PCI DSS Compliance

PCI DSS

Card data compliance, scoped properly first

Most PCI DSS cost is self-inflicted — an environment that is far larger in scope than it needs to be. We reduce the scope first, then close the gaps.

Scope first
before controls
SAQ or ROC
we determine which
2 clients
taken through validation
Who it applies to

If you touch cardholder data, it applies

Storing, processing or transmitting cardholder data brings you into scope — and so does anything that can affect the security of that environment.

  • Merchants taking card payments, online or in person
  • Service providers handling card data on behalf of others
  • Call centres where card numbers are read aloud
  • Anything connected to the cardholder data environment without proper segmentation
  • Your acquirer or the card brands set the validation level; the standard itself is set by the PCI Security Standards Council
How we run it

Reduce, then remediate

1. Scope assessment

We map every place card data enters, moves, rests and leaves. Almost every first engagement finds systems in scope that nobody expected.

2. Segmentation

Cutting the cardholder data environment down with proper network segmentation is the single biggest lever on cost and effort. We design it, build it and test it.

3. Gap assessment

Against the current version of the standard, requirement by requirement, with each gap owned and estimated.

4. Remediation

Encryption, key management, access control, logging, patching, secure configuration, vulnerability management. Implemented, not just written up.

5. Validation

Self-assessment questionnaire or report on compliance, depending on your level. We prepare the evidence and work alongside the QSA where one is involved.

6. Keeping it

PCI DSS is annual, with quarterly external scanning in between. We run the cycle rather than leaving you to remember it.

Before you ask

Common questions

Can we get out of scope entirely?

Sometimes, yes — by outsourcing card handling to a compliant provider and never touching the data yourself. Where that is possible it is usually the right answer, and we will say so.

What is the difference between an SAQ and a ROC?

A self-assessment questionnaire is completed by you; a report on compliance is produced by a qualified security assessor. Which one applies depends on your transaction volume and how you accept payments.

We are a service provider, not a merchant. Different rules?

The requirements are largely the same but the validation path and reporting obligations differ, and your customers will ask for your attestation. We handle both.

Does PCI DSS overlap with ISO 27001?

Substantially. If you are pursuing both, the control work should be done once and mapped twice. We plan them together.

Start with the scope, not the checklist.

A scoping assessment usually pays for itself in the remediation you avoid.

02 3537 5791