Card data compliance, scoped properly first
Most PCI DSS cost is self-inflicted — an environment that is far larger in scope than it needs to be. We reduce the scope first, then close the gaps.
If you touch cardholder data, it applies
Storing, processing or transmitting cardholder data brings you into scope — and so does anything that can affect the security of that environment.
- Merchants taking card payments, online or in person
- Service providers handling card data on behalf of others
- Call centres where card numbers are read aloud
- Anything connected to the cardholder data environment without proper segmentation
- Your acquirer or the card brands set the validation level; the standard itself is set by the PCI Security Standards Council
Reduce, then remediate
1. Scope assessment
We map every place card data enters, moves, rests and leaves. Almost every first engagement finds systems in scope that nobody expected.
2. Segmentation
Cutting the cardholder data environment down with proper network segmentation is the single biggest lever on cost and effort. We design it, build it and test it.
3. Gap assessment
Against the current version of the standard, requirement by requirement, with each gap owned and estimated.
4. Remediation
Encryption, key management, access control, logging, patching, secure configuration, vulnerability management. Implemented, not just written up.
5. Validation
Self-assessment questionnaire or report on compliance, depending on your level. We prepare the evidence and work alongside the QSA where one is involved.
6. Keeping it
PCI DSS is annual, with quarterly external scanning in between. We run the cycle rather than leaving you to remember it.
Common questions
Can we get out of scope entirely?
Sometimes, yes — by outsourcing card handling to a compliant provider and never touching the data yourself. Where that is possible it is usually the right answer, and we will say so.
What is the difference between an SAQ and a ROC?
A self-assessment questionnaire is completed by you; a report on compliance is produced by a qualified security assessor. Which one applies depends on your transaction volume and how you accept payments.
We are a service provider, not a merchant. Different rules?
The requirements are largely the same but the validation path and reporting obligations differ, and your customers will ask for your attestation. We handle both.
Does PCI DSS overlap with ISO 27001?
Substantially. If you are pursuing both, the control work should be done once and mapped twice. We plan them together.
Start with the scope, not the checklist.
A scoping assessment usually pays for itself in the remediation you avoid.
02 3537 5791
