Confessions of the QSA: An Introduction to the Payment Card Industry Data Security Standard

 

As most in the industry know, a QSA must get certified by the PCI Security Standards Security Council to audit merchants for Payment Card Industry Data Security Standard (PCI DSS) compliance. Created in 2004 by major credit card brands, such as Visa and American Express, the council acts as a form of self-regulation.

So, how did Weaver become an expert on PCI, and what types of solutions does it offer its clients?

On this episode of Weaver: Beyond The Numbers, host Tyler Kern talked with Trip Hillman, Director of Cyber Security Services at Weaver, and Kyle Morris, Manager of IT at Advisory Services at Weaver. The trio dug into insights from Weaver’s Quality Security Assessor and explored how Weaver dove headfirst into PCI.

The PCI DSS applies to organizations that store, process, transmit or could affect the security of cardholder data. Companies that fall under this standard could do a variety of things, such as an annual self-assessment questionnaire, or bring in a third-party, independent QSA to do a full-blown report on compliance audit.

Morris is a QSA and started at Weaver about eight years ago. A few years into his career, they had a client, a service provider, start getting asked by their customers if they knew anything about PCI and the report on compliance. At the time, they hadn’t done anything with it, but decided to figure it out. That morphed into Weaver diving headfirst into PCI.

“We help people with self-assessment questionnaires or SAQs and everything from full-on ROCs for Fortune 50 Cloud Providers to small merchants to SaaS solutions,” Morris said.

Follow us on social media for the latest updates in B2B!

Image

Latest

radiology
Growing Without Compromise: How Vision Radiology Balances Scale, AI, and Clinical Quality
June 4, 2026

Radiology sits at the center of a modern healthcare squeeze: imaging volumes are climbing, hospitals need faster reads, and there simply are not enough radiologists to meet demand the old way. At the same time, remote work and AI are reshaping what a clinical practice can look like. The challenge is no longer whether…

Read More
Radar
Physical Retail’s Next Infrastructure Layer: Item-Level Intelligence with Radar
June 4, 2026

Physical retail is under pressure to become as measurable and responsive as e-commerce. While retailers have spent years optimizing digital channels with real-time data, store teams have often had to make decisions with incomplete inventory visibility and delayed operational signals. That gap matters because stores still account for 80% of U.S. retail sales, making…

Read More
Healthcare in Pakistan
From Institutional Excellence to Population-Level Access: How Pakistan Can Bridge Its Healthcare Divide
June 1, 2026

Healthcare systems are under pressure almost everywhere, but the strain is especially visible in lower-resource settings where demand is rising faster than infrastructure. In Pakistan, that pressure is playing out across a system that has to serve more than 250 million people with limited public investment. Public health spending remains below 1% of GDP,…

Read More
Engineering
Scaling Experiential Learning in the Curriculum: How Iron Range Engineering Transformed Engineering Education
June 1, 2026

Engineering has transformed nearly every part of modern life, from the phones in our pockets to the systems powering global industry. But the way engineers are educated has often moved far more slowly than the profession itself. Employers are asking for graduates who can navigate ambiguity, communicate across teams, and contribute meaningfully from the…

Read More