/march-2025
New mandatory requirements effective March 31, 2025
$ npx -y skills add GRCEngClub/claude-grc-engineering --agent claude-codeHow it fires
How this command gets triggered: by you, by Claude, or both.
- Fires itselfClaude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/march-2025
Context preview
What this command does when you run it.
New mandatory requirements effective March 31, 2025
Command definition
march-2025.mddescription: New mandatory requirements effective March 31, 2025
March 2025 Mandatory Requirements
Requirements that became mandatory on March 31, 2025 (previously "future-dated").
Arguments
- `$1` - Requirement number or category (optional)
Critical March 2025 Requirements
Requirement 3: Protect Stored Account Data
| Req | Description | |-----|-------------| | 3.3.3 | SAD stored prior to authorization is encrypted | | 3.4.2 | Technical controls prevent copy/relocation of PAN | | 3.5.1.1 | Keyed cryptographic hashes if used for PAN storage | | 3.5.1.2 | Disk-level encryption only for removable media |
Requirement 5: Malware Protection
| Req | Description | |-----|-------------| | 5.3.3 | Anti-malware for removable media | | 5.4.1 | Mechanisms detect phishing attacks |
Requirement 6: Secure Development
| Req | Description | |-----|-------------| | 6.4.2 | WAF for public-facing web apps | | 6.4.3 | Payment page scripts inventoried and managed |
Requirement 7 & 8: Access Control
| Req | Description | |-----|-------------| | 7.2.5 | Application/system account access reviewed | | 7.2.5.1 | Access reviews include all access types | | 8.4.2 | MFA for all access into CDE | | 8.5.1 | MFA systems secured against replay | | 8.6.1 | Interactive login for app/system accounts managed | | 8.6.2 | Passwords/passphrases for interactive use not hardcoded | | 8.6.3 | Passwords for app/system accounts meet complexity |
Requirement 10: Logging
| Req | Description | |-----|-------------| | 10.4.1.1 | Automated audit log review mechanisms | | 10.4.2.1 | Targeted risk analysis for log review frequency | | 10.7.2 | Failures of security controls detected and reported | | 10.7.3 | Failures responded to promptly |
Requirement 11: Security Testing
| Req | Description | |-----|-------------| | 11.3.1.1 | Internal vulnerability scans via authenticated scanning | | 11.3.1.2 | Internal scans performed after significant changes | | 11.4.7 | Multi-tenant service providers support pen testing | | 11.5.1.1 | IDS/IPS detect covert malware channels | | 11.6.1 | Change/tamper detection on payment pages |
Requirement 12: Policies
| Req | Description | |-----|-------------| | 12.3.1 | Targeted risk analysis for each flexible requirement | | 12.3.2 | Targeted risk analyses documented and reviewed |
Priority Actions
1. **Payment page security** (6.4.3, 11.6.1) - Script inventory, change detection 2. **MFA everywhere** (8.4.2, 8.5.1) - CDE access requires MFA 3. **Automated log review** (10.4.1.1) - Manual review no longer sufficient 4. **Authenticated scanning** (11.3.1.1) - Better vulnerability detection
Example
/pci-dss:march-2025
/pci-dss:march-2025 8
/pci-dss:march-2025 "payment page"
Read more
description: New mandatory requirements effective March 31, 2025
March 2025 Mandatory Requirements
Requirements that became mandatory on March 31, 2025 (previously "future-dated").
Arguments
- `$1` - Requirement number or category (optional)
Critical March 2025 Requirements
Requirement 3: Protect Stored Account Data
| Req | Description | |-----|-------------| | 3.3.3 | SAD stored prior to authorization is encrypted | | 3.4.2 | Technical controls prevent copy/relocation of PAN | | 3.5.1.1 | Keyed cryptographic hashes if used for PAN storage | | 3.5.1.2 | Disk-level encryption only for removable media |
Requirement 5: Malware Protection
| Req | Description | |-----|-------------| | 5.3.3 | Anti-malware for removable media | | 5.4.1 | Mechanisms detect phishing attacks |
Requirement 6: Secure Development
| Req | Description | |-----|-------------| | 6.4.2 | WAF for public-facing web apps | | 6.4.3 | Payment page scripts inventoried and managed |
Requirement 7 & 8: Access Control
| Req | Description | |-----|-------------| | 7.2.5 | Application/system account access reviewed | | 7.2.5.1 | Access reviews include all access types | | 8.4.2 | MFA for all access into CDE | | 8.5.1 | MFA systems secured against replay | | 8.6.1 | Interactive login for app/system accounts managed | | 8.6.2 | Passwords/passphrases for interactive use not hardcoded | | 8.6.3 | Passwords for app/system accounts meet complexity |
Requirement 10: Logging
| Req | Description | |-----|-------------| | 10.4.1.1 | Automated audit log review mechanisms | | 10.4.2.1 | Targeted risk analysis for log review frequency | | 10.7.2 | Failures of security controls detected and reported | | 10.7.3 | Failures responded to promptly |
Requirement 11: Security Testing
| Req | Description | |-----|-------------| | 11.3.1.1 | Internal vulnerability scans via authenticated scanning | | 11.3.1.2 | Internal scans performed after significant changes | | 11.4.7 | Multi-tenant service providers support pen testing | | 11.5.1.1 | IDS/IPS detect covert malware channels | | 11.6.1 | Change/tamper detection on payment pages |
Requirement 12: Policies
| Req | Description | |-----|-------------| | 12.3.1 | Targeted risk analysis for each flexible requirement | | 12.3.2 | Targeted risk analyses documented and reviewed |
Priority Actions
1. **Payment page security** (6.4.3, 11.6.1) - Script inventory, change detection 2. **MFA everywhere** (8.4.2, 8.5.1) - CDE access requires MFA 3. **Automated log review** (10.4.1.1) - Manual review no longer sufficient 4. **Authenticated scanning** (11.3.1.1) - Better vulnerability detection
Example
/pci-dss:march-2025 /pci-dss:march-2025 8 /pci-dss:march-2025 "payment page"
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Other commands on trust-center.
- /research
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Open command - /collect
Query AWS for compliance-relevant configuration across IAM, S3, CloudTrail, EBS, and emit findings conforming to the v1 contract.
Open command - /setup
Install the frdocx-to-froscal-ssp Python pipeline and verify its dependencies. Idempotent.
Open command - /status
Check the deployment status of the trust center.
Open command - /scan
Run testssl.sh against one or more HTTPS endpoints and emit v1 Findings mapped to SOC 2, NIST 800-53, PCI DSS 4.0.1, ISO 27001, and SCF controls.
Open command - /compliance-posture
Serve a localhost compliance posture dashboard from monitor-continuous JSON
Open command

