Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.
Part of Compliance13 services in this practice area

Secure Cardholder Data

PCI DSS Compliance and Cardholder Data Security

PCI DSS is the security standard for anyone handling payment cards. We help you scope your environment, close the gaps, and get through your assessment cleanly.

See the engagement path, 6 phasesSee the full Compliance service index

Overview

The Payment Card Industry Data Security Standard, or PCI DSS, sets out how to protect cardholder data across the systems that store, process, or transmit it. It matters because banks and card brands require it, and a breach of card data is costly and public. Version 4.0 raises the bar on things like authentication and continuous controls. We help you shrink your scope where possible, meet the requirements that remain, and prepare the right report, whether that is a self-assessment questionnaire or a full Report on Compliance.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the PCI DSS engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Cardholder Data Flow. We map how card data moves through your environment and define the systems in scope. Reducing scope is the fastest way to cut effort. Activities: Trace cardholder data flows end to end; Identify systems that store, process, or transmit card data; Assess segmentation and tokenisation options; Confirm your merchant or service provider level. Hands over Scope Definition and Cardholder Data Flow Diagram. Phase 2, Gap Assessment. We measure your environment against the PCI DSS requirements and give you a prioritised remediation list. Activities: Assess controls against the 12 PCI DSS requirements; Review firewall rules, encryption, and logging; Check authentication against version 4.0 changes; Rank gaps by remediation effort and audit risk. Hands over PCI DSS Gap Assessment Report. Phase 3, Control Remediation. We help you implement the missing controls, from network segmentation to strong authentication and logging. Activities: Implement network segmentation around card data; Roll out multi-factor authentication; Configure logging and file integrity monitoring; Schedule quarterly ASV scans and penetration tests. Hands over Remediated Control Environment. Phase 4, Evidence Collection. We gather the evidence each requirement needs, so the assessment is a review, not a scramble. Activities: Map each requirement to its evidence artefacts; Collect scan results, configs, and policy records; Verify evidence covers the assessment period; Index the package for the assessor. Hands over Evidence Package Indexed by Requirement. Phase 5, Assessment Preparation. We prepare you for the SAQ or the QSA-led Report on Compliance, depending on your level. Activities: Select the correct SAQ type or ROC path; Run a dry-run walkthrough of assessor questions; Brief control owners on interview expectations; Fix last-mile issues before the assessment. Hands over Completed SAQ or Assessment Readiness Pack. Phase 6, Attestation and Maintenance. We support the attestation of compliance and help you keep controls running between assessments. Activities: Support QSA fieldwork and finding resolution; Finalise the attestation of compliance; Set the quarterly scan and review calendar; Monitor control drift between assessments. Hands over Attestation of Compliance. Each phase begins from the artefact the phase before it produced.

Phase 01 Scoping and Cardholder Data Flow

We map how card data moves through your environment and define the systems in scope. Reducing scope is the fastest way to cut effort.

What Happens In This Phase

  • Trace cardholder data flows end to end
  • Identify systems that store, process, or transmit card data
  • Assess segmentation and tokenisation options
  • Confirm your merchant or service provider level

The Handover

Scope Definition and Cardholder Data Flow Diagram

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Scoping and Cardholder Data Flow

    We map how card data moves through your environment and define the systems in scope. Reducing scope is the fastest way to cut effort.

    OutputScope Definition and Cardholder Data Flow Diagram

    Activities

    • Trace cardholder data flows end to end
    • Identify systems that store, process, or transmit card data
    • Assess segmentation and tokenisation options
    • Confirm your merchant or service provider level
  2. 02

    Gap Assessment

    We measure your environment against the PCI DSS requirements and give you a prioritised remediation list.

    OutputPCI DSS Gap Assessment Report

    Activities

    • Assess controls against the 12 PCI DSS requirements
    • Review firewall rules, encryption, and logging
    • Check authentication against version 4.0 changes
    • Rank gaps by remediation effort and audit risk
  3. 03

    Control Remediation

    We help you implement the missing controls, from network segmentation to strong authentication and logging.

    OutputRemediated Control Environment

    Activities

    • Implement network segmentation around card data
    • Roll out multi-factor authentication
    • Configure logging and file integrity monitoring
    • Schedule quarterly ASV scans and penetration tests
  4. 04

    Evidence Collection

    We gather the evidence each requirement needs, so the assessment is a review, not a scramble.

    OutputEvidence Package Indexed by Requirement

    Activities

    • Map each requirement to its evidence artefacts
    • Collect scan results, configs, and policy records
    • Verify evidence covers the assessment period
    • Index the package for the assessor
  5. 05

    Assessment Preparation

    We prepare you for the SAQ or the QSA-led Report on Compliance, depending on your level.

    OutputCompleted SAQ or Assessment Readiness Pack

    Activities

    • Select the correct SAQ type or ROC path
    • Run a dry-run walkthrough of assessor questions
    • Brief control owners on interview expectations
    • Fix last-mile issues before the assessment
  6. 06

    Attestation and Maintenance

    We support the attestation of compliance and help you keep controls running between assessments.

    OutputAttestation of Compliance

    Activities

    • Support QSA fieldwork and finding resolution
    • Finalise the attestation of compliance
    • Set the quarterly scan and review calendar
    • Monitor control drift between assessments

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Built by SecureRoot

TrustGrid

Our own GRC platform. Control mapping, evidence collection, policy workflow and third-party risk, all in one place.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the PCI DSS scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: Qualys, Tenable Nessus, Rapid7 InsightVM, Splunk, AWS Config, Jira, Confluence, Vanta. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 4 published standards: PCI DSS v4.0.1, PCI SAQ, PA-DSS, NIST SP 800-53.

What We Run

8 tools

  • Qualys
  • Tenable Nessus
  • Rapid7 InsightVM
  • Splunk
  • AWS Config
  • Jira
  • Confluence
  • Vanta

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

4 standards

  • PCI DSS v4.0.1
  • PCI SAQ
  • PA-DSSPCI SSC
  • NIST SP 800-53
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Scope and data flow diagram
  • Gap assessment report
  • Remediation plan
  • Evidence package
  • SAQ or Report on Compliance support

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Do I need a QSA or can I self-assess?

It depends on your merchant or service provider level and transaction volume. Smaller volumes often use a self-assessment questionnaire; larger ones need a QSA-led Report on Compliance.

How can we reduce our PCI DSS scope?

By segmenting card data away from the rest of your network and using tokenisation or a compliant payment provider. Less scope means fewer controls to prove.

What changed in PCI DSS 4.0?

It adds stronger authentication, more continuous controls, and a customised approach option. We help you meet the new requirements before they become mandatory.

Keep Moving Through Compliance

Service 6 of 13 in this practice area