Confessions of the QSA: An Introduction to the Payment Card Industry Data Security Standard

 

As most in the industry know, a QSA must get certified by the PCI Security Standards Security Council to audit merchants for Payment Card Industry Data Security Standard (PCI DSS) compliance. Created in 2004 by major credit card brands, such as Visa and American Express, the council acts as a form of self-regulation.

So, how did Weaver become an expert on PCI, and what types of solutions does it offer its clients?

On this episode of Weaver: Beyond The Numbers, host Tyler Kern talked with Trip Hillman, Director of Cyber Security Services at Weaver, and Kyle Morris, Manager of IT at Advisory Services at Weaver. The trio dug into insights from Weaver’s Quality Security Assessor and explored how Weaver dove headfirst into PCI.

The PCI DSS applies to organizations that store, process, transmit or could affect the security of cardholder data. Companies that fall under this standard could do a variety of things, such as an annual self-assessment questionnaire, or bring in a third-party, independent QSA to do a full-blown report on compliance audit.

Morris is a QSA and started at Weaver about eight years ago. A few years into his career, they had a client, a service provider, start getting asked by their customers if they knew anything about PCI and the report on compliance. At the time, they hadn’t done anything with it, but decided to figure it out. That morphed into Weaver diving headfirst into PCI.

“We help people with self-assessment questionnaires or SAQs and everything from full-on ROCs for Fortune 50 Cloud Providers to small merchants to SaaS solutions,” Morris said.

Follow us on social media for the latest updates in B2B!

Image

Latest

Casey Brown
From Poverty to Pricing Power | Why Great Companies Undercharge
April 2, 2026

Casey Brown didn’t grow up thinking she would become an entrepreneur. She grew up in a blue-collar family where money was always tight — close enough to the edge that the fear of poverty shaped many of her early decisions. That fear led her into engineering, into corporate America, and eventually into a moment…

Read More
Nightingales Summit: Empowering the Next Generation of Nigerian Nurses
Nightingales Summit: Empowering the Next Generation of Nigerian Nurses
April 2, 2026

In this episode of Care Anywhere, host Lea Sims sits down with Nigerian nurse entrepreneur and advocate Obafemi Arowosegbe to discuss leadership, mentorship, and the future of nursing in Africa. While still a nursing student, Obafemi founded the Nightingale Summit, a growing conference designed to empower nursing students and early-career nurses with leadership skills,…

Read More
Oncology
From Denial to Access: Rethinking Oncology Care Through AI, Clinical Trials, and Patient-Centered Innovation
April 1, 2026

The rapid expansion of precision medicine, biologics, and targeted cancer therapies is transforming oncology—but it’s also overwhelming a system not built to keep pace. In the U.S., cancer drugs now account for some of the highest-cost treatments in healthcare, and with that has come a surge in prior authorization requirements and denials. Studies suggest physicians…

Read More
Firefly
Pursuing the Impossible: The New Space Race with Firefly Aerospace Co-Founder Eric Salwan
April 1, 2026

Many companies set out to do something hard. Firefly Aerospace set out to do the impossible. After 10 years and several existential moments, Firefly did what no private company ever had: in 2025, it successfully landed on the Moon. Before Firefly, only countries had ever landed on the Moon—and it took extraordinary national effort…

Read More