
Jul 16, 2026
PCI DSS Scoping
In this episode of InfoSec Insider, Tibor Laczko and Alastair Stewart, both Senior Consultants and Qualified Security Assessors (QSAs) at URM, explore scoping in the Payment Card Industry Data Security Standard (PCI DSS). Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss:
- When an organisation stops being ‘just a merchant’ and becomes a PCI DSS service provider and how this distinction is made
- Whether organisations can be a merchant and service provider at the same time and how this should be reflected in the PCI DSS assessment
- Why Requirement 6.4.3 and 11.6.1 are particularly important for modern e-commerce scoping
- Some examples of systems that are not in the card data environment (CDE) but are still security-impacting and therefore in PCI DSS scope
- How elements such as administrative access, deployment pipelines, cloud consoles, source code repositories, and secrets management tools be considered during scoping
- And more.
Ask Alastair and Tibor a question: https://urmconsulting.com/podcasts/pci-dss-scoping
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Connect with us on LinkedIn
Brought to you by URM, the UK’s leading information and cyber security specialists.
No comments yet. Be the first to say something!