PCI DSS v4.0.1 Every SAQ, every scan, every attestation — verified, not assumed

The most rigorous PCI DSS compliance production engine for multi-location merchants.

AttestRow assembles a documentation-complete PCI DSS compliance pack for every location — SAQ classification, evidence extraction, ASV scan orchestration, and franchisor-level rollup — checked against the letter of PCI DSS v4.0.1 before an ISA releases it.

Every SAQ type per PCI DSS v4.0.1Nine SAQ types, gate-checked per locationASV · evidence · network diagram · policy searchesISA review on every pack5-business-day SLA
Why packs fail

A single missing SAQ element can void the entire compliance posture.

A multi-location merchant's PCI DSS compliance is only as strong as the weakest location's attestation. Miss the correct SAQ type, skip a required evidence item, mis-time a quarterly ASV scan, or fail to roll up a location's Attestation of Compliance — and the entire estate can be fined, non-compliant, or exposed to breach liability.

Most compliance officers run this by hand, from memory, across dozens or hundreds of locations. The standard has not been read end-to-end since the last assessment. That is exactly where completeness gaps hide.

AttestRow exists to close that gap with a single, exhaustive standard applied identically to every location.

1 of 9
SAQ types misclassified is enough to jeopardize compliance
The benchmark

Measured against the letter of PCI DSS v4.0.1 — requirement by requirement.

We do not summarize the standard and hope. Every location pack is scored against a versioned rule pack tied to the exact text of PCI DSS v4.0.1. These are the provisions each pack is held to.

PCI DSS v4.0.1 Req. 12

SAQ classification

Each location is classified into the correct SAQ type (A, B, B-IP, C-VT, C, P2PE, D for merchants, D for service providers, or SAQ A-EP) based on payment channel and POS configuration — verified, not assumed.

PCI DSS v4.0.1 Req. 11

Quarterly ASV scans

For every location with an internet-facing IP address, quarterly external vulnerability scans by a PCI SSC-Approved Scanning Vendor are orchestrated and results triaged.

PCI DSS v4.0.1 Req. 12.8

Evidence collection

Required evidence — network diagrams, policy documents, configuration files, and manager attestations — is chased automatically from local managers and verified against the SAQ requirements.

PCI DSS v4.0.1 Req. 8

MFA and access controls

Multi-factor authentication for all access to the cardholder data environment is verified per location, with evidence of implementation.

PCI DSS v4.0.1 Req. 10

Logging and monitoring

Audit logs, monitoring mechanisms, and retention policies are documented and evidenced for each location's CDE.

PCI DSS v4.0.1 Req. 12.9

Franchisor-level rollup

All location Attestations of Compliance are rolled into a single franchisor/HQ-level compliance packet in the exact format the acquiring bank or processor expects.

How a pack is built

Intake to ISA release, with deterministic gates the AI cannot overrule.

AI extracts and drafts. Deterministic rules — running as code, outside the model — decide what is complete. A PCI SSC-credentialed Internal Security Assessor (ISA) signs every release. That order is never reversed.

01

Compliance Gap Scan

Upload your location list and POS vendor details. We return a free completeness read: which SAQ types, evidence items, and scans you already have, and which are missing.

02

Evidence & scan orchestration

As your authorized clerical agent, we order ASV scans, collect evidence from local managers, and build the location-level evidence log, corroborated across sources.

03

Grounded drafting

Each SAQ is drafted from your validated data and the PCI DSS v4.0.1 rule pack into field-locked templates — no legal opinions, no invented facts.

04

Deterministic completeness gates

SAQ type is verified against POS configuration; evidence checklist is resolved; scan findings are triaged; any failure blocks release.

05

ISA release

A PCI SSC-credentialed ISA reviews the exception queue and signs the release. High-value or complex locations route to senior ISA review first.

06

Delivery

You receive the pack: per-location SAQs, evidence log, scan reports, network diagrams, and the franchisor-level rollup — ready for submission to your acquiring bank.

The bar we hold

Rigor you can measure.

100%
ISA-released
No pack ships without a human signature.
5 days
Standard SLA
From complete intake to released pack.
<1%
Critical-defect target
Tracked against a gold-standard pack library.
4
Evidence sources
ASV scans · network diagrams · policy docs · manager attestations, every applicable location.
Why AttestRow

Built to be the most thorough option a multi-location merchant has.

Documentation-complete, by design

The deliverable is completeness itself — every SAQ element and evidence item accounted for or explicitly exception-coded. Nothing is left implicit.

Deterministic, not vibes

The gates that decide completeness are code, not a model's opinion. A drafting error cannot slip past a PCI DSS requirement.

In its lane, on purpose

We prepare documentation and run scans as your clerical agent. We never contact cardholders, give legal advice, or conduct the assessment.

Engagement

Flat fee, per location per year. No hourly billing, ever.

Simple, predictable, and aligned with a documentation standard — not a percentage of any fine avoidance.

  • A free Compliance Gap Scan before you commit — see exactly what is missing.
  • One flat fee per location per year for the full production engine; disclosed pass-through ASV scan fees.
  • Optional fixed-fee senior ISA review for complex or high-value locations.
  • Optional Remediation Pack Add-on for locations with identified gaps, pre-dated to your compliance deadline.
FAQ

Questions, answered precisely.

Is AttestRow a Qualified Security Assessor (QSA) company?
No. AttestRow, a service of Your Deputy, Obuke LLC, provides documentation-completeness services. It is not a QSA company, does not provide legal advice, and does not represent you in any compliance matter. ISA review is available and recommended for complex or high-value locations.
Do you contact cardholders or conduct the assessment?
Never. AttestRow is not a QSA and does not contact cardholders or assessors. The merchant remains the entity responsible for submitting all attestations and maintaining compliance.
What makes a pack 'complete'?
Completeness is defined by PCI DSS v4.0.1: the correct SAQ type per location, all required evidence collected, ASV scans resolved, and the franchisor-level rollup verified. Deterministic gates enforce each one before release.
How fast is it?
The standard SLA is five business days from complete intake to an ISA-released pack. The free Gap Scan is returned much sooner and tells you exactly what is still needed.
How are you priced?
A flat fee per location per year, plus disclosed pass-through ASV scan costs. No hourly billing and no percentage of any fine avoidance or recovery.

See what's missing before it costs you compliance.

Start with a free Compliance Gap Scan. Send your location list and POS vendor details and we'll return a completeness read against every requirement of PCI DSS v4.0.1.

Documentation-completeness service · not legal advice · the merchant submits every attestation.