PCI-DSS SAQ & Scope Author
Get Started with This SkillOverview
Guided elaboration of PCI-DSS scope documentation and SAQ support: cardholder data environment (CDE), network segmentation narrative, and control evidence mapping to SAQ requirements.
Getting Started
Add your source materials to the project workspace, then activate the PCI-DSS SAQ & Scope Author skill. The agent will guide you through the process step by step.
Example Conversation
You: We need a PCI scope document and SAQ D support. We have a segmented network; cardholder data is only in our payment gateway.
Agent: I’ll draft the scope document (CDE, segmentation narrative) and then a requirement-by-requirement SAQ response pack with evidence references. For each requirement I’ll mark Compliant, N/A with justification, or Out of scope with scope doc reference.
You: Run the validator when done.
Agent: I ran
check_pci_requirement_coverage. Requirements referenced; N/A justifications present. No warnings.
Sample Output Excerpt
Requirement 1.1 — Compliant. Firewall at perimeter; evidence: network diagram, firewall rule review. Requirement 2.2 — N/A. No default passwords in CDE; justification: all systems use SSO, no vendor defaults.
Built-in Validation Tools
check_pci_requirement_coverage checks for: PCI requirement numbers, CDE/scope section, and justification when N/A or out-of-scope is used. Run on scope or SAQ document after drafting.