All I can say is Wow! WOW!
There is a LOT of “busy work” in this version.
For any QSA that does not have access to some form of tool for filling this bad boy out, heaven help you. It seems that the Council has declared war on the QSACs and QSAs. I would venture a guess that the number of hours required to fill out and ticking and tying things will be twice the amount of time a QSA spends on actually doing the assessment.
Sadly, it is painfully obvious as to why this has happened.
I am sure it is to get back at all of the “ROC Mills” out there (you know who you are) that conduct PCI assessments by essentially licking a finger, putting it in the air and sensing which way the wind is blowing, i.e., “you are compliant!”
But sadder still are the poor merchants and service providers that are now collateral damage in this “war”. I would not be surprised that, if after reviewing this Albatross of a standard, those merchants and service providers revolt. That constituency is not going to pay for the overhead in this new version. Even those that have done the correct thing and minimized their scope are going to get screwed over because of all of the “busy work” required to even complete their assessments.
If the Council wanted to find a way to put themselves out of business, I think they have found that in v4.
I thought I was only joking in my April Fool’s Day post about “Miserable Edition”. But I was apparently spot on. I cannot wait to attend training on this abomination to understand their justification for making a PCI assessment even more miserable than it already was.
Spot on! Sadly, the hand writing was on the wall ans this is one reason a i sold my QSAC in 2018.