{
	"version": "https://jsonfeed.org/version/1.1",
	"title": "Payment Card Industry Data Security Standard (PCI DSS) news from Infosec Standards",
	"description": "News about Payment Card Industry Data Security Standard (PCI DSS), including major updates to our page on it.",
	"home_page_url": "https://infosecstandards.org/standards/pci-dss",
	"feed_url": "https://infosecstandards.org/standards/pci-dss/feed.json",
	"authors": [
		{
			"name": "Infosec Standards",
			"url": "https://infosecstandards.org"
		}
	],
	"language": "en-US",
	"items": [
		{
			"id": "https://infosecstandards.org/news/who-decides-what-to-ask",
			"url": "https://infosecstandards.org/news/who-decides-what-to-ask",
			"title": "Standard pages now say who decides your obligation, and what to ask them",
			"summary": "The HIPAA, PCI DSS, CMMC, and SOC 2 pages each gained a section naming the party that actually sets your obligation and the questions to put to them in writing. HIPAA and SOC 2 also gained a first-decision picker.",
			"content_text": "The HIPAA, PCI DSS, CMMC, and SOC 2 pages each gained a section naming the party that actually sets your obligation and the questions to put to them in writing. HIPAA and SOC 2 also gained a first-decision picker.",
			"date_published": "2026-09-03T00:00:00.000Z",
			"tags": [
				"site-updates"
			]
		},
		{
			"id": "https://infosecstandards.org/news/risk-assessment-tool",
			"url": "https://infosecstandards.org/news/risk-assessment-tool",
			"title": "Infosec Standards now has a free, browser-only risk assessment tool",
			"summary": "Infosec Standards now has a guided, NIST SP 800-30 based risk assessment tool. Everything stays in your browser; you leave with a JSON file to resume from, a spreadsheet register, and a printable report.",
			"content_text": "Infosec Standards now has a guided, NIST SP 800-30 based risk assessment tool. Everything stays in your browser; you leave with a JSON file to resume from, a spreadsheet register, and a printable report.",
			"date_published": "2026-09-02T00:00:00.000Z",
			"tags": [
				"site-updates"
			]
		},
		{
			"id": "https://infosecstandards.org/news/pci-dss-roc-saq-guide",
			"url": "https://infosecstandards.org/news/pci-dss-roc-saq-guide",
			"title": "PCI SSC revises FAQ 1331 on using SAQs to scope ROC assessments",
			"summary": "On August 4, 2026, PCI SSC updated FAQ 1331 so merchants cannot use SAQ eligibility criteria to decide ROC applicability without Compliance Accepting Entity agreement.",
			"content_text": "On August 4, 2026, PCI SSC updated FAQ 1331 so merchants cannot use SAQ eligibility criteria to decide ROC applicability without Compliance Accepting Entity agreement.",
			"date_published": "2026-08-10T00:00:00.000Z",
			"tags": [
				"program-changes",
				"email-all"
			]
		},
		{
			"id": "https://infosecstandards.org/news/pci-dss-v4-0-1",
			"url": "https://infosecstandards.org/news/pci-dss-v4-0-1",
			"title": "PCI DSS v4.0.1 is the current standard",
			"summary": "On June 11, 2024, PCI SSC published PCI DSS v4.0.1, a limited revision of v4.0. Future-dated v4 requirements became mandatory on March 31, 2025.",
			"content_text": "On June 11, 2024, PCI SSC published PCI DSS v4.0.1, a limited revision of v4.0. Future-dated v4 requirements became mandatory on March 31, 2025.",
			"date_published": "2024-06-11T00:00:00.000Z",
			"tags": [
				"version-updates"
			]
		}
	]
}
