Denied party screening: strict liability, so keep the evidence
Screening is not a judgement call. There is no minimum order value, no exemption for small companies, and the defence is the screening record you kept.
Compliance is a set of things that happen quarterly and monthly. The annual questionnaire only records whether they did.
A PCI compliance checklist is the working list of recurring tasks that keep a merchant genuinely compliant between annual validations. It is not the questionnaire, not a substitute for it, and not the same thing as knowing your pci compliance levels: the questionnaire asks whether these things are true, and the checklist is how they become true and stay true.
Framing it this way matters because the common failure is not a missing control, it is a control that existed on the day of the attestation and lapsed the following month. Access reviews, scan schedules and policy acknowledgements are the items that decay quietly, and they are exactly what an investigation after an incident examines.
Merchants are responsible for confirming that the providers handling card data on their behalf are themselves compliant, and for keeping a list of them with what each is responsible for. In practice that list is compiled once during a first assessment and never updated, while the business quietly adds a new gateway, a new analytics script on the checkout page, or a new hosting arrangement. Review it on the same cycle as everything else and treat a new script on a payment page as a change that needs checking, because that is precisely where recent card-skimming attacks have lived.
Evidence has to be contemporaneous. A screenshot taken during the annual questionnaire showing a setting is correct today says nothing about the year behind it. Capture the scan reports, review sign-offs and training records when they happen, not when the questionnaire is due.
The checklist works when each item has a named owner, a cadence and a place the evidence lands — and when that survives the person who set it up leaving. Ettex Sheets holds the checklist with owners, due dates and last-completed dates, so what is overdue is visible rather than remembered; Ettex Records keeps the evidence per item and per period; and the annual submission it feeds is covered in pci saq.
To be clear: this is a spreadsheet and a file, not PCI software, and none of it is security advice. The requirements come from the current version of the standard, the validation obligation from your acquirer, and a qualified assessor is the authority on scope and applicability.
The recurring tasks between annual validations: vulnerability scans, access reviews, patching, log review, policy review, training, provider status checks and incident response testing.
On the cadence set by the standard for your scope, by an approved scanning vendor, with passing results retained. A failed scan must be remediated and re-run.
Yes. Merchants keep a list of providers handling card data on their behalf, with what each is responsible for and their current status.
No. The questionnaire records whether the controls are in place; the checklist is the recurring work that keeps them in place.
Screening is not a judgement call. There is no minimum order value, no exemption for small companies, and the defence is the screening record you kept.
The reason code is a specification. It tells you exactly which evidence will be considered — and, just as usefully, which evidence will be ignored.
Economic nexus made sales tax a function of revenue rather than of offices. The work is not the filing — it is knowing, month by month, which states you have crossed.