Skip to content

Global — Payments

PCI DSS Compliance Assessment

Scoping review, gap assessment and remediation planning against the Payment Card Industry Data Security Standard — for organisations that store, process or transmit cardholder data.

Scope is where compliance is won or lost

The single most consequential decision in a PCI DSS programme is scope definition. Every system that stores, processes or transmits cardholder data is in scope — and so is every system connected to or able to affect the security of that environment. Organisations routinely underestimate the second category, which is how an environment believed to be twenty servers turns out to be four hundred.

Getting scope right early, and reducing it deliberately through segmentation and tokenisation, is almost always cheaper than compliance across an unnecessarily large estate. We start every engagement here.

What the assessment covers

PCI DSS is organised into control requirements spanning network security, protection of stored data, vulnerability management, access control, monitoring and testing, and information security policy. Version 4.x introduced a customised approach allowing alternative implementations that meet the stated control objective, along with a substantial number of requirements that became mandatory following a defined transition period.

  • Cardholder data discovery — locating card data across the estate, including where it should not be.
  • Scope definition and segmentation validation, including penetration testing of segmentation controls.
  • Requirement-by-requirement gap assessment against the applicable version.
  • Compensating and customised control evaluation, where a stated requirement cannot be met directly.
  • Evidence readiness — whether you can actually produce what an assessor will request.
  • Self-assessment questionnaire selection and completion support, where a full assessment is not required.

Scope is where compliance is won or lost

CDE card data Connected systems In scope whether you like it or not Wider estate Out of scope only if segmentation holds Scope reduction Cheaper than compliance across the wholeestate

Our role and its limits

We provide readiness assessment, gap analysis, remediation planning and internal audit. Formal validation of compliance for entities requiring a Report on Compliance must be performed by a PCI-registered Qualified Security Assessor, and external vulnerability scanning for compliance purposes must be performed by an Approved Scanning Vendor. Where you require these, we will tell you plainly and help you prepare for them rather than implying we can substitute for them. Confirm your specific validation requirements with your acquiring bank or the relevant card scheme.

How the engagement runs

  1. 1

    Data discovery

    Find where cardholder data actually lives, including in places nobody expected.

  2. 2

    Scope definition

    Define the cardholder data environment and the connected systems that fall in scope with it.

  3. 3

    Scope reduction

    Identify segmentation and tokenisation opportunities that legitimately shrink the compliance burden.

  4. 4

    Gap assessment

    Requirement-by-requirement assessment with evidence.

  5. 5

    Remediation planning

    Sequenced plan with effort, cost indication and dependency mapping.

  6. 6

    Validation readiness

    Prepare the evidence package ahead of formal assessment.

What you receive

Cardholder data discovery report
Documented scope definition with segmentation assessment
Requirement-by-requirement gap analysis
Scope reduction recommendations with cost impact
Prioritised remediation roadmap
Evidence pack prepared for formal assessment

Frequently asked questions

No. A Report on Compliance can only be issued by a Qualified Security Assessor registered with the PCI Security Standards Council. We prepare you for that assessment and provide the internal assurance around it. Any firm claiming to issue a RoC without QSA registration is misrepresenting what it can do.

Almost certainly yes, though the scope may be small and a self-assessment questionnaire may suffice rather than a full assessment. Even where you never touch card data, you retain responsibility for the integrity of the redirect and for vendor due diligence. The right questionnaire depends on how the payment page is implemented — a genuinely hosted page and an iframe carry different obligations.

For an organisation starting without formal PCI controls, six to twelve months is realistic. The long poles are usually network segmentation, logging and monitoring coverage, and key management. Scope reduction done early is the most reliable way to shorten it.

Related services

Not sure this is the framework that binds you?

Six questions, ninety seconds, runs in your browser. It will tell you which frameworks apply and why.

Request a proposal
Top