<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Payment Card Industry Data Security Standard (PCI DSS) news from Infosec Standards</title>
    <link>https://infosecstandards.org/standards/pci-dss</link>
    <description>News about Payment Card Industry Data Security Standard (PCI DSS), including major updates to our page on it.</description>
    <language>en-us</language>
    <atom:link href="https://infosecstandards.org/standards/pci-dss/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Standard pages now say who decides your obligation, and what to ask them</title>
      <link>https://infosecstandards.org/news/who-decides-what-to-ask</link>
      <guid>https://infosecstandards.org/news/who-decides-what-to-ask</guid>
      <pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate>
      <description>The HIPAA, PCI DSS, CMMC, and SOC 2 pages each gained a section naming the party that actually sets your obligation and the questions to put to them in writing. HIPAA and SOC 2 also gained a first-decision picker.</description>
    </item>
    <item>
      <title>Infosec Standards now has a free, browser-only risk assessment tool</title>
      <link>https://infosecstandards.org/news/risk-assessment-tool</link>
      <guid>https://infosecstandards.org/news/risk-assessment-tool</guid>
      <pubDate>Wed, 02 Sep 2026 00:00:00 GMT</pubDate>
      <description>Infosec Standards now has a guided, NIST SP 800-30 based risk assessment tool. Everything stays in your browser; you leave with a JSON file to resume from, a spreadsheet register, and a printable report.</description>
    </item>
    <item>
      <title>PCI SSC revises FAQ 1331 on using SAQs to scope ROC assessments</title>
      <link>https://infosecstandards.org/news/pci-dss-roc-saq-guide</link>
      <guid>https://infosecstandards.org/news/pci-dss-roc-saq-guide</guid>
      <pubDate>Mon, 10 Aug 2026 00:00:00 GMT</pubDate>
      <description>On August 4, 2026, PCI SSC updated FAQ 1331 so merchants cannot use SAQ eligibility criteria to decide ROC applicability without Compliance Accepting Entity agreement.</description>
    </item>
    <item>
      <title>PCI DSS v4.0.1 is the current standard</title>
      <link>https://infosecstandards.org/news/pci-dss-v4-0-1</link>
      <guid>https://infosecstandards.org/news/pci-dss-v4-0-1</guid>
      <pubDate>Tue, 11 Jun 2024 00:00:00 GMT</pubDate>
      <description>On June 11, 2024, PCI SSC published PCI DSS v4.0.1, a limited revision of v4.0. Future-dated v4 requirements became mandatory on March 31, 2025.</description>
    </item>
  </channel>
</rss>
