PCI DSS Scope Reducer
18 of 22 systems are in PCI DSS scope (11 CDE, 7 connected-to or security-impacting); combining all options would leave 5 in scope, with SAQ A for e-commerce, SAQ P2PE for card-present and SAQ C-VT for mail and telephone order.
The inventory says POS-TERM-01 processes and transmits cardholder data, so it is part of the CDE; the flow list shows it on 1 card data flow: POS-TERM-01 -> POS-SRV-01 (TCP/443).
Method1CDE: a system that stores, processes or transmits cardholder data, or shares a network segment with one (PCI SSC scoping guidance: without segmentation the whole segment is in scope).
2Cardholder data is traced through the flow list from where it enters (terminals, the Internet, keyed entry, storage, TPSPs); a flow marked Y proves both ends handle it, even if the inventory says otherwise.
| System | Function | Segment |
|---|---|---|
| POS-TERM-01 | EMV PIN pad payment terminal (store 12) | Store LAN |
| POS-TERM-02 | EMV PIN pad payment terminal (store 12) | Store LAN |
| POS-SRV-01 | Store POS server (integrated POS application) | Store LAN |
System inventory and network flow list
Scope classification, SAQ eligibility and reduction options (Scope classification (CSV), Scope summary (JSON), Reduction options (CSV))
$3,500 / month, 30% to the referring partner
Read in memory for the session, never stored, never used to train a model.
Not financial, investment, banking or securities advice. Filings and screening results must be reviewed by a qualified compliance professional. Privacy and security findings are not legal advice or an audit opinion. Confirm them with privacy counsel or a qualified assessor.