Self-assessment

PCI DSS readiness check

Ten questions, two minutes. Find out whether you’re ready for a QSA — or whether you’d be paying for an assessment that stalls. Scored 0–2 per question; the scoring is shown, not hidden.

1. Is cardholder data limited to as few systems as possible, with the cardholder data environment segmented from the rest of the network?

2. Is multi-factor authentication enforced for all remote access and for all access into the cardholder data environment?

3. Are security patches applied within one month of release on all in-scope systems?

4. Do you retain logs of access to cardholder data for at least 12 months (3 months immediately available)?

5. Is cardholder data encrypted in transit and at rest (or rendered unreadable by truncation, tokenization, or masking)?

6. Do you run quarterly external ASV scans and an annual penetration test (external + internal)?

7. Are default passwords changed on all in-scope systems, and is there a formal access-review process?

8. Is there a documented incident response plan, tested in the last 12 months?

9. Do all service providers with access to cardholder data have current PCI DSS compliance evidence (AoC/ROC)?

10. Is there a named owner for PCI compliance and a current network/data-flow diagram of the cardholder data environment?

What the score means. 16–20: book the QSA. 10–15: close gaps first — a gap engagement costs far less than stalled fieldwork. Below 10: do readiness work before any QSA engagement. A QSA verifies everything independently; this quiz just tells you where you stand.

Ready? Get competing ROC quotes

If you scored 16+, get scoped quotes from matched QSA companies — free, two minutes.

Get a free quote

Estimate the cost  ·  See the timeline