Synthetic browser-local workpaper
This index is assembled from fictional reference data and browser-local verdicts. Its browser-computed digest is not a tenant ledger receipt and no row contributes to a method-performance corpus.
Calloway & Reyes LLP · ENG-2026-0418
Workpaper index
Meridian Health Plan · PCI DSS 4.0.1 · period 2025-10-01 to 2026-09-30
46
indexed rows
38 adjudicated · 8 open
Engagement particulars
Prepared 2026-08-05
Assessor firm
Lead assessor and testers
Period of coverage
Methods performed
Index of procedures performed
46 rows · 15 requirements
| Ref | Control | Procedure performed | Evidence reference | Result | Basis | Tester / date |
|---|---|---|---|---|---|---|
| 001 | 1.2.8 Configuration files for NSCs are secured and kept consistent with active network configurations | cr-pci-1-2-8-nsc-ruleset-review@3.2.0 plan 790698f49c80ea85 H1 FY26 · ruleset export | 754349f0e6a97e27 captured 2026-01-14 | Accepted | Population reconciled Enumerated population tied to an independent count with a zero or explained delta. | QSA-04412 2026-07-14 |
| 002 | 1.2.8 Configuration files for NSCs are secured and kept consistent with active network configurations | cr-pci-1-2-8-nsc-ruleset-review@3.2.0 plan 790698f49c80ea85 H2 FY26 · ruleset export | 6ae494fd035e0787 captured 2026-07-09 | Accepted | Population reconciled Enumerated population tied to an independent count with a zero or explained delta. | QSA-04412 2026-07-14 |
| 003 | 3.5.1.2 Disk-level encryption is only used on removable media, or is combined with another mechanism | cr-pci-3-5-1-2-pan-storage-encryption@1.4.1 plan 322f76c38fe4bb66 FY26 annual attestation | 365f551b50f272c4 captured 2026-06-18 | Accepted with conditions Column-level protection is evidenced in the console, but the key-management procedure document it relies on is not referenced from the artifact. | Management response pending Artifact accepted; a deviation it exposed awaits a management response. | QSA-07731 2026-07-15 |
| 004 | 6.3.3 All system components are protected from known vulnerabilities by installing applicable security patches | cr-pci-6-3-3-patch-sla-conformance@2.0.3 plan 0effc17ab4ce1e42 Oct 2025 remediation window | 69a2def4339288dc captured 2025-11-04 | Rejected Dashboard tile count is not corroborated through an independent path and no record-ID list was captured. | No independent corroboration Single-source count with no second path to confirm the population. | QSA-04412 2026-07-16 |
| 005 | 6.3.3 All system components are protected from known vulnerabilities by installing applicable security patches | cr-pci-6-3-3-patch-sla-conformance@2.0.3 plan 0effc17ab4ce1e42 Nov 2025 remediation window | 97f95595d117e5fa captured 2025-12-03 | Rejected Same defect as the October window. Re-collection requested with an enumerated finding list. | No independent corroboration Single-source count with no second path to confirm the population. | QSA-04412 2026-07-16 |
| 006 | 6.3.3 All system components are protected from known vulnerabilities by installing applicable security patches | cr-pci-6-3-3-patch-sla-conformance@2.0.3 plan 0effc17ab4ce1e42 Dec 2025 remediation window | f8bee1bde9a0501e captured 2026-01-06 | Rejected The artifact shows a filtered view, not the complete set of critical findings for the window. | Insufficient population No enumerated population, or a population that cannot be shown to be complete. | QSA-04412 2026-07-16 |
| 007 | 6.3.3 All system components are protected from known vulnerabilities by installing applicable security patches | cr-pci-6-3-3-patch-sla-conformance@2.0.3 plan 0effc17ab4ce1e42 Jan 2026 remediation window | 10c35ed364ec43a7 captured 2026-02-04 | Accepted with conditions Accepted on the strength of the exception register; the selection method for the reviewed items is not reproducible. | Sample extension required Accepted on condition the sample is extended before the opinion is signed. | QSA-07731 2026-07-17 |
| 008 | 6.3.3 All system components are protected from known vulnerabilities by installing applicable security patches | cr-pci-6-3-3-patch-sla-conformance@2.0.3 plan 0effc17ab4ce1e42 Feb 2026 remediation window | 3892e4de85d8818e captured 2026-03-04 | Accepted | Corroborated, second source A second system path produced a consistent count or record set. | QSA-07731 2026-07-17 |
| 009 | 6.3.3 All system components are protected from known vulnerabilities by installing applicable security patches | cr-pci-6-3-3-patch-sla-conformance@2.0.3 plan 0effc17ab4ce1e42 Mar 2026 remediation window | e48823323db5a8e9 captured 2026-04-07 | Accepted | Corroborated, second source A second system path produced a consistent count or record set. | QSA-07731 2026-07-17 |
| 010 | 6.3.3 All system components are protected from known vulnerabilities by installing applicable security patches | cr-pci-6-3-3-patch-sla-conformance@2.0.3 plan 0effc17ab4ce1e42 Apr 2026 remediation window | ef37999e80c2cb70 captured 2026-05-05 | Accepted | Corroborated, second source A second system path produced a consistent count or record set. | QSA-07731 2026-07-17 |
| 011 | 6.3.3 All system components are protected from known vulnerabilities by installing applicable security patches | cr-pci-6-3-3-patch-sla-conformance@2.0.3 plan 0effc17ab4ce1e42 May 2026 remediation window | e73b200084aebaea captured 2026-06-03 | Open — awaiting verdict | — | — — |
| 012 | 7.2.4 All user accounts and related access privileges are reviewed at least once every six months | cr-pci-7-2-4-privileged-access-review@4.1.0 plan d94250ab90fd8521 Q1 FY26 · Dec 2025 review | a80ebe9fd5f2699f captured 2025-12-19 | Accepted | Population reconciled Enumerated population tied to an independent count with a zero or explained delta. | QSA-04412 2026-07-20 |
| 013 | 7.2.4 All user accounts and related access privileges are reviewed at least once every six months | cr-pci-7-2-4-privileged-access-review@4.1.0 plan d94250ab90fd8521 Q2 FY26 · Mar 2026 review | 7eb4ddb3521cf65a captured 2026-03-20 | Accepted | Population reconciled Enumerated population tied to an independent count with a zero or explained delta. | QSA-04412 2026-07-20 |
| 014 | 7.2.4 All user accounts and related access privileges are reviewed at least once every six months | cr-pci-7-2-4-privileged-access-review@4.1.0 plan d94250ab90fd8521 Q3 FY26 · Jun 2026 review | 2679b5cffc871def captured 2026-06-19 | Rejected Reviewer decisions carry timestamps nine days after the campaign close date recorded in the artifact. | Stale evidence Captured outside the assessment period or beyond the freshness window. | QSA-04412 2026-07-20 |
| 015 | 7.2.4 All user accounts and related access privileges are reviewed at least once every six months | cr-pci-7-2-4-privileged-access-review@4.1.0 plan d94250ab90fd8521 Q3 FY26 · remediation re-test | 9cd29f898c2672f6 captured 2026-07-02 | Accepted | Independently re-performed Assessor re-ran the procedure and obtained a matching result. | QSA-04412 2026-07-24 |
| 016 | 7.2.4 All user accounts and related access privileges are reviewed at least once every six months | cr-pci-7-2-4-privileged-access-review@4.1.0 plan d94250ab90fd8521 Q4 FY26 · Jul 2026 interim | 838f79f720be7c1c captured 2026-07-24 | Open — awaiting verdict | — | — — |
| 017 | 8.2.4 Addition, deletion, and modification of user IDs is managed through a formal process | cr-pci-8-2-4-account-lifecycle@2.2.0 plan 731548f4bcd73451 Q1 FY26 · leaver cohort | a6c0ce1612107355 captured 2026-01-09 | Accepted | Population reconciled Enumerated population tied to an independent count with a zero or explained delta. | SA-2210 2026-07-21 |
| 018 | 8.2.4 Addition, deletion, and modification of user IDs is managed through a formal process | cr-pci-8-2-4-account-lifecycle@2.2.0 plan 731548f4bcd73451 Q2 FY26 · leaver cohort | 4b5e5e64d9c77d39 captured 2026-04-08 | Accepted | Population reconciled Enumerated population tied to an independent count with a zero or explained delta. | SA-2210 2026-07-21 |
| 019 | 8.2.4 Addition, deletion, and modification of user IDs is managed through a formal process | cr-pci-8-2-4-account-lifecycle@2.2.0 plan 731548f4bcd73451 Q3 FY26 · leaver cohort | 078f3afdea8a329b captured 2026-07-08 | Accepted with conditions The delta of one against the HR register is explained in writing and approved; the corroboration path remains single-source. | Sample extension required Accepted on condition the sample is extended before the opinion is signed. | QSA-07731 2026-07-21 |
| 020 | 8.2.4 Addition, deletion, and modification of user IDs is managed through a formal process | cr-pci-8-2-4-account-lifecycle@2.2.0 plan 731548f4bcd73451 Q3 FY26 · joiner cohort | 86572ce369f77809 captured 2026-07-08 | Accepted | Population reconciled Enumerated population tied to an independent count with a zero or explained delta. | SA-2210 2026-07-21 |
| 021 | 8.3.6 Minimum password/passphrase strength for in-scope accounts | cf-pci-8-3-6-auth-parameters@1.4.0 plan 5d0f70b14cafda38 Primary identity provider realm | eee7628db1be23a3 captured 2026-07-10 | Accepted | Accepted as designed Design-effectiveness conclusion only; no operating population required at this stage. | QSA-04412 2026-07-22 |
| 022 | 8.3.6 Minimum password/passphrase strength for in-scope accounts | cf-pci-8-3-6-auth-parameters@1.4.0 plan 5d0f70b14cafda38 Break-glass local realm · bastion | c9c36221fadb876c captured 2026-07-10 | Accepted | Accepted as designed Design-effectiveness conclusion only; no operating population required at this stage. | QSA-04412 2026-07-22 |
| 023 | 8.4.2 MFA is implemented for all access into the cardholder data environment | cr-pci-8-4-2-mfa-all-cde-access@3.0.1 plan dc4cc5256ff79265 Access path · VPN | 5913d22f60f72ebc captured 2026-07-11 | Accepted | Independently re-performed Assessor re-ran the procedure and obtained a matching result. | QSA-04412 2026-07-22 |
| 024 | 8.4.2 MFA is implemented for all access into the cardholder data environment | cr-pci-8-4-2-mfa-all-cde-access@3.0.1 plan dc4cc5256ff79265 Access path · SSH bastion | 65881fa79a1992bb captured 2026-07-11 | Accepted | Independently re-performed Assessor re-ran the procedure and obtained a matching result. | QSA-04412 2026-07-22 |
| 025 | 8.4.2 MFA is implemented for all access into the cardholder data environment | cr-pci-8-4-2-mfa-all-cde-access@3.0.1 plan dc4cc5256ff79265 Access path · cloud console | 19804a5cc1b61c4c captured 2026-07-13 | Open — awaiting verdict | — | — — |
| 026 | 9.4.1 All media with cardholder data is physically secured and inventoried | cr-pci-9-4-1-media-inventory@1.2.0 plan bccd43d9b1f453a2 H1 FY26 · media room walk | e35548f1e32f5f79 captured 2026-01-22 | Accepted | Independently re-performed Assessor re-ran the procedure and obtained a matching result. | QSA-07731 2026-07-30 |
| 027 | 9.4.1 All media with cardholder data is physically secured and inventoried | cr-pci-9-4-1-media-inventory@1.2.0 plan bccd43d9b1f453a2 H1 FY26 · vault reconciliation | e03ca953d16694fe captured 2026-01-23 | Accepted | Corroborated, second source A second system path produced a consistent count or record set. | QSA-07731 2026-07-30 |
| 028 | 9.4.1 All media with cardholder data is physically secured and inventoried | cr-pci-9-4-1-media-inventory@1.2.0 plan bccd43d9b1f453a2 H2 FY26 · media room walk | 7ab148671e7f6888 captured 2026-07-21 | Open — awaiting verdict | — | — — |
| 029 | 9.4.1 All media with cardholder data is physically secured and inventoried | cr-pci-9-4-1-media-inventory@1.2.0 plan bccd43d9b1f453a2 H2 FY26 · vault reconciliation | 719cb317164891a7 captured 2026-07-22 | Open — awaiting verdict | — | — — |
| 030 | 10.2.1.1 Audit logs capture all individual user access to cardholder data | cr-pci-10-2-1-1-audit-log-coverage@1.9.0 plan cf4b3493a67ffebc Q1 FY26 coverage check | db350ba6cc6d475e captured 2025-12-30 | Accepted | Population reconciled Enumerated population tied to an independent count with a zero or explained delta. | SA-2210 2026-07-23 |
| 031 | 10.2.1.1 Audit logs capture all individual user access to cardholder data | cr-pci-10-2-1-1-audit-log-coverage@1.9.0 plan cf4b3493a67ffebc Q2 FY26 coverage check | 1fe87c25bd44e845 captured 2026-03-31 | Accepted | Population reconciled Enumerated population tied to an independent count with a zero or explained delta. | SA-2210 2026-07-23 |
| 032 | 10.2.1.1 Audit logs capture all individual user access to cardholder data | cr-pci-10-2-1-1-audit-log-coverage@1.9.0 plan cf4b3493a67ffebc Q3 FY26 coverage check | e54ef9dc219faf6d captured 2026-06-30 | Rejected Two in-scope hosts show no events for 41 days inside the period; the assertion is made against a filtered view rather than the enumerated component list. | Insufficient population No enumerated population, or a population that cannot be shown to be complete. | QSA-04412 2026-07-23 |
| 033 | 10.2.1.1 Audit logs capture all individual user access to cardholder data | cr-pci-10-2-1-1-audit-log-coverage@1.9.0 plan cf4b3493a67ffebc Q3 FY26 gap re-test | 4728d9a9832aa37e captured 2026-07-17 | Accepted | Population reconciled Enumerated population tied to an independent count with a zero or explained delta. | QSA-04412 2026-07-28 |
| 034 | 10.4.1 Audit logs are reviewed at least once daily | cf-pci-10-4-1-daily-log-review@2.1.0 plan d10a945ff9d5f53a Correlation search inventory | 9651f6c82e914160 captured 2026-06-25 | Accepted | Accepted as designed Design-effectiveness conclusion only; no operating population required at this stage. | SA-2210 2026-07-24 |
| 035 | 10.4.1 Audit logs are reviewed at least once daily | cf-pci-10-4-1-daily-log-review@2.1.0 plan d10a945ff9d5f53a Notable-event routing configuration | 6ec6d33e5086c3d0 captured 2026-06-25 | Accepted | Accepted as designed Design-effectiveness conclusion only; no operating population required at this stage. | SA-2210 2026-07-24 |
| 036 | 10.7.2 Failures of critical security control systems are detected, alerted, and addressed promptly | cr-pci-10-7-2-log-failure-detection@1.1.2 plan 73be709f1aee1e07 Alert configuration | 85ae08706b8633ad captured 2026-07-15 | Accepted | Independently re-performed Assessor re-ran the procedure and obtained a matching result. | QSA-07731 2026-07-27 |
| 037 | 10.7.2 Failures of critical security control systems are detected, alerted, and addressed promptly | cr-pci-10-7-2-log-failure-detection@1.1.2 plan 73be709f1aee1e07 Induced failure test | 48ad3a3228e9f59e captured 2026-07-15 | Accepted | Independently re-performed Assessor re-ran the procedure and obtained a matching result. | QSA-07731 2026-07-27 |
| 038 | 11.3.1.1 All other applicable vulnerabilities are managed and rescans are performed as needed | cr-pci-11-3-1-1-internal-scan-cadence@2.5.0 plan 8cb43c088c2a6b24 Q1 FY26 scan and rescan | 8ab6dd52c5afa632 captured 2025-12-22 | Accepted | Corroborated, second source A second system path produced a consistent count or record set. | SA-2210 2026-07-28 |
| 039 | 11.3.1.1 All other applicable vulnerabilities are managed and rescans are performed as needed | cr-pci-11-3-1-1-internal-scan-cadence@2.5.0 plan 8cb43c088c2a6b24 Q2 FY26 scan and rescan | cb4d550b05818065 captured 2026-03-23 | Accepted | Corroborated, second source A second system path produced a consistent count or record set. | SA-2210 2026-07-28 |
| 040 | 11.3.1.1 All other applicable vulnerabilities are managed and rescans are performed as needed | cr-pci-11-3-1-1-internal-scan-cadence@2.5.0 plan 8cb43c088c2a6b24 Q3 FY26 scan and rescan | 00fd27bb4e8b906b captured 2026-06-22 | Accepted | Corroborated, second source A second system path produced a consistent count or record set. | SA-2210 2026-07-28 |
| 041 | 11.3.1.1 All other applicable vulnerabilities are managed and rescans are performed as needed | cr-pci-11-3-1-1-internal-scan-cadence@2.5.0 plan 8cb43c088c2a6b24 Q4 FY26 scan · interim | 7f72d88fba39c19f captured 2026-07-27 | Open — awaiting verdict | — | — — |
| 042 | 11.6.1 Change- and tamper-detection mechanism on payment pages | cf-pci-11-6-1-change-detection@1.2.0 plan fa6c14222a531b65 Q2 FY26 payment page baseline | 28db0b41aa0c9f25 captured 2026-04-30 | Accepted | Population reconciled Enumerated population tied to an independent count with a zero or explained delta. | SA-2210 2026-07-29 |
| 043 | 11.6.1 Change- and tamper-detection mechanism on payment pages | cf-pci-11-6-1-change-detection@1.2.0 plan fa6c14222a531b65 Q3 FY26 payment page baseline | d953e12d60bd2a92 captured 2026-07-28 | Open — awaiting verdict | — | — — |
| 044 | 12.5.2 PCI DSS scope is documented and confirmed at least once every 12 months | cr-pci-12-5-2-scope-validation@1.3.0 plan 44caed821ce0aedc Data-flow walkthrough | 051a621c2277ab50 captured 2026-05-21 | Accepted | Independently re-performed Assessor re-ran the procedure and obtained a matching result. | QSA-04412 2026-07-29 |
| 045 | 12.5.2 PCI DSS scope is documented and confirmed at least once every 12 months | cr-pci-12-5-2-scope-validation@1.3.0 plan 44caed821ce0aedc Segmentation confirmation walkthrough | ade461c170380e93 captured 2026-05-21 | Accepted with conditions The walkthrough confirms the diagram, but one connected settlement service is described as out of scope without a segmentation test reference. | Scope narrowed by note Accepted for the named subset only; remainder carried to a separate request. | QSA-04412 2026-07-29 |
| 046 | 12.10.1 Incident response plan exists and is ready to be activated | cf-pci-12-10-1-ir-plan-currency@1.0.0 plan 55afe88a7f5304b6 FY26 responder cohort completion | f25a011205802320 captured 2026-04-30 | Open — awaiting verdict | — | — — |
Exception register
5 rejected · 4 accepted with conditions
| Control | Basis | What the code asserts | Assessor note | Disposition |
|---|---|---|---|---|
| 3.5.1.2 | Management response pending | Artifact accepted; a deviation it exposed awaits a management response. | Column-level protection is evidenced in the console, but the key-management procedure document it relies on is not referenced from the artifact. | Accepted with conditionsQSA-07731 · 2026-07-15 |
| 6.3.3 | No independent corroboration | Single-source count with no second path to confirm the population. | Dashboard tile count is not corroborated through an independent path and no record-ID list was captured. | RejectedQSA-04412 · 2026-07-16 |
| 6.3.3 | No independent corroboration | Single-source count with no second path to confirm the population. | Same defect as the October window. Re-collection requested with an enumerated finding list. | RejectedQSA-04412 · 2026-07-16 |
| 6.3.3 | Insufficient population | No enumerated population, or a population that cannot be shown to be complete. | The artifact shows a filtered view, not the complete set of critical findings for the window. | RejectedQSA-04412 · 2026-07-16 |
| 6.3.3 | Sample extension required | Accepted on condition the sample is extended before the opinion is signed. | Accepted on the strength of the exception register; the selection method for the reviewed items is not reproducible. | Accepted with conditionsQSA-07731 · 2026-07-17 |
| 7.2.4 | Stale evidence | Captured outside the assessment period or beyond the freshness window. | Reviewer decisions carry timestamps nine days after the campaign close date recorded in the artifact. | RejectedQSA-04412 · 2026-07-20 |
| 8.2.4 | Sample extension required | Accepted on condition the sample is extended before the opinion is signed. | The delta of one against the HR register is explained in writing and approved; the corroboration path remains single-source. | Accepted with conditionsQSA-07731 · 2026-07-21 |
| 10.2.1.1 | Insufficient population | No enumerated population, or a population that cannot be shown to be complete. | Two in-scope hosts show no events for 41 days inside the period; the assertion is made against a filtered view rather than the enumerated component list. | RejectedQSA-04412 · 2026-07-23 |
| 12.5.2 | Scope narrowed by note | Accepted for the named subset only; remainder carried to a separate request. | The walkthrough confirms the diagram, but one connected settlement service is described as out of scope without a segmentation test reference. | Accepted with conditionsQSA-04412 · 2026-07-29 |
Attestation
Index seal · 2026-08-05
The procedures listed in this index were performed under the direction of QSA-04412 of Calloway & Reyes LLP for the period 2025-10-01 to 2026-09-30. Each result is the assessor’s own conclusion; platform-collected artifacts were accepted, accepted with conditions, or rejected on the reason codes shown.
The seal is a SHA-256 over the canonicalized index — every row’s control, procedure at version, evidence reference, result, reason code, tester, and date. Change one verdict and the fingerprint changes, which is what makes this index a record rather than a report.