PCI DSS v4.0.1

PCI DSS validation without over-scoping your environment

Get the cardholder data environment small and well-defined, close the gaps against PCI DSS v4.0.1, and get through a SAQ or a QSA-led Report on Compliance.

  • Built around PCI DSS v4.0.1, including the requirements mandatory since 31 March 2025
  • Scope reduction first — outsourcing, tokenisation and segmentation before controls
  • Right validation path confirmed with your acquirer (SAQ type or RoC)
  • Support completing the SAQ, or working alongside your QSA

Where do you stand?

A quick self-check before you get in touch

PCI DSS readiness check

Six quick questions, about a minute. You see the result straight away — no email required.

Why this comes up

PCI DSS applies to any organisation that stores, processes or transmits cardholder data, and to service providers that can affect the security of that data. How you validate depends on volume and role — a Self-Assessment Questionnaire for many merchants, a QSA-led Report on Compliance for higher volumes and most service providers.

The single biggest lever on cost and effort is scope: how much of your environment touches card data, and how well it is segmented from everything else. Getting that right early changes what the rest of the programme looks like.

What the engagement covers

Scoping and segmentation

Map where cardholder data flows, identify every connected system, and use payment-channel choices and network segmentation to keep the in-scope environment as small as possible.

SAQ or RoC path

Determine the right validation route and SAQ type for your channels, or the scope of a Report on Compliance, and what each requirement means for your setup.

Gap assessment

Assess current controls against the applicable PCI DSS v4.0.1 requirements and produce a prioritised remediation plan with owners.

Remediation support

Support the teams closing gaps — access control, logging and monitoring, change and vulnerability management, secure development, and the v4 requirements on payment-page scripts and phishing resistance.

Evidence and validation

Prepare the documentation and evidence set, complete the SAQ and Attestation of Compliance, or work alongside your chosen QSA through the assessment.

How it runs

  1. 01

    Scoping workshop

    Map card data flows, payment channels and connected systems, and agree the validation path with your acquirer.

  2. 02

    Scope reduction

    Where possible, remove card data from your environment — compliant providers, hosted pages, tokenisation — and segment what remains.

  3. 03

    Gap assessment

    Assess the in-scope environment against PCI DSS v4.0.1 and produce the remediation plan.

  4. 04

    Remediation

    Work through the plan with your teams and assemble the evidence set as controls come into place.

  5. 05

    Validation

    Complete the SAQ and Attestation of Compliance, or support your QSA through the Report on Compliance.

What you get

  • Cardholder data flow diagrams and PCI DSS scope definition
  • Validation-path recommendation (SAQ type or RoC)
  • Gap assessment against PCI DSS v4.0.1 and remediation plan
  • Policy and procedure set aligned to the standard
  • Evidence pack and completed SAQ / Attestation of Compliance, or QSA-assessment support

Common questions

More detail on the PCI DSS service page.

Frameworks and platforms we work across

AWS Security
Microsoft Azure
Google Cloud
ISO 27001
SOC 2
OWASP
PCI DSS

Scope your PCI DSS work

Book a short assessment call — we map where you are against the standard and agree the next step.