# PCI DSS scope labeling register

Structure for recording where the scope boundary runs and how the room is labeled to match.
This template does not interpret any PCI DSS requirement, determine scope, assert that a
requirement is satisfied, or replace the judgment of the assessor or the entity.

## Assessment and vocabulary

- Register ID / revision / prepared by / date:
- PCI DSS version named in the assessment:
- Source used for the requirement text:
- Date the scope states were defined:
- Definition source for the scope states:
- Scope decision owner:

## Scope states in use

- In scope — local wording:
- Connected to or security-impacting — local wording:
- Out of scope — local wording:
- Where the wording appears (diagram / register / cage / cabinet / port strip):

## Boundary inventory

For each boundary, record one row.

- Boundary ID:
- Type (cage / cabinet / panel / port range):
- Location reference:
- Scope state:
- Label text carried:
- Faces labeled (front / rear / both):
- Last verified on / by:

## Cross-connects crossing the boundary

- Local circuit ID:
- Provider circuit ID:
- Provider and order reference:
- A-end label / location:
- B-end label / location:
- In-scope cabinet touched:
- Present in scope register (yes / no):
- Last verified on / by:

## Removable media and portable devices

- Object ID:
- Identifier carried on the object:
- Where movement is recorded:
- Movement approver:
- Current location / status:

## Two-way reconciliation

- Population described as:
- Population extraction date:
- Exclusions and why:
- Direction one — register to room: run on / by / findings:
- Direction two — room to register: run on / by / findings:

## Exception log

- Exception ID:
- Found on / by / direction:
- What was found:
- Owner:
- Approved by / date:
- Closed on, or open with target date:

## Statement of limits

- What this register supports:
- What this register does not establish:
- Open items carried into the assessment:
