To address some of the past confusion regarding the dating of PCI reports, the PCI Security Standards Council (SSC) has altered the report date methodology for PCI DSS v4.0 to provide more clarity and consistency to this process.
The two new report dates are:
So while the date of report is your official compliance date, you can use the assessment end date for tracking your periodic requirements—which means that you can track stale evidence or quarterly scans based on your final evidence acceptance date.
That should come as somewhat of a relief for organizations that have had to deal with the pain points of tracking their quarterly scans and trying to fit them in within 90 days of their ROC date in the past. Now, with the new standard, the time frame relevant to evidence collection stops once the final piece of evidence is accepted by the QSA.
Understanding these new dates is important when preparing for a PCI DSS v4.0 assessment, so here are a few things you can do to ensure a smooth transition to the new PCI DSS v4.0 reporting:
If you have any questions about the new report dates in PCI DSS v4.0, please contact us, as we’d be happy to help, and be sure to check out our other disseminations on the new standard as well: