Insight
Annual PCI compliance as a calendar, not a crisis
Annual PCI compliance is easier when it runs on a calendar. So the quarterly and yearly tasks happen on time, and evidence builds up without a scramble.
- Not a QSA, stated first
- Introductions to independent QSAs
- Written answers, no call
Why annual PCI compliance needs a calendar
Validation happens once a year. However, many controls must run throughout the year, and assessors check that they did. Therefore a missed quarter shows up later.
A typical annual PCI compliance calendar
Exact tasks depend on your setup. Still, most merchants share a common rhythm.
| Frequency | Typical tasks |
|---|---|
| Quarterly | External ASV scans and internal scans, where required |
| Every six months | Firewall rule reviews |
| Annually | Scope confirmation, penetration testing, training, policy review |
| Annually | Questionnaire or assessment, plus attestation |
Annual PCI compliance check
Tick what is already on your calendar.
Your result appears here as you tick, so you can see what is still open.
Evidence for annual PCI compliance
Keep evidence as you go. For example, save each scan report and review record when it happens, not months later.
- Dated scan reports and rescans
- Training completion records
- Policy approval dates
- Provider attestations
- Change and access review records
Avoiding the year-end scramble
Assign an owner to each task. Also set reminders a month ahead. As a result, nobody discovers a missing scan during the assessment.
In addition, confirm scope early each year. Changes in payment channels can change the questionnaire, so check before you start.
Where Winslow helps
We build the calendar and help keep it running. We are not a QSA. Gap analysis generally runs $8,000 to $40,000. Requirements are in the PCI SSC document library.
Also review the calendar after each validation. For example, note which tasks slipped and why. So next year's plan improves on this one. In addition, share the calendar with providers who run controls for you, because their evidence feeds yours. As a result, the whole chain stays on schedule, and validation becomes routine rather than stressful.
Annual PCI compliance questions
What does annual PCI compliance involve?
Recurring quarterly and yearly tasks, then validation through a questionnaire or assessment.
When should annual PCI compliance work start?
Early in the cycle, because quarterly evidence cannot be recreated later.
Can software automate annual PCI compliance?
It can track tasks, but people still run the controls.
What if we missed a quarter?
Run the task now and record why, because the assessor will ask.
Related guides
Build your annual PCI compliance calendar
Tell us what you validate today. We reply in writing, usually within one business day. Also mention any providers that run controls for you, because their evidence feeds your calendar. So the plan covers the whole chain.
Ask us anything