PCI DSS readiness & compliance support
Scope your cardholder data environment, close the gaps against PCI DSS v4.0.1, and get through a SAQ or a QSA-led Report on Compliance.
PCI DSS applies to any organisation that stores, processes or transmits cardholder data, and to service providers that can affect the security of that data. The current standard is PCI DSS v4.0.1, with several requirements that became mandatory in 2025.
How you validate depends on volume and role — a Self-Assessment Questionnaire (SAQ) for many merchants, or a QSA-led Report on Compliance (RoC) for higher volumes and most service providers. Readiness work gets the cardholder data environment small, well-defined and evidenced before validation starts.
What the engagement covers
Scoping and segmentation
Map where cardholder data flows, identify every connected system, and use network segmentation and payment-channel choices to keep the environment in scope as small as possible.
SAQ or RoC path
Determine the right validation route and SAQ type for your channels, or the scope of a Report on Compliance, and what each requirement means for your setup.
Gap assessment
Assess current controls against the applicable PCI DSS v4.0.1 requirements and produce a prioritised remediation plan with owners.
Remediation support
Support the teams closing gaps — access control, logging and monitoring, change management, secure development, vulnerability management and the v4 requirements around scripts and phishing resistance.
Evidence and validation
Prepare the documentation and evidence set, complete the SAQ and Attestation of Compliance, or work alongside your chosen QSA through the assessment.
Common questions
Talk through PCI DSS for your team
A short call to confirm scope, timeline and a firm price — before you commit to anything.
