Free Workbook
The PCI DSS Scope & Evidence Workbook
Anyone can find a list of the twelve PCI DSS requirements. What that list will not tell you is which of your systems they apply to -- and that question is where the money is. This workbook walks a real system inventory through the in-scope test, shows exactly what segmentation and tokenisation move out of scope and what stays in, then hands you an evidence register organised the way an assessor samples it.
- A fully worked scope decision table across fourteen systems, including the connected-to and security-impacting ones teams miss
- An SAQ selection guide covering every instrument and what disqualifies you from each
- An evidence register with a worked row for all twelve requirements: named artifact, owning role, cadence, and what makes it sufficient
- The annual cadence that keeps scanning and testing evidence current, and eight scope-reduction moves ranked by scope removed per unit of effort
Get the workbook
Enter your work email and we'll take you straight to the download.