A new version (v3) of the PCI Card Production Physical Security reporting template (AOC/SOC ROC reporting template) appears to have been published, which assessors and card production vendors use for compliance reporting.
VIEW SOURCE ↗PCI DSS
Payment SecurityIssued by PCI Security Standards Council
PCI DSS is maintained by the PCI Security Standards Council and sets technical and operational requirements for protecting cardholder data. It applies to any merchant or service provider that stores, processes, or transmits payment card data, with the required validation method scaled to transaction volume. The only currently valid version is PCI DSS v4.0.1 (June 2024); v3.2.1 was retired on March 31, 2024. Of the requirements introduced in v4.0, 51 were "future-dated" and became mandatory on March 31, 2025, so every requirement in v4.0.1 is now in scope for assessments.
Get notified the moment PCI DSS actually changes — reviewed by a human before it ever reaches you.
Get started freeMost recent update
▸ 12 EARLIER UPDATES IN THE FULL HISTORY
The complete change log for PCI DSS — every confirmed update, with severity and source — is included in every account, free ones too.
Sign up free to see the full history