Knowledge center
Is PCI DSS reviewed or renewed?
PCI DSS is not a one-time activity. Validation is commonly repeated according to the relationship with the acquirer or requester, and scope should be reviewed periodically and after significant changes.
Why it matters
New channels, providers, systems or locations can change scope and the SAQ route.
What to confirm
- Requester’s validation period
- Changes to payments, systems, providers or locations
- Version and documents required for the new period
Official PCI DSS documentation · PCI DSS v4.0.1 · reviewed 2026-07-31
This content is informational and is not legal advice. The applicable route and validation method depend on the operation and requesting party.