If you store, process or transmit cardholder data, you are in scope — currently v4.0.1, twelve requirements, four levels by annual transaction volume.
PCI DSS is set by the PCI Security Standards Council and enforced contractually through acquirers and card brands; non-compliance can mean fines and ultimately loss of the ability to accept cards. Complexity tracks one thing above all: how far cardholder data reaches into your systems. The less card data your systems touch, the fewer controls you have to prove. So we map the data flows and shrink the scope first, then close control gaps, then complete the self-assessment questionnaire or support the QSA audit. Run in the other order, cost multiplies.
Trace cardholder data end to end and identify which systems genuinely touch card numbers. Tokenisation and hosted payment redirects can keep your own systems clear of real card data, which cuts audit scope substantially.
Network security controls, secure configuration, protection of stored data, encryption in transit, anti-malware, secure development and vulnerability management, need-to-know access, identification and authentication, physical access, logging and monitoring, regular testing, and security policy — each assessed against your current state with concrete remediation.
Establish your level from annual transaction volume, determine whether a self-assessment questionnaire suffices or a QSA on-site audit is required, and pick the SAQ type that matches how you actually take payments — the wrong type answers the wrong questions.
Vulnerability scanning, penetration testing, log retention and key rotation all run on defined cycles. We set up an annual calendar and a change review so nothing is crammed in before the deadline.
Work through checkout, payment, refund and reconciliation to chart where cardholder data really goes, and confirm which systems, networks and people fall in scope.
Assess current state against the twelve requirements while proposing practical ways to take systems out of scope — not touching card data at all is the most effective saving available.
Close technical and procedural gaps, and stand up evidence retention so every requirement has supporting material at validation time.
Complete the SAQ or support the QSA audit and obtain the attestation, then maintain scanning, testing and review against the annual calendar.
The PCI DSS cost curve is steep: every extra system inside the scope adds controls to prove, scans to run and evidence to keep. Spending on scope reduction usually beats spending on more controls.
Tell us how payments flow, whether your systems touch card numbers, and roughly what your annual volume is. We will come back with a level determination, scope reduction options and a plan.
Book a consultation