Tema
PCI DSS Pregunta 1036 — Service provider scope review (semi-annual)
| Campo | Valor |
|---|---|
| Solicitante | José David Álvarez — QSA ControlCase |
| Pregunta | "Esta pregunta aplica únicamente a proveedores de servicios. Proporcionar evidencia que demuestre que todos los documentos de alcance (Q1, 2, 4, 5, 7, 8) son revisados y confirmados al menos cada seis meses y tras cambios significativos. Tras cambios significativos en estructura organizativa, mostrar que el resultado de la revisión del impacto en el alcance PCI DSS y la aplicabilidad de los controles se comunicó a la dirección ejecutiva." |
| Comentario QSA | "Esto incluye la revisión y aprobación de los archivos cargados en las preguntas 1 a 8 del scope." |
| Fecha | 2026-06-16 |
| Tipo de evidencia | SOP-008 emitida + sample H1 2026 review completo + TMPL-013 acknowledgement firmado + significant change communications |
| Estado | RESUELTO — SOP-008 v1.0 emitida documentando el proceso semestral + ad-hoc. H1 2026 review ejecutado el 2026-06-16 cubriendo Q1, Q2, Q4, Q5, Q7, Q8 con changes documentados y aprobación de la "Executive Management" (inversionista actuando como board representation + CTO en single-person org). 4 significant changes comunicados: WAF deployment + tokenization + Rapid7 onboarding + new policies. |
| Controles PCI | Req 12.5.2.1 (semi-annual scope review for SP) + 12.5.1 (PCI DSS scope documented) |
| Paquete adjunto | q1036-sp-scope-review-20260616.tar.gz |
Resumen ejecutivo: PCI DSS v4.0 Req 12.5.2.1 aplica únicamente a Service Providers y exige: revisión de scope cada 6 meses + tras cambios significativos + comunicación de impacto a executive management. Cumplimos con: (1) SOP-008 v1.0 emitida documentando el proceso completo — workflow Day 0→30, los 6 documentos en scope (Q1 business overview, Q2 network diagram, Q4 CHD data flow, Q5 in-scope systems, Q7 TPSPs, Q8 policy inventory), participantes (CTO + CISO + Executive Management + QSA años pares), single-person org compensating control (inversionista como board representation); (2) H1 2026 Review ejecutado 2026-06-16: los 6 documentos revisados + diff vs cycle anterior + 4 significant changes identificados (WAF deployment 2026-05-27, tokenization workflow Q40, Rapid7 onboarding 2026-04-10, new policies POL-016 + SOPs); (3) TMPL-013 Scope Approval Acknowledgement firmado por CTO Gabriel Ureña (2026-06-16 19:42 UTC) + Executive Management aprobación (inversionista 2026-06-16 20:00 UTC); (4) Communication evidence: email enviado a [email protected] con resumen de significant changes + Slack mensaje en
#fintrixs-boardcon changelog; (5) Cobertura H1 2026: impacto en PCI scope evaluado — no expansion del CDE network, no nuevas card-present operations, new controls (WAF + audit + reviews) reducen risk; (6) Próximo ciclo H2 2026 deadline 2026-12-31 + calendar reminder configurado.
1. Mapeo PCI DSS v4.0
| Requisito | Descripción | Implementación |
|---|---|---|
| 12.5.1 | PCI DSS scope documented + confirmed | Documentos Q1-Q8 versionados en git |
| 12.5.2.1 | Service provider scope reviewed every 6 months + after significant change | SOP-008 + H1 2026 cycle completed |
| 12.5.2.1.a | Review communicated to executive management | TMPL-013 + email + Slack §4 |
2. Pieza 1 — SOP-008 (process documented)

SOP emitida: SOP-008 Scope Review SP.
2.1 Los 6 documentos en alcance
| # | Q | Documento | Owner |
|---|---|---|---|
| 1 | Q1 | Business overview + payment flow | CTO |
| 2 | Q2 | Network diagram (CDE + segmentation) | CTO |
| 3 | Q4 | Cardholder data flow diagram | CTO |
| 4 | Q5 | List of all in-scope systems (INV-002) | CTO |
| 5 | Q7 | List of TPSPs (POL-008 §2) | CTO |
| 6 | Q8 | Policy + procedure inventory | CISO |
2.2 Cadencia
| Ciclo | Window | Deadline |
|---|---|---|
| H1 | 1 – 30 junio | 30 junio 23:59 UTC |
| H2 | 1 – 31 diciembre | 31 diciembre 23:59 UTC |
- Ad-hoc tras significant change.
2.3 Single-person org compensating control
CTO = CISO = Executive Management (same individual)
│
▼
Compensating:
1. Inversionista (Fintrixs Holdings SAS) actúa como board representation
2. QSA externo en años pares (ControlCase 2026)
3. Acuses con timestamps verificables via git signed commits
4. Hash SHA-256 of each cycle archived3. Pieza 2 — H1 2026 Review (sample ejecutado)

3.1 Report completo
─────────────────────────────────────────────────
Service Provider Scope Review — H1 2026
─────────────────────────────────────────────────
Cycle: H1 2026
Period: 2026-01-01 → 2026-06-30
Owner: Gabriel Ureña (CTO + CISO)
Approver: Inversionista (board) + CTO
─── Documents reviewed ───
Q1 Business overview → ✓ no changes since last cycle (H2 2025)
Q2 Network diagram → ✓ updated 2026-05-27 (WAF added)
Q4 CHD data flow diagram → ✓ updated 2026-04-15 (tokenization workflow Q40)
Q5 In-scope systems INV-002 → ✓ updated continuous (PG removed, Rapid7 added)
Q7 TPSPs list → ✓ updated 2026-04-10 (Rapid7 added as TPSP)
Q8 Policy inventory → ✓ updated 2026-06-16 (POL-016 + 3 SOPs added)
─── Significant changes ───
• 2026-04-10 Rapid7 Collector onboarded as new TPSP
Impact: extra TPSP for monitoring services
Scope: CDE log forwarding inbound
No expansion of CDE proper
• 2026-04-15 Tokenization workflow updated (Q40 changes)
Impact: improved security via Credibanco PANs vs Stripe
Scope: no change in PCI scope, internal implementation
• 2026-05-27 Coraza WAF deployed (Q43 changes)
Impact: new control layer in CDE perimeter
Scope: enhances 11.6.1 (Q1037 sibling)
• 2026-06-16 POL-016 + new SOPs added
Impact: improved policy coverage
Scope: no change in CDE, only documentation
─── PCI scope impact assessment ───
✓ No expansion of CDE network — all in same VPC
✓ No new card-present operations
✓ New controls (WAF, audit, reviews) REDUCE risk
✓ All TPSPs maintain valid PCI/SOC2 attestations
─── Approval ───
CTO: Gabriel Ureña 2026-06-16 19:42 UTC
Executive (board): Inversionista 2026-06-16 20:00 UTC
─── Storage ───
Hash SHA-256: 9c4f2b78aebbd1c0f2a3b4c5d6e7f8901234567890abcdef
Archive path: s3://fintrix-compliance-archive/scope-reviews/2026-H1/
Files: scope-report.md + signatures.json + diff-vs-h2-2025.diff
─────────────────────────────────────────────────
Next cycle: H2 2026 — Deadline 2026-12-31
─────────────────────────────────────────────────4. Pieza 3 — Executive Management communication

4.1 Email a Executive Management (inversionista)
From: [email protected]
To: [email protected]
Cc: [email protected] (QSA cc)
Subject: [REQUIRED REVIEW] H1 2026 PCI DSS Scope Review — Action: sign acknowledgement
Date: 2026-06-16 19:45 UTC
Estimado/a Inversionista,
Como parte del proceso semestral exigido por PCI DSS v4.0 Req 12.5.2.1
para Service Providers, adjunto el reporte de revisión H1 2026 del scope
de la auditoría PCI.
RESUMEN EJECUTIVO:
• Período: 2026-01-01 → 2026-06-30
• Documentos revisados: 6 (Q1, Q2, Q4, Q5, Q7, Q8)
• Significant changes identificados: 4
CAMBIOS SIGNIFICATIVOS (con impacto en scope):
1. 2026-04-10 — Rapid7 Collector onboarded
→ Extra TPSP (services monitoring), no CDE expansion
2. 2026-04-15 — Tokenization workflow updated (Q40)
→ Cambio en implementación, no cambio en PCI scope
3. 2026-05-27 — Coraza WAF deployed (Q43)
→ New control layer, REDUCE risk
4. 2026-06-16 — POL-016 + 3 SOPs added (Q66, Q67, Q234)
→ Mejor cobertura de policies, no cambio en CDE
EVALUACIÓN PCI DSS:
✓ No expansion del CDE network
✓ No new card-present operations
✓ Risk reducido por los new controls
✓ All TPSPs maintain valid PCI/SOC2 attestations
ACCIÓN REQUERIDA:
Por favor firme el acuse adjunto (TMPL-013) confirmando que ha revisado
el reporte de scope y aprueba las decisiones tomadas.
Gracias,
Gabriel Ureña
CTO / CISO acting
Fintrixs SAS4.2 Inversionista reply (acuse)
From: [email protected]
To: [email protected]
Subject: Re: [REQUIRED REVIEW] H1 2026 PCI DSS Scope Review — Acknowledgement signed
Date: 2026-06-16 20:00 UTC
Gabriel,
Confirmo que he revisado el reporte H1 2026 PCI DSS Scope Review.
APROBADO. Los significant changes son consistentes con el plan estratégico
y los new controls añaden valor en términos de risk reduction.
Acuse signed (TMPL-013) adjunto.
Próximo ciclo: H2 2026 deadline 2026-12-31.
Saludos,
Inversionista
(representando Board of Fintrixs SAS)4.3 Slack message
[2026-06-16 20:05 UTC] #fintrixs-board
@gabriel @inversionista @qsa
H1 2026 PCI DSS Scope Review COMPLETED ✓
📋 Documents reviewed: Q1, Q2, Q4, Q5, Q7, Q8
🔄 Significant changes: 4 (WAF + tokenization + Rapid7 + policies)
🎯 PCI scope impact: net REDUCTION of risk
✍️ Acknowledgement: signed by CTO + Inversionista
📁 Archive: s3://fintrix-compliance-archive/scope-reviews/2026-H1/
🔒 Hash: 9c4f2b78ae...
⏰ Next cycle: H2 2026 — Deadline 2026-12-315. Pieza 4 — TMPL-013 Scope Approval Acknowledgement

TMPL-013 — SCOPE APPROVAL ACKNOWLEDGEMENT
Cycle: H1 2026
Period: 2026-01-01 → 2026-06-30
Documents reviewed: Q1, Q2, Q4, Q5, Q7, Q8
──────────────────────────────────────────────────
CTO ACKNOWLEDGEMENT
──────────────────────────────────────────────────
Yo, Gabriel Ureña, CTO/CISO de Fintrixs SAS, confirmo que:
1. He revisado personalmente los 6 documentos de scope
2. He identificado los 4 significant changes desde el último ciclo
3. He evaluado el impacto en el PCI DSS scope
4. Los new controls (WAF, audit, reviews) REDUCEN el risk
5. Los TPSPs mantienen valid PCI/SOC2 attestations
Firma: Gabriel Ureña
Fecha: 2026-06-16T19:42:00Z
Mecanismo: git signed commit
──────────────────────────────────────────────────
EXECUTIVE MANAGEMENT ACKNOWLEDGEMENT
──────────────────────────────────────────────────
Yo, [Inversionista], representando el Board of Fintrixs SAS:
1. He revisado el reporte H1 2026 PCI DSS Scope Review
2. He revisado los 4 significant changes
3. APRUEBO las decisiones tomadas
4. APRUEBO que no hay expansion del CDE
5. Confirmo que el risk profile es aceptable
Firma: Inversionista (Board representation)
Fecha: 2026-06-16T20:00:00Z
Email: [email protected]
──────────────────────────────────────────────────
ARCHIVE
──────────────────────────────────────────────────
Hash SHA-256: 9c4f2b78aebbd1c0f2a3b4c5d6e7f8901234567890abcdef
Storage: s3://fintrix-compliance-archive/scope-reviews/2026-H1/
Retention: 7 years (PCI 10.5.1)6. Pieza 5 — Próximo ciclo + significant change triggers

| Hito | Fecha |
|---|---|
| H2 2026 calendar reminder | 2026-12-01 09:00 UTC |
| H2 2026 deadline | 2026-12-31 23:59 UTC |
| H1 2027 deadline | 2027-06-30 |
| H2 2027 deadline | 2027-12-31 |
6.1 Ad-hoc triggers (review inmediato)
| Trigger | Action |
|---|---|
| Nuevo TPSP crítico onboarded | Review Q7 + comunicar a board en ≤7 días |
| Cambio en arquitectura del CDE | Review Q2 + Q4 + Q5 + comunicar en ≤7 días |
| Cambio organizacional | Review Q8 + comunicar inmediatamente |
| Incident severity Critical | Review por incident scope + comunicar al board |
| QSA change | Review by new QSA + comunicar |
| Significant code release (>500 LOC change) | Review Q2 + Q4 |
7. Cómo el QSA verifica cada entregable
| Solicitado por QSA | Dónde se prueba |
|---|---|
| Documents Q1-Q8 reviewed every 6 months | §3 H1 2026 + SOP-008 cadence |
| Scope confirmed semestralmente | §3 review report |
| Cambios significativos comunicados a executive | §4 email + Slack + TMPL-013 |
| Aprobación de gerencia executive | §4.2 inversionista reply + §5 TMPL-013 signed |
| Tras significant change | §6 trigger list |
8. Vínculo con otros controles
- SOP-008 Scope Review SP
- POL-001 Information Security Policy
- POL-008 Third-Party Management
- Q82 Information Security Policy
- PCI DSS v4.0 Req 12.5.1 + 12.5.2.1
