-2-1-1-audit-log-coverage@1.9.0
61→12
Two in-scope hosts show no events for 41 days inside the period; the assertion is made against a filtered view rather than the enumerated component list.
QSA-04412 · 2026-07-23 09:44Z
10.2.1.1
2026-07-17
Audit logs capture all individual user access to cardholder data
cr-pci-10-2-1-1-audit-log-coverage@1.9.0
61→12
QSA-04412 · 2026-07-28 10:02Z
10.4.1
2026-06-25
Audit logs are reviewed at least once daily
cf-pci-10-4-1-daily-log-review@2.1.0
34→34
SA-2210 · 2026-07-24 14:20Z
10.4.1
2026-06-25
Audit logs are reviewed at least once daily
cf-pci-10-4-1-daily-log-review@2.1.0
34→34
SA-2210 · 2026-07-24 14:29Z
10.7.2
2026-07-15
Failures of critical security control systems are detected, alerted, and addressed promptly
cr-pci-10-7-2-log-failure-detection@1.1.2
single instance
QSA-07731 · 2026-07-27 11:15Z
10.7.2
2026-07-15
Failures of critical security control systems are detected, alerted, and addressed promptly
cr-pci-10-7-2-log-failure-detection@1.1.2
single instance
QSA-07731 · 2026-07-27 11:31Z
11.6.1
2026-04-30
Change- and tamper-detection mechanism on payment pages
cf-pci-11-6-1-change-detection@1.2.0
6→6
SA-2210 · 2026-07-29 14:02Z
11.6.1
2026-07-28
Change- and tamper-detection mechanism on payment pages
cf-pci-11-6-1-change-detection@1.2.0
6→6
11.3.1.1
2025-12-22
All other applicable vulnerabilities are managed and rescans are performed as needed
cr-pci-11-3-1-1-internal-scan-cadence@2.5.0
4→4
SA-2210 · 2026-07-28 13:02Z
11.3.1.1
2026-03-23
All other applicable vulnerabilities are managed and rescans are performed as needed
cr-pci-11-3-1-1-internal-scan-cadence@2.5.0
4→4
SA-2210 · 2026-07-28 13:09Z
11.3.1.1
2026-06-22
All other applicable vulnerabilities are managed and rescans are performed as needed
cr-pci-11-3-1-1-internal-scan-cadence@2.5.0
4→4
SA-2210 · 2026-07-28 13:16Z
11.3.1.1
2026-07-27
All other applicable vulnerabilities are managed and rescans are performed as needed
cr-pci-11-3-1-1-internal-scan-cadence@2.5.0
4→4
12.5.2
2026-05-21
PCI DSS scope is documented and confirmed at least once every 12 months
cr-pci-12-5-2-scope-validation@1.3.0
single instance
QSA-04412 · 2026-07-29 09:30Z
12.5.2
2026-05-21
PCI DSS scope is documented and confirmed at least once every 12 months
cr-pci-12-5-2-scope-validation@1.3.0
single instance
The walkthrough confirms the diagram, but one connected settlement service is described as out of scope without a segmentation test reference.
QSA-04412 · 2026-07-29 09:52Z
12.10.1
2026-04-30
Incident response plan exists and is ready to be activated
cf-pci-12-10-1-ir-plan-currency@1.0.0
19→19
38 of 46 rows carry a verdict
The deliverable leaves in the firm’s shape, not the platform’s: a workpaper index of control, procedure at version, evidence reference, verdict, reason code, tester, and date — sealed with a digest computed over the index itself.
8 items still awaiting a verdict will appear in the index as open.