Skip to content

Add PCI TPSP service coverage gates#1610

Open
NiXouuuu wants to merge 1 commit into
UnitOneAI:mainfrom
NiXouuuu:improve/pci-tpsp-aoc-gates
Open

Add PCI TPSP service coverage gates#1610
NiXouuuu wants to merge 1 commit into
UnitOneAI:mainfrom
NiXouuuu:improve/pci-tpsp-aoc-gates

Conversation

@NiXouuuu
Copy link
Copy Markdown

@NiXouuuu NiXouuuu commented Jun 7, 2026

Closes #1607.

Summary

  • Add a TPSP responsibility and AOC service-coverage gate to PCI DSS scope reduction.
  • Require provider/service match, data-flow proof, requirement-level responsibility ownership, customer-owned controls, provider-side drift review, and monitoring cadence before confirming SAQ impact.
  • Add a Scope Reduction Not Proven classification and a TPSP/SAQ output section so provider evidence is reported separately from the requirement summary.
  • Extend common pitfalls and prompt-injection guardrails for generic provider or contract claims.

Validation

  • git diff --check
  • Markdown fence-balance check for skills/compliance/pci-dss-review/SKILL.md
  • Required marker check for TPSP service-coverage, evidence record, scope-reduction classification, SAQ output, provider drift, and service-specific AOC guardrails

Payment preference: PayPal; details can be provided privately after maintainer acceptance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[REVIEW] pci-dss-review: add TPSP responsibility and AOC service-coverage gates

1 participant