Have you almost quit your PCI Compliance job after submitting your organization’s Report on Compliance?

Don’t be shy. It’s okay if you walked away.

I almost quit I submitted the first PCI Report on Compliance I ever worked on.


I didn’t quit. 

I didn’t walk away.

Instead, I saw the opportunity to build a world class PCI DSS Compliance program.

Over the course of my 10 years managing a complex continuous PCI Compliance program at a level 1 merchant, I created a laundry list of do’s and don’ts. 

I captured a lot of up front work that must be done *before* you start your PCI Report on Compliance.

Understanding your scope before you begin assessing is critical to the success of your Report on compliance. That upfront work must be done before you start the RoC.

I don’t believe in reinventing the wheel with every assessment so I created a Report on Compliance Planner as well as a Consolidated Interview and Observation Schedule.

Why? There are so many moving parts during a Report on Compliance. Without

  • repeatable processes
  • clear milestones
  • a communication’s plan
  • an escalation path
  • and who does what directory

All you’ll have is a big ball of goo.

And that’s no fun.

I’m also lazy.

The more efficiently I can work, the more time I have to play word games…I mean work on process improvement.

Together with Lisa Cressey, we automated critical controls so that we could self-collect the evidence and not depend on squirrely system administrators.

We also automated the entire Report on Compliance assessment process


We did.


Because there were only two of us running a PCI Compliance program at a Fortune 100 Company and Level 1 merchant.

It was nerve wrecking to say the least.


Keep reading (and watch the video at the end) because I’ve got 5 actionable tips that you can implement today or this week so that you can crush your next PCI Report on Compliance.

And the Report on Compliance next year, and the next, and so on and so on…

1. Begin with the end in mind

In other words, if you don’t know where you’re going how will you know how to get there?

2. Plan the work; work the plan

I was in my master degree program when I first heard this gem. I was learning project management for software development (eons ago) and this made So. Much. Sense.

This tip goes hand in hand with tip #1.

Once you know where you’re going, plan the work.

Then work the plan.

Adjust the plan as needed. 

3. Complete an end to end scope assessment BEFORE you kick off your Report on Compliance

I can’t begin to tell you how much easier your next PCI assessment will be when you have a complete and accurate scope. 

It’s almost mind blowing how much time you’ll save because you won’t be suffering the pains of email hell or chasing things down from the QSA.

In our course, How to Manage Your PCI Scope Without Losing Your Mind, we share our simple 6 step process to continuously manage your scope.

Trust me, you’re going to need this repeatable process for PCI DSS v4.0. 

There’s 11 new requirements that depend on an accurate scope of people, processes, and technologies.

4. Don’t just blindly pick a QSA company. Vet them

Picking the right QSA company matters. Your QSA is an integral part of your ability to successfully navigate the level 5 rapids of a Report on Compliance. 

QSAs who assess with integrity are the best.

5. Consolidate the interviews and observations and SAVE at least 100 hours (or 20k) in wasted, mindless, unnecessary churn

Powerful, right?

Want to save even more? Email support@paymentcardassessments.com and let’s schedule a time to chat!

The Ultimate Guide On How To Manage PCI DSS Requirement Frequencies

Through our Ultimate Guide On How To Manage PCI DSS Requirement Frequencies, we’ll walk you through each requirement area and show you what the specific requirement frequencies are, why they have a frequency, and we’re going to share our best practices on how to create sustainable processes so that you can maintain PCI DSS Compliance without pulling your hair out.

Leave a Reply

Your email address will not be published. Required fields are marked *

This field is required.

This field is required.