This piece is written for PCI consultancies and payment security specialists, not for merchants working on compliance. It is not compliance advice. It maps the questions merchants typically have about PCI DSS, distinguishes the roles of different PCI professionals, and translates both into content decisions.
01 Uncertainty is the starting point
Uncertainty is the starting point
Most merchants do not begin by looking for a PCI consultant. They begin confused: a payment provider mentions an annual questionnaire, an acquirer asks for an attestation, or the business changes how it takes payments and nobody knows what that means for compliance.
That confusion is structural. The PCI Security Standards Council publishes the standard and supporting documents, but, as the Council itself states, it does not define compliance requirements for individual organizations or set their validation responsibilities. Card brands, acquirers and payment facilitators do. Merchants therefore hear about obligations from several directions, in inconsistent terms.
02 The questions merchants actually have
The questions merchants actually have
Merchant questions tend to fall into a few groups:
- Scope. Which systems, people and processes handle cardholder data, and how outsourcing payments to a provider changes that.
- Validation. Which self-assessment questionnaire applies, whether an on-site assessment is needed, and who decides.
- Changes. What changed with PCI DSS v4.x, and what the updates mean for their setup.
- Gaps. What they are missing and how to fix it without rebuilding everything.
- Help. Whether they need outside expertise, and which kind.
03 Version 4 created a wave of specific questions
Version 4 created a wave of specific questions
PCI DSS v4.x introduced requirements that were future-dated and became effective on 31 March 2025. Among them were requirements covering scripts on payment pages and detection of unauthorized changes to those pages, aimed at attacks that skim card data in the browser.
In January 2025, the Council announced changes for merchants validating with SAQ A: those payment-page requirements were removed from that questionnaire, and a new eligibility criterion was added requiring merchants to confirm their site is not susceptible to script attacks that could affect their e-commerce systems. Merchants who cannot meet the criterion may no longer qualify for that questionnaire.
Changes like this generate precise, high-intent questions from merchants who thought their compliance was settled.
What it means for your firm: dated explainers on specific changes, such as SAQ A eligibility, attract qualified merchants. They must be accurate, cite primary sources and avoid implying that every merchant is affected the same way.04 Different merchants, different obligations
Different merchants, different obligations
Obligations differ significantly between merchants. A retailer using a fully hosted payment page, one embedding a provider's payment fields, one processing cards through its own systems and one with physical stores and payment terminals have very different scopes and validation paths. Validation expectations also vary with transaction volumes and the requirements of acquirers and card brands.
What it means for your firm: organize content around merchant situations rather than around the standard's structure. A merchant can recognize “we use a hosted checkout” far faster than a requirement number.05 Which kind of PCI professional does the merchant need?
Which kind of PCI professional does the merchant need?
Merchants often do not know that PCI work involves distinct roles, and search results rarely explain the difference:
- Qualified Security Assessors (QSAs) are firms and individuals qualified by the Council to perform PCI DSS assessments.
- Approved Scanning Vendors (ASVs) are qualified to perform the external vulnerability scans that many merchants need.
- Internal Security Assessors (ISAs) are employees of an organization trained to perform internal assessments.
- Advisory consultancies help with scoping, gap analysis, remediation and readiness, and may or may not also hold assessor status.
Independence matters here: organizations often want to separate the advice that shapes their environment from the assessment that validates it, and assessors have their own rules on this.
What it means for your firm: state clearly which roles your firm holds and which services you provide, and explain the difference plainly. Merchants searching “do I need a QSA” are often really asking whether they need an assessor, an adviser or neither.06 Translating merchant questions into search and content decisions
Translating merchant questions into search and content decisions
The query types below are hypotheses to validate, not measured demand.
Accuracy is the competitive advantage in this segment. Payment security content is heavily produced and often wrong. A consultancy whose explanations are precise, dated and sourced earns trust from merchants and gives AI assistants reliable material to draw on.
07 Limits of this analysis
Limits of this analysis
This article is not compliance advice. PCI DSS applicability and validation requirements depend on the merchant's setup and on requirements set by card brands, acquirers and other compliance enforcing entities. Always verify with primary PCI SSC sources and the relevant payment partners.
Standard and questionnaire references are current as of September 2026 and may be revised.
The query types are hypotheses. Validate them with merchant enquiries you receive and your Search Console data.
Accurate, sourced content that AI assistants can rely on is part of AI search optimization.
KRYSTON PUBLICATIONS
Analysis for cybersecurity service firms on search, AI visibility and buyer trust.