On June 15, 2009, MasterCard changed what some merchants (Level 1 & 2 merchants) must do to verify that they comply with the Payment Card Industry Data Security Standard (PCI DSS). These changes remove the ability for Level 1 merchants to validate compliance by using their internal audit functions, and require Level 2 merchants to engage an outside consultant to conduct an on-site assessment to validate compliance with the security requirements. This PCI FAQ guide answers questions received from merchants and is designed to help organizations prepare for their on-site assessments by anticipating common challenges and compliance issues.