Hacker News new | ask | show | jobs
by snazz 2571 days ago
Do we have proof of that? I think the fact that we're taking your word for everything so far is the source of the discomfort here.
1 comments

Sort of humorous comment, as PCI DSS is self assessment and attestation of compliance. If OP states they’ve met their burden, that’s all that’s required at their scale.
Really? I evidently know nothing of the matter, but you're saying that the auditors only get involved when they become a larger operation?
Yep. Card networks can also unilaterally decide your level.

https://www.pcicomplianceguide.org/faq/#4

Disclaimer: I work in governance/risk/compliance, but have not performed PCI compliance work in the last several years.

PCI DSS assessments are signed by natural persons, not arbitrary HTML content.
Natural persons who are rarely, if ever, pursued when breaches occur.