PCI DSS readiness & compliance support

Scope your cardholder data environment, close the gaps against PCI DSS v4.0.1, and get through a SAQ or a QSA-led Report on Compliance.

PCI DSS applies to any organisation that stores, processes or transmits cardholder data, and to service providers that can affect the security of that data. The current standard is PCI DSS v4.0.1, with several requirements that became mandatory in 2025.

How you validate depends on volume and role — a Self-Assessment Questionnaire (SAQ) for many merchants, or a QSA-led Report on Compliance (RoC) for higher volumes and most service providers. Readiness work gets the cardholder data environment small, well-defined and evidenced before validation starts.

What the engagement covers

Scoping and segmentation

Map where cardholder data flows, identify every connected system, and use network segmentation and payment-channel choices to keep the environment in scope as small as possible.

SAQ or RoC path

Determine the right validation route and SAQ type for your channels, or the scope of a Report on Compliance, and what each requirement means for your setup.

Gap assessment

Assess current controls against the applicable PCI DSS v4.0.1 requirements and produce a prioritised remediation plan with owners.

Remediation support

Support the teams closing gaps — access control, logging and monitoring, change management, secure development, vulnerability management and the v4 requirements around scripts and phishing resistance.

Evidence and validation

Prepare the documentation and evidence set, complete the SAQ and Attestation of Compliance, or work alongside your chosen QSA through the assessment.

Common questions

Talk through PCI DSS for your team

A short call to confirm scope, timeline and a firm price — before you commit to anything.