AI Governance Meets Compliance – How AI Is Reshaping PCI, SOC 2, HITRUST, and ISO 27001

March 5, 2026

AI is rapidly moving inside the enterprise control environment. As organizations embed AI into operational decisions, security programs, and regulated…

What PCI SSC’s 2025 Annual Report Means for Our Clients – A QSA Perspective

February 9, 2026

The PCI Security Standards Council (PCI SSC) recently published its first-ever Annual Report, offering transparency into how PCI standards are…

Should You Complete a PCI SAQ on Your Own or Engage a QSA?

January 27, 2026

For organizations that accept, process, store, or transmit payment card data, PCI DSS compliance is a required but often misunderstood…

Transitioning from a PCI DSS SAQ to a Level 1 Assessment

January 21, 2026

For PCI DSS-certified businesses, compliance obligations tend to grow alongside the business itself. Merchants and service providers are classified differently…

Common Remediation Items Found in PCI DSS Audits

January 7, 2026

Achieving and maintaining PCI DSS compliance requires more than completing an annual assessment—it requires security controls that are consistently implemented,…

A Comprehensive Guide to PCI DSS SAQ Types

August 7, 2025

PCI DSS Self-Assessment Questionnaires (SAQs) are tools that help merchants and service providers assess their compliance with the Payment Card…

A QSA’s Perspective on Integrating AI into PCI Assessments Guidance

March 26, 2025

The PCI Security Standards Council (PCI SSC) released new guidance on integrating Artificial Intelligence (AI) into PCI assessments. This is…

Two Audits, One Stone: The Benefits of Combining PCI and SOC 2 Audits

December 10, 2024

For many businesses, especially those dealing with sensitive customer data, compliance with industry standards like PCI DSS and SOC 2…

Act Now on PCI DSS v4.0 Future-dated Requirements

September 13, 2024

On March 31, 2024, PCI DSS v4.0 became the active version of the standard as v3.2.1 was officially retired. Organizations…

PCI DSS v4.0 Vulnerability Scanning and Penetration Testing Requirements

April 8, 2024

Organizations seeking PCI DSS certification must comply with the new 4.0 version of the standard, which includes vulnerability scan and penetration…

Finding a credible expert with the appropriate background, expertise, and credentials can be difficult. CompliancePoint is here to help.