Confessions of the QSA: An Introduction to the Payment Card Industry Data Security Standard

 

As most in the industry know, a QSA must get certified by the PCI Security Standards Security Council to audit merchants for Payment Card Industry Data Security Standard (PCI DSS) compliance. Created in 2004 by major credit card brands, such as Visa and American Express, the council acts as a form of self-regulation.

So, how did Weaver become an expert on PCI, and what types of solutions does it offer its clients?

On this episode of Weaver: Beyond The Numbers, host Tyler Kern talked with Trip Hillman, Director of Cyber Security Services at Weaver, and Kyle Morris, Manager of IT at Advisory Services at Weaver. The trio dug into insights from Weaver’s Quality Security Assessor and explored how Weaver dove headfirst into PCI.

The PCI DSS applies to organizations that store, process, transmit or could affect the security of cardholder data. Companies that fall under this standard could do a variety of things, such as an annual self-assessment questionnaire, or bring in a third-party, independent QSA to do a full-blown report on compliance audit.

Morris is a QSA and started at Weaver about eight years ago. A few years into his career, they had a client, a service provider, start getting asked by their customers if they knew anything about PCI and the report on compliance. At the time, they hadn’t done anything with it, but decided to figure it out. That morphed into Weaver diving headfirst into PCI.

“We help people with self-assessment questionnaires or SAQs and everything from full-on ROCs for Fortune 50 Cloud Providers to small merchants to SaaS solutions,” Morris said.

Follow us on social media for the latest updates in B2B!

Image

Latest

TGR Foundation
Tiger Woods’ TGR Foundation Is Reimagining Educational Access Through STEAM, AI, and Community Partnerships
May 19, 2026

As schools across the United States continue grappling with post-pandemic learning loss, declining student engagement, and shrinking emergency funding, nonprofit organizations are increasingly stepping in to fill critical gaps. Recent national studies on literacy recovery, student engagement, and career-connected learning show that educators are facing significant post-pandemic challenges in keeping students connected to pathways that…

Read More
Talent
Higher Ed Must Build a Talent Supply Chain to Fix Workforce Readiness
May 18, 2026

The traditional pathway from college to career is starting to break down—and both universities and employers are feeling the strain. Higher education is under mounting pressure to prove career outcomes as employers question graduate readiness and internships decline. In fact, many institutions are reporting shrinking internship pipelines even as employers continue to prioritize prior…

Read More
healthcare
The Healthcare Talent Fix: Build Pipelines Early, Use Data, and Get the Experience Right
May 18, 2026

There’s a growing tension inside healthcare right now—between the people leaving the workforce and the patients still arriving every day. It’s a dynamic that leaders can no longer afford to ignore. The numbers make that clear: the Association of American Medical Colleges estimates that the U.S. could be short of as many as 86,000 physicians…

Read More
education
Just Thinking… About Federal Funds, Student Support, and the Future of Education with Eric Reaves
May 15, 2026

As conversations around the future of the U.S. Department of Education continue to intensify, educators and federal program leaders are facing mounting uncertainty about how federal funds will be managed, distributed, and regulated. At the same time, schools serving historically underserved students remain heavily reliant on programs like Title I and other federally supported initiatives…

Read More