According toSection 12.2.3.3 of PCI DSS v4.0.1, aPartial Assessmentis defined as a result whereat least one PCI DSS requirement is marked as “Not Tested.”This is typically seen duringgap assessments or pre-validation efforts, not official compliance validation.
Option A:❌Incorrect. SAQs are self-assessments; Partial Assessment is a different concept.
Option B:❌Incorrect. Interim drafts are not labeled as “Partial”.
Option C:❌Incorrect. That is a misinterpretation of segmentation by payment channel.
Option D:✅Correct. "Not Tested" = Partial Assessment.
[Reference:PCI DSS v4.0.1 – Section 12.2.3.3 (Assessment Result Definitions)., , , ]
Submit