← Back to all briefings
Compliance 5 min read Published Updated Credibility 45/100

PCI SSC permits remote assessments during COVID-19 disruptions

The PCI Security Standards Council issued guidance on conducting PCI DSS assessments remotely during the pandemic, outlining conditions for evidence collection and compensating controls when onsite reviews are impossible.

Timeline plotting source publication cadence sized by credibility.
1 publication timestamps supporting this briefing. Source data (JSON)

Executive briefing: On , the PCI Security Standards Council (PCI SSC) published guidance for remote PCI DSS assessments in response to COVID-19 travel and site-access restrictions. The council affirmed QSAs can perform evaluations remotely when evidence (screenshares, photos, video walkthroughs) sufficiently demonstrates control operation, and stressed documenting any temporary compensating controls.

Operator action: Coordinate with your QSA to determine which testing steps can be executed remotely, ensure logging, configuration exports, and video walkthroughs are available, and document interim controls for items requiring onsite validation. Update ROC/SAQ narratives to capture COVID-19 constraints and schedule onsite follow-up for physical inspections once restrictions lift.

Sources: PCI SSC’s blog post details acceptable evidence types, documentation expectations, and when additional validation is needed.

Timeline plotting source publication cadence sized by credibility.
1 publication timestamps supporting this briefing. Source data (JSON)
Horizontal bar chart of credibility scores per cited source.
Credibility scores for every source cited in this briefing. Source data (JSON)

Continue in the Compliance pillar

Return to the hub for curated research and deep-dive guides.

Visit pillar hub

Latest guides

  • PCI DSS
  • Remote Assessment
  • COVID-19
Back to curated briefings