Synthetic browser-local workpaper

This index is assembled from fictional reference data and browser-local verdicts. Its browser-computed digest is not a tenant ledger receipt and no row contributes to a method-performance corpus.

Calloway & Reyes LLP · ENG-2026-0418

Workpaper index

Meridian Health Plan · PCI DSS 4.0.1 · period 2025-10-01 to 2026-09-30

46

indexed rows

38 adjudicated · 8 open

Back to the adjudication queue

Engagement particulars

Prepared 2026-08-05

Assessor firm

Calloway & Reyes LLPQualified Security Assessor Company

Lead assessor and testers

QSA-04412QSA-04412, QSA-07731, SA-2210

Period of coverage

2025-10-012026-09-30Fieldwork opened 2026-07-06

Methods performed

15 procedures, 4 from the shared registryNo model output carries a verdict. Every conclusion in this index was recorded by a named tester against a versioned procedure.

Index of procedures performed

46 rows · 15 requirements

RefControlProcedure performedEvidence referenceResultBasisTester / date
001

1.2.8

Configuration files for NSCs are secured and kept consistent with active network configurations

cr-pci-1-2-8-nsc-ruleset-review@3.2.0

plan 790698f49c80ea85

H1 FY26 · ruleset export

754349f0e6a97e27

captured 2026-01-14

Accepted

Population reconciled

Enumerated population tied to an independent count with a zero or explained delta.

QSA-04412

2026-07-14

002

1.2.8

Configuration files for NSCs are secured and kept consistent with active network configurations

cr-pci-1-2-8-nsc-ruleset-review@3.2.0

plan 790698f49c80ea85

H2 FY26 · ruleset export

6ae494fd035e0787

captured 2026-07-09

Accepted

Population reconciled

Enumerated population tied to an independent count with a zero or explained delta.

QSA-04412

2026-07-14

003

3.5.1.2

Disk-level encryption is only used on removable media, or is combined with another mechanism

cr-pci-3-5-1-2-pan-storage-encryption@1.4.1

plan 322f76c38fe4bb66

FY26 annual attestation

365f551b50f272c4

captured 2026-06-18

Accepted with conditions

Column-level protection is evidenced in the console, but the key-management procedure document it relies on is not referenced from the artifact.

Management response pending

Artifact accepted; a deviation it exposed awaits a management response.

QSA-07731

2026-07-15

004

6.3.3

All system components are protected from known vulnerabilities by installing applicable security patches

cr-pci-6-3-3-patch-sla-conformance@2.0.3

plan 0effc17ab4ce1e42

Oct 2025 remediation window

69a2def4339288dc

captured 2025-11-04

Rejected

Dashboard tile count is not corroborated through an independent path and no record-ID list was captured.

No independent corroboration

Single-source count with no second path to confirm the population.

QSA-04412

2026-07-16

005

6.3.3

All system components are protected from known vulnerabilities by installing applicable security patches

cr-pci-6-3-3-patch-sla-conformance@2.0.3

plan 0effc17ab4ce1e42

Nov 2025 remediation window

97f95595d117e5fa

captured 2025-12-03

Rejected

Same defect as the October window. Re-collection requested with an enumerated finding list.

No independent corroboration

Single-source count with no second path to confirm the population.

QSA-04412

2026-07-16

006

6.3.3

All system components are protected from known vulnerabilities by installing applicable security patches

cr-pci-6-3-3-patch-sla-conformance@2.0.3

plan 0effc17ab4ce1e42

Dec 2025 remediation window

f8bee1bde9a0501e

captured 2026-01-06

Rejected

The artifact shows a filtered view, not the complete set of critical findings for the window.

Insufficient population

No enumerated population, or a population that cannot be shown to be complete.

QSA-04412

2026-07-16

007

6.3.3

All system components are protected from known vulnerabilities by installing applicable security patches

cr-pci-6-3-3-patch-sla-conformance@2.0.3

plan 0effc17ab4ce1e42

Jan 2026 remediation window

10c35ed364ec43a7

captured 2026-02-04

Accepted with conditions

Accepted on the strength of the exception register; the selection method for the reviewed items is not reproducible.

Sample extension required

Accepted on condition the sample is extended before the opinion is signed.

QSA-07731

2026-07-17

008

6.3.3

All system components are protected from known vulnerabilities by installing applicable security patches

cr-pci-6-3-3-patch-sla-conformance@2.0.3

plan 0effc17ab4ce1e42

Feb 2026 remediation window

3892e4de85d8818e

captured 2026-03-04

Accepted

Corroborated, second source

A second system path produced a consistent count or record set.

QSA-07731

2026-07-17

009

6.3.3

All system components are protected from known vulnerabilities by installing applicable security patches

cr-pci-6-3-3-patch-sla-conformance@2.0.3

plan 0effc17ab4ce1e42

Mar 2026 remediation window

e48823323db5a8e9

captured 2026-04-07

Accepted

Corroborated, second source

A second system path produced a consistent count or record set.

QSA-07731

2026-07-17

010

6.3.3

All system components are protected from known vulnerabilities by installing applicable security patches

cr-pci-6-3-3-patch-sla-conformance@2.0.3

plan 0effc17ab4ce1e42

Apr 2026 remediation window

ef37999e80c2cb70

captured 2026-05-05

Accepted

Corroborated, second source

A second system path produced a consistent count or record set.

QSA-07731

2026-07-17

011

6.3.3

All system components are protected from known vulnerabilities by installing applicable security patches

cr-pci-6-3-3-patch-sla-conformance@2.0.3

plan 0effc17ab4ce1e42

May 2026 remediation window

e73b200084aebaea

captured 2026-06-03

Open — awaiting verdict

012

7.2.4

All user accounts and related access privileges are reviewed at least once every six months

cr-pci-7-2-4-privileged-access-review@4.1.0

plan d94250ab90fd8521

Q1 FY26 · Dec 2025 review

a80ebe9fd5f2699f

captured 2025-12-19

Accepted

Population reconciled

Enumerated population tied to an independent count with a zero or explained delta.

QSA-04412

2026-07-20

013

7.2.4

All user accounts and related access privileges are reviewed at least once every six months

cr-pci-7-2-4-privileged-access-review@4.1.0

plan d94250ab90fd8521

Q2 FY26 · Mar 2026 review

7eb4ddb3521cf65a

captured 2026-03-20

Accepted

Population reconciled

Enumerated population tied to an independent count with a zero or explained delta.

QSA-04412

2026-07-20

014

7.2.4

All user accounts and related access privileges are reviewed at least once every six months

cr-pci-7-2-4-privileged-access-review@4.1.0

plan d94250ab90fd8521

Q3 FY26 · Jun 2026 review

2679b5cffc871def

captured 2026-06-19

Rejected

Reviewer decisions carry timestamps nine days after the campaign close date recorded in the artifact.

Stale evidence

Captured outside the assessment period or beyond the freshness window.

QSA-04412

2026-07-20

015

7.2.4

All user accounts and related access privileges are reviewed at least once every six months

cr-pci-7-2-4-privileged-access-review@4.1.0

plan d94250ab90fd8521

Q3 FY26 · remediation re-test

9cd29f898c2672f6

captured 2026-07-02

Accepted

Independently re-performed

Assessor re-ran the procedure and obtained a matching result.

QSA-04412

2026-07-24

016

7.2.4

All user accounts and related access privileges are reviewed at least once every six months

cr-pci-7-2-4-privileged-access-review@4.1.0

plan d94250ab90fd8521

Q4 FY26 · Jul 2026 interim

838f79f720be7c1c

captured 2026-07-24

Open — awaiting verdict

017

8.2.4

Addition, deletion, and modification of user IDs is managed through a formal process

cr-pci-8-2-4-account-lifecycle@2.2.0

plan 731548f4bcd73451

Q1 FY26 · leaver cohort

a6c0ce1612107355

captured 2026-01-09

Accepted

Population reconciled

Enumerated population tied to an independent count with a zero or explained delta.

SA-2210

2026-07-21

018

8.2.4

Addition, deletion, and modification of user IDs is managed through a formal process

cr-pci-8-2-4-account-lifecycle@2.2.0

plan 731548f4bcd73451

Q2 FY26 · leaver cohort

4b5e5e64d9c77d39

captured 2026-04-08

Accepted

Population reconciled

Enumerated population tied to an independent count with a zero or explained delta.

SA-2210

2026-07-21

019

8.2.4

Addition, deletion, and modification of user IDs is managed through a formal process

cr-pci-8-2-4-account-lifecycle@2.2.0

plan 731548f4bcd73451

Q3 FY26 · leaver cohort

078f3afdea8a329b

captured 2026-07-08

Accepted with conditions

The delta of one against the HR register is explained in writing and approved; the corroboration path remains single-source.

Sample extension required

Accepted on condition the sample is extended before the opinion is signed.

QSA-07731

2026-07-21

020

8.2.4

Addition, deletion, and modification of user IDs is managed through a formal process

cr-pci-8-2-4-account-lifecycle@2.2.0

plan 731548f4bcd73451

Q3 FY26 · joiner cohort

86572ce369f77809

captured 2026-07-08

Accepted

Population reconciled

Enumerated population tied to an independent count with a zero or explained delta.

SA-2210

2026-07-21

021

8.3.6

Minimum password/passphrase strength for in-scope accounts

cf-pci-8-3-6-auth-parameters@1.4.0

plan 5d0f70b14cafda38

Primary identity provider realm

eee7628db1be23a3

captured 2026-07-10

Accepted

Accepted as designed

Design-effectiveness conclusion only; no operating population required at this stage.

QSA-04412

2026-07-22

022

8.3.6

Minimum password/passphrase strength for in-scope accounts

cf-pci-8-3-6-auth-parameters@1.4.0

plan 5d0f70b14cafda38

Break-glass local realm · bastion

c9c36221fadb876c

captured 2026-07-10

Accepted

Accepted as designed

Design-effectiveness conclusion only; no operating population required at this stage.

QSA-04412

2026-07-22

023

8.4.2

MFA is implemented for all access into the cardholder data environment

cr-pci-8-4-2-mfa-all-cde-access@3.0.1

plan dc4cc5256ff79265

Access path · VPN

5913d22f60f72ebc

captured 2026-07-11

Accepted

Independently re-performed

Assessor re-ran the procedure and obtained a matching result.

QSA-04412

2026-07-22

024

8.4.2

MFA is implemented for all access into the cardholder data environment

cr-pci-8-4-2-mfa-all-cde-access@3.0.1

plan dc4cc5256ff79265

Access path · SSH bastion

65881fa79a1992bb

captured 2026-07-11

Accepted

Independently re-performed

Assessor re-ran the procedure and obtained a matching result.

QSA-04412

2026-07-22

025

8.4.2

MFA is implemented for all access into the cardholder data environment

cr-pci-8-4-2-mfa-all-cde-access@3.0.1

plan dc4cc5256ff79265

Access path · cloud console

19804a5cc1b61c4c

captured 2026-07-13

Open — awaiting verdict

026

9.4.1

All media with cardholder data is physically secured and inventoried

cr-pci-9-4-1-media-inventory@1.2.0

plan bccd43d9b1f453a2

H1 FY26 · media room walk

e35548f1e32f5f79

captured 2026-01-22

Accepted

Independently re-performed

Assessor re-ran the procedure and obtained a matching result.

QSA-07731

2026-07-30

027

9.4.1

All media with cardholder data is physically secured and inventoried

cr-pci-9-4-1-media-inventory@1.2.0

plan bccd43d9b1f453a2

H1 FY26 · vault reconciliation

e03ca953d16694fe

captured 2026-01-23

Accepted

Corroborated, second source

A second system path produced a consistent count or record set.

QSA-07731

2026-07-30

028

9.4.1

All media with cardholder data is physically secured and inventoried

cr-pci-9-4-1-media-inventory@1.2.0

plan bccd43d9b1f453a2

H2 FY26 · media room walk

7ab148671e7f6888

captured 2026-07-21

Open — awaiting verdict

029

9.4.1

All media with cardholder data is physically secured and inventoried

cr-pci-9-4-1-media-inventory@1.2.0

plan bccd43d9b1f453a2

H2 FY26 · vault reconciliation

719cb317164891a7

captured 2026-07-22

Open — awaiting verdict

030

10.2.1.1

Audit logs capture all individual user access to cardholder data

cr-pci-10-2-1-1-audit-log-coverage@1.9.0

plan cf4b3493a67ffebc

Q1 FY26 coverage check

db350ba6cc6d475e

captured 2025-12-30

Accepted

Population reconciled

Enumerated population tied to an independent count with a zero or explained delta.

SA-2210

2026-07-23

031

10.2.1.1

Audit logs capture all individual user access to cardholder data

cr-pci-10-2-1-1-audit-log-coverage@1.9.0

plan cf4b3493a67ffebc

Q2 FY26 coverage check

1fe87c25bd44e845

captured 2026-03-31

Accepted

Population reconciled

Enumerated population tied to an independent count with a zero or explained delta.

SA-2210

2026-07-23

032

10.2.1.1

Audit logs capture all individual user access to cardholder data

cr-pci-10-2-1-1-audit-log-coverage@1.9.0

plan cf4b3493a67ffebc

Q3 FY26 coverage check

e54ef9dc219faf6d

captured 2026-06-30

Rejected

Two in-scope hosts show no events for 41 days inside the period; the assertion is made against a filtered view rather than the enumerated component list.

Insufficient population

No enumerated population, or a population that cannot be shown to be complete.

QSA-04412

2026-07-23

033

10.2.1.1

Audit logs capture all individual user access to cardholder data

cr-pci-10-2-1-1-audit-log-coverage@1.9.0

plan cf4b3493a67ffebc

Q3 FY26 gap re-test

4728d9a9832aa37e

captured 2026-07-17

Accepted

Population reconciled

Enumerated population tied to an independent count with a zero or explained delta.

QSA-04412

2026-07-28

034

10.4.1

Audit logs are reviewed at least once daily

cf-pci-10-4-1-daily-log-review@2.1.0

plan d10a945ff9d5f53a

Correlation search inventory

9651f6c82e914160

captured 2026-06-25

Accepted

Accepted as designed

Design-effectiveness conclusion only; no operating population required at this stage.

SA-2210

2026-07-24

035

10.4.1

Audit logs are reviewed at least once daily

cf-pci-10-4-1-daily-log-review@2.1.0

plan d10a945ff9d5f53a

Notable-event routing configuration

6ec6d33e5086c3d0

captured 2026-06-25

Accepted

Accepted as designed

Design-effectiveness conclusion only; no operating population required at this stage.

SA-2210

2026-07-24

036

10.7.2

Failures of critical security control systems are detected, alerted, and addressed promptly

cr-pci-10-7-2-log-failure-detection@1.1.2

plan 73be709f1aee1e07

Alert configuration

85ae08706b8633ad

captured 2026-07-15

Accepted

Independently re-performed

Assessor re-ran the procedure and obtained a matching result.

QSA-07731

2026-07-27

037

10.7.2

Failures of critical security control systems are detected, alerted, and addressed promptly

cr-pci-10-7-2-log-failure-detection@1.1.2

plan 73be709f1aee1e07

Induced failure test

48ad3a3228e9f59e

captured 2026-07-15

Accepted

Independently re-performed

Assessor re-ran the procedure and obtained a matching result.

QSA-07731

2026-07-27

038

11.3.1.1

All other applicable vulnerabilities are managed and rescans are performed as needed

cr-pci-11-3-1-1-internal-scan-cadence@2.5.0

plan 8cb43c088c2a6b24

Q1 FY26 scan and rescan

8ab6dd52c5afa632

captured 2025-12-22

Accepted

Corroborated, second source

A second system path produced a consistent count or record set.

SA-2210

2026-07-28

039

11.3.1.1

All other applicable vulnerabilities are managed and rescans are performed as needed

cr-pci-11-3-1-1-internal-scan-cadence@2.5.0

plan 8cb43c088c2a6b24

Q2 FY26 scan and rescan

cb4d550b05818065

captured 2026-03-23

Accepted

Corroborated, second source

A second system path produced a consistent count or record set.

SA-2210

2026-07-28

040

11.3.1.1

All other applicable vulnerabilities are managed and rescans are performed as needed

cr-pci-11-3-1-1-internal-scan-cadence@2.5.0

plan 8cb43c088c2a6b24

Q3 FY26 scan and rescan

00fd27bb4e8b906b

captured 2026-06-22

Accepted

Corroborated, second source

A second system path produced a consistent count or record set.

SA-2210

2026-07-28

041

11.3.1.1

All other applicable vulnerabilities are managed and rescans are performed as needed

cr-pci-11-3-1-1-internal-scan-cadence@2.5.0

plan 8cb43c088c2a6b24

Q4 FY26 scan · interim

7f72d88fba39c19f

captured 2026-07-27

Open — awaiting verdict

042

11.6.1

Change- and tamper-detection mechanism on payment pages

cf-pci-11-6-1-change-detection@1.2.0

plan fa6c14222a531b65

Q2 FY26 payment page baseline

28db0b41aa0c9f25

captured 2026-04-30

Accepted

Population reconciled

Enumerated population tied to an independent count with a zero or explained delta.

SA-2210

2026-07-29

043

11.6.1

Change- and tamper-detection mechanism on payment pages

cf-pci-11-6-1-change-detection@1.2.0

plan fa6c14222a531b65

Q3 FY26 payment page baseline

d953e12d60bd2a92

captured 2026-07-28

Open — awaiting verdict

044

12.5.2

PCI DSS scope is documented and confirmed at least once every 12 months

cr-pci-12-5-2-scope-validation@1.3.0

plan 44caed821ce0aedc

Data-flow walkthrough

051a621c2277ab50

captured 2026-05-21

Accepted

Independently re-performed

Assessor re-ran the procedure and obtained a matching result.

QSA-04412

2026-07-29

045

12.5.2

PCI DSS scope is documented and confirmed at least once every 12 months

cr-pci-12-5-2-scope-validation@1.3.0

plan 44caed821ce0aedc

Segmentation confirmation walkthrough

ade461c170380e93

captured 2026-05-21

Accepted with conditions

The walkthrough confirms the diagram, but one connected settlement service is described as out of scope without a segmentation test reference.

Scope narrowed by note

Accepted for the named subset only; remainder carried to a separate request.

QSA-04412

2026-07-29

046

12.10.1

Incident response plan exists and is ready to be activated

cf-pci-12-10-1-ir-plan-currency@1.0.0

plan 55afe88a7f5304b6

FY26 responder cohort completion

f25a011205802320

captured 2026-04-30

Open — awaiting verdict

Exception register

5 rejected · 4 accepted with conditions

ControlBasisWhat the code assertsAssessor noteDisposition
3.5.1.2Management response pendingArtifact accepted; a deviation it exposed awaits a management response.Column-level protection is evidenced in the console, but the key-management procedure document it relies on is not referenced from the artifact.Accepted with conditionsQSA-07731 · 2026-07-15
6.3.3No independent corroborationSingle-source count with no second path to confirm the population.Dashboard tile count is not corroborated through an independent path and no record-ID list was captured.RejectedQSA-04412 · 2026-07-16
6.3.3No independent corroborationSingle-source count with no second path to confirm the population.Same defect as the October window. Re-collection requested with an enumerated finding list.RejectedQSA-04412 · 2026-07-16
6.3.3Insufficient populationNo enumerated population, or a population that cannot be shown to be complete.The artifact shows a filtered view, not the complete set of critical findings for the window.RejectedQSA-04412 · 2026-07-16
6.3.3Sample extension requiredAccepted on condition the sample is extended before the opinion is signed.Accepted on the strength of the exception register; the selection method for the reviewed items is not reproducible.Accepted with conditionsQSA-07731 · 2026-07-17
7.2.4Stale evidenceCaptured outside the assessment period or beyond the freshness window.Reviewer decisions carry timestamps nine days after the campaign close date recorded in the artifact.RejectedQSA-04412 · 2026-07-20
8.2.4Sample extension requiredAccepted on condition the sample is extended before the opinion is signed.The delta of one against the HR register is explained in writing and approved; the corroboration path remains single-source.Accepted with conditionsQSA-07731 · 2026-07-21
10.2.1.1Insufficient populationNo enumerated population, or a population that cannot be shown to be complete.Two in-scope hosts show no events for 41 days inside the period; the assertion is made against a filtered view rather than the enumerated component list.RejectedQSA-04412 · 2026-07-23
12.5.2Scope narrowed by noteAccepted for the named subset only; remainder carried to a separate request.The walkthrough confirms the diagram, but one connected settlement service is described as out of scope without a segmentation test reference.Accepted with conditionsQSA-04412 · 2026-07-29

Attestation

Index seal · 2026-08-05

The procedures listed in this index were performed under the direction of QSA-04412 of Calloway & Reyes LLP for the period 2025-10-01 to 2026-09-30. Each result is the assessor’s own conclusion; platform-collected artifacts were accepted, accepted with conditions, or rejected on the reason codes shown.

The seal is a SHA-256 over the canonicalized index — every row’s control, procedure at version, evidence reference, result, reason code, tester, and date. Change one verdict and the fingerprint changes, which is what makes this index a record rather than a report.

SEALING00000000
Synthetic Workpaper Index | ControlFrame