I have been reading and reviewing all this changes that start in Feb 1st and have some doubts regarding when some of them should be done. for example anything new as for example 12.11 internal quarterly assessment, should start 3 months after Feb 1st, which would be May 1st. right?
and if so, what happens if a company by that time is undergoing a PCI Assessment?, the this internal assessment could be completed 3 months after the last PCI QSA audit?
As of February 1, 2018, if your organization is a Service Provider, you MUST then be doing quarterly reviews of these items. That is how you interpret it. That would mean if you did them at the end of the quarter, you would have four for 2018 dated around March 31, June 30, September 30 and December 31.
Welcome to the PCI Guru blog. The PCI Guru reserves the right to censor comments as they see fit. Sales people beware! This is not a place to push your goods and services.
I have been reading and reviewing all this changes that start in Feb 1st and have some doubts regarding when some of them should be done. for example anything new as for example 12.11 internal quarterly assessment, should start 3 months after Feb 1st, which would be May 1st. right?
and if so, what happens if a company by that time is undergoing a PCI Assessment?, the this internal assessment could be completed 3 months after the last PCI QSA audit?
thanks
As of February 1, 2018, if your organization is a Service Provider, you MUST then be doing quarterly reviews of these items. That is how you interpret it. That would mean if you did them at the end of the quarter, you would have four for 2018 dated around March 31, June 30, September 30 and December 31.