Global — Payments
PCI DSS Compliance Assessment
Scoping review, gap assessment and remediation planning against the Payment Card Industry Data Security Standard — for organisations that store, process or transmit cardholder data.
Scope is where compliance is won or lost
The single most consequential decision in a PCI DSS programme is scope definition. Every system that stores, processes or transmits cardholder data is in scope — and so is every system connected to or able to affect the security of that environment. Organisations routinely underestimate the second category, which is how an environment believed to be twenty servers turns out to be four hundred.
Getting scope right early, and reducing it deliberately through segmentation and tokenisation, is almost always cheaper than compliance across an unnecessarily large estate. We start every engagement here.
What the assessment covers
PCI DSS is organised into control requirements spanning network security, protection of stored data, vulnerability management, access control, monitoring and testing, and information security policy. Version 4.x introduced a customised approach allowing alternative implementations that meet the stated control objective, along with a substantial number of requirements that became mandatory following a defined transition period.
- Cardholder data discovery — locating card data across the estate, including where it should not be.
- Scope definition and segmentation validation, including penetration testing of segmentation controls.
- Requirement-by-requirement gap assessment against the applicable version.
- Compensating and customised control evaluation, where a stated requirement cannot be met directly.
- Evidence readiness — whether you can actually produce what an assessor will request.
- Self-assessment questionnaire selection and completion support, where a full assessment is not required.
Scope is where compliance is won or lost
Our role and its limits
We provide readiness assessment, gap analysis, remediation planning and internal audit. Formal validation of compliance for entities requiring a Report on Compliance must be performed by a PCI-registered Qualified Security Assessor, and external vulnerability scanning for compliance purposes must be performed by an Approved Scanning Vendor. Where you require these, we will tell you plainly and help you prepare for them rather than implying we can substitute for them. Confirm your specific validation requirements with your acquiring bank or the relevant card scheme.
How the engagement runs
-
1
Data discovery
Find where cardholder data actually lives, including in places nobody expected.
-
2
Scope definition
Define the cardholder data environment and the connected systems that fall in scope with it.
-
3
Scope reduction
Identify segmentation and tokenisation opportunities that legitimately shrink the compliance burden.
-
4
Gap assessment
Requirement-by-requirement assessment with evidence.
-
5
Remediation planning
Sequenced plan with effort, cost indication and dependency mapping.
-
6
Validation readiness
Prepare the evidence package ahead of formal assessment.
What you receive
Frequently asked questions
Related services
Not sure this is the framework that binds you?
Six questions, ninety seconds, runs in your browser. It will tell you which frameworks apply and why.
Request a proposal