SAQ classification
Each location is classified into the correct SAQ type (A, B, B-IP, C-VT, C, P2PE, D for merchants, D for service providers, or SAQ A-EP) based on payment channel and POS configuration — verified, not assumed.
AttestRow assembles a documentation-complete PCI DSS compliance pack for every location — SAQ classification, evidence extraction, ASV scan orchestration, and franchisor-level rollup — checked against the letter of PCI DSS v4.0.1 before an ISA releases it.
A multi-location merchant's PCI DSS compliance is only as strong as the weakest location's attestation. Miss the correct SAQ type, skip a required evidence item, mis-time a quarterly ASV scan, or fail to roll up a location's Attestation of Compliance — and the entire estate can be fined, non-compliant, or exposed to breach liability.
Most compliance officers run this by hand, from memory, across dozens or hundreds of locations. The standard has not been read end-to-end since the last assessment. That is exactly where completeness gaps hide.
AttestRow exists to close that gap with a single, exhaustive standard applied identically to every location.
We do not summarize the standard and hope. Every location pack is scored against a versioned rule pack tied to the exact text of PCI DSS v4.0.1. These are the provisions each pack is held to.
Each location is classified into the correct SAQ type (A, B, B-IP, C-VT, C, P2PE, D for merchants, D for service providers, or SAQ A-EP) based on payment channel and POS configuration — verified, not assumed.
For every location with an internet-facing IP address, quarterly external vulnerability scans by a PCI SSC-Approved Scanning Vendor are orchestrated and results triaged.
Required evidence — network diagrams, policy documents, configuration files, and manager attestations — is chased automatically from local managers and verified against the SAQ requirements.
Multi-factor authentication for all access to the cardholder data environment is verified per location, with evidence of implementation.
Audit logs, monitoring mechanisms, and retention policies are documented and evidenced for each location's CDE.
All location Attestations of Compliance are rolled into a single franchisor/HQ-level compliance packet in the exact format the acquiring bank or processor expects.
AI extracts and drafts. Deterministic rules — running as code, outside the model — decide what is complete. A PCI SSC-credentialed Internal Security Assessor (ISA) signs every release. That order is never reversed.
Upload your location list and POS vendor details. We return a free completeness read: which SAQ types, evidence items, and scans you already have, and which are missing.
As your authorized clerical agent, we order ASV scans, collect evidence from local managers, and build the location-level evidence log, corroborated across sources.
Each SAQ is drafted from your validated data and the PCI DSS v4.0.1 rule pack into field-locked templates — no legal opinions, no invented facts.
SAQ type is verified against POS configuration; evidence checklist is resolved; scan findings are triaged; any failure blocks release.
A PCI SSC-credentialed ISA reviews the exception queue and signs the release. High-value or complex locations route to senior ISA review first.
You receive the pack: per-location SAQs, evidence log, scan reports, network diagrams, and the franchisor-level rollup — ready for submission to your acquiring bank.
The deliverable is completeness itself — every SAQ element and evidence item accounted for or explicitly exception-coded. Nothing is left implicit.
The gates that decide completeness are code, not a model's opinion. A drafting error cannot slip past a PCI DSS requirement.
We prepare documentation and run scans as your clerical agent. We never contact cardholders, give legal advice, or conduct the assessment.
Simple, predictable, and aligned with a documentation standard — not a percentage of any fine avoidance.
Start with a free Compliance Gap Scan. Send your location list and POS vendor details and we'll return a completeness read against every requirement of PCI DSS v4.0.1.
Documentation-completeness service · not legal advice · the merchant submits every attestation.