Scope
Describe the cardholder data environment, payment channels (eCommerce, POS), included locations, excluded systems, and network segmentation that limit PCI scope for assessment purposes.
Using the Business PCI Template centralizes evidence, clarifies control ownership, and reduces audit time by structuring required documentation. It supports consistent adherence to PCI DSS objectives and streamlines validation for assessors, acquiring banks, and internal compliance teams.
Typical users of the Business PCI Template include internal compliance teams, IT security staff, and merchant operations.
Small businesses, service providers, and third-party vendors also use the template to standardize PCI documentation.
Describe the cardholder data environment, payment channels (eCommerce, POS), included locations, excluded systems, and network segmentation that limit PCI scope for assessment purposes.
List technical and administrative controls mapped to PCI DSS objectives: firewalls, encryption, access controls, logging, vulnerability management, patching schedules, and responsible owners.
Reference logs, configuration screenshots, ASV/scan reports, policies, training records, and transaction samples that demonstrate controls are implemented and operating effectively.
Record payment processors, gateways, hosting providers, and their PCI status, contract terms, contact points, and delineation of cardholder data responsibilities.
Track open findings with risk ratings, remediation owners, target completion dates, verification steps, and required post-remediation evidence for assessor review.
Include attestation language, executive or compliance officer approvals, effective dates, and the method of signature (wet, RON, or e-signature) with audit-trail reference.
Choose eSignature and document platforms that provide tamper-evident audit trails, configurable signer authentication, and export to common formats for evidence retention.
| Field | Configuration |
|---|---|
| Signer Authentication | Email link, SMS OTP, or SSO as available. |
| Field Validation | Use required fields, format patterns, and conditional logic to reduce errors. |
| Document Routing | Sequential approval, optional reviewers, and bulk send for multiple merchants. |
| Audit Trail Level | Capture full action logs, timestamps, and IP addresses for each signer. |
| Criterion | eSign | Paper |
|---|---|---|
| Authentication | email/sms/kba | photo id/witness |
| Processing Time | under 24 hours | days to weeks |
| Audit Trail | detailed digital log | manual notes |
| Storage | encrypted cloud | physical files |
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No envelope cap | 100 envelopes/user/year | Varies by plan | Varies by plan | Varies by plan |
Complete annual SAQ or ROC as required by card brands and acquirers.
Perform external ASV scans quarterly for applicable environments.
Assign remediation deadlines with owner and verification steps; prioritize critical findings immediately.
Verify third-party PCI attestations annually or on contract renewal.
Report confirmed breaches to acquiring bank per contractual timelines; act immediately on suspected compromises.
Identify in-scope systems and payment channels before evidence collection.
Gather logs, scans, screenshots, and vendor attestations.
Compliance reviews entries, confirms completeness, and assigns remediation.
Submit the package to a QSA or provide SAQ and evidence to the acquirer.