Batch Register

Compliance attestation and scope confirmation

The shortest fixed clock in the held texts is 8,760 hours (yearly), set by PCI DSS 12.5.2. Paste one job that feeds this consumer, for example pci_scope_confirmation, weekly, and the register reads its period against the clocks below, names the gap in hours, and carries the question for its owner.

Matched on the job name or the consumer column by these words: attestation, aoc, roc export, self assessment, saq, scope confirm, compliance review, scope confirmation.

The clock each rule sets

RegimeClockClause
PCI DSS8,760hPCI DSS 12.5.2 PCI DSS scope documented and confirmed annuallyconfirmed at least once every 12 months

Questions this page answers

How often does PCI DSS v4.0 require compliance attestation and scope confirmation?

Yearly (8,760 hours): PCI DSS 12.5.2, PCI DSS scope documented and confirmed annually. PCI DSS scope is documented and confirmed at least once every 12 months by identifying all data flows, system components, and segmentation controls in use.

What does the register ask the owner of a compliance attestation and scope confirmation job?

Which data flows, components and segmentation controls did the last confirmation list, and what changed since?

The clauses in full

PCI DSS 12.5.2 PCI DSS scope documented and confirmed annuallythe standard's page

PCI DSS scope is documented and confirmed at least once every 12 months by identifying all data flows, system components, and segmentation controls in use.

What an assessor asks to see: Scope document with named components; Data flow diagrams covering all CHD flows; Network and segmentation diagrams; Annual scoping exercise minutes and sign-off. Where it usually falls short: Diagrams stale

Requirement text quoted from the standards themselves, published at compliance.theartofservice.com, the same publisher as this register, read against the held text of each standard: our statement of each clause, not the instrument verbatim. Run this job through the register