Confessions of the QSA: An Introduction to the Payment Card Industry Data Security Standard

 

As most in the industry know, a QSA must get certified by the PCI Security Standards Security Council to audit merchants for Payment Card Industry Data Security Standard (PCI DSS) compliance. Created in 2004 by major credit card brands, such as Visa and American Express, the council acts as a form of self-regulation.

So, how did Weaver become an expert on PCI, and what types of solutions does it offer its clients?

On this episode of Weaver: Beyond The Numbers, host Tyler Kern talked with Trip Hillman, Director of Cyber Security Services at Weaver, and Kyle Morris, Manager of IT at Advisory Services at Weaver. The trio dug into insights from Weaver’s Quality Security Assessor and explored how Weaver dove headfirst into PCI.

The PCI DSS applies to organizations that store, process, transmit or could affect the security of cardholder data. Companies that fall under this standard could do a variety of things, such as an annual self-assessment questionnaire, or bring in a third-party, independent QSA to do a full-blown report on compliance audit.

Morris is a QSA and started at Weaver about eight years ago. A few years into his career, they had a client, a service provider, start getting asked by their customers if they knew anything about PCI and the report on compliance. At the time, they hadn’t done anything with it, but decided to figure it out. That morphed into Weaver diving headfirst into PCI.

“We help people with self-assessment questionnaires or SAQs and everything from full-on ROCs for Fortune 50 Cloud Providers to small merchants to SaaS solutions,” Morris said.

Follow us on social media for the latest updates in B2B!

Image

Latest

safer HVAC chemicals
Stronger Training Pipelines and Smarter Social Media Can Help Solve HVAC’s Talent Shortage
June 9, 2026

The skilled trades are at a crossroads. By some industry estimates, for every five experienced technicians retiring, only two new ones are entering the field—highlighting a growing HVAC talent gap. At the same time, buildings are becoming more complex, more connected, and more dependent on high-performance mechanical systems. The stakes are real: without a…

Read More
design
Where Design Meets Durability: Why Commercial Surfaces Must Support Safety, Cleanability, and Long-Term Value
June 8, 2026

When a commercial space fails, it often fails quietly: a lobby floor that becomes slippery when wet, a hotel bathroom that is difficult to clean, a healthcare surface that cannot withstand constant disinfection, or an office finish that looks great until afternoon glare makes the room uncomfortable. These are not purely aesthetic problems; they are…

Read More
creative career
Crafted Journey How To: Building a Creative Career Across Scripts, Stages, and Sound
June 8, 2026

Creative careers rarely move in a straight line, especially for writers working across stage, screen, audio, books, and independent film. Sustaining that kind of life often means finding opportunities wherever they appear, building a strong network, staying open to different formats, and saying yes to collaborations that can lead somewhere unexpected. The stakes are…

Read More
EMR
EMR Strategy, Consulting, and Career Pivots with MedSys Co-Founder Mark Embry
June 8, 2026

Electronic medical records (EMRs) have moved from a back-office upgrade to a frontline determinant of care quality, clinician burnout, and hospital economics. With U.S. hospitals often spending tens to hundreds of millions—sometimes exceeding $100 million—on EMR implementations, the stakes have never been higher for getting both the technology and the human adoption right. As…

Read More