Secure Cardholder Data
PCI DSS Compliance and Cardholder Data Security
PCI DSS is the security standard for anyone handling payment cards. We help you scope your environment, close the gaps, and get through your assessment cleanly.
See the engagement path, 6 phasesSee the full Compliance service index
Overview
The Payment Card Industry Data Security Standard, or PCI DSS, sets out how to protect cardholder data across the systems that store, process, or transmit it. It matters because banks and card brands require it, and a breach of card data is costly and public. Version 4.0 raises the bar on things like authentication and continuous controls. We help you shrink your scope where possible, meet the requirements that remain, and prepare the right report, whether that is a self-assessment questionnaire or a full Report on Compliance.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the PCI DSS engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Cardholder Data Flow. We map how card data moves through your environment and define the systems in scope. Reducing scope is the fastest way to cut effort. Activities: Trace cardholder data flows end to end; Identify systems that store, process, or transmit card data; Assess segmentation and tokenisation options; Confirm your merchant or service provider level. Hands over Scope Definition and Cardholder Data Flow Diagram. Phase 2, Gap Assessment. We measure your environment against the PCI DSS requirements and give you a prioritised remediation list. Activities: Assess controls against the 12 PCI DSS requirements; Review firewall rules, encryption, and logging; Check authentication against version 4.0 changes; Rank gaps by remediation effort and audit risk. Hands over PCI DSS Gap Assessment Report. Phase 3, Control Remediation. We help you implement the missing controls, from network segmentation to strong authentication and logging. Activities: Implement network segmentation around card data; Roll out multi-factor authentication; Configure logging and file integrity monitoring; Schedule quarterly ASV scans and penetration tests. Hands over Remediated Control Environment. Phase 4, Evidence Collection. We gather the evidence each requirement needs, so the assessment is a review, not a scramble. Activities: Map each requirement to its evidence artefacts; Collect scan results, configs, and policy records; Verify evidence covers the assessment period; Index the package for the assessor. Hands over Evidence Package Indexed by Requirement. Phase 5, Assessment Preparation. We prepare you for the SAQ or the QSA-led Report on Compliance, depending on your level. Activities: Select the correct SAQ type or ROC path; Run a dry-run walkthrough of assessor questions; Brief control owners on interview expectations; Fix last-mile issues before the assessment. Hands over Completed SAQ or Assessment Readiness Pack. Phase 6, Attestation and Maintenance. We support the attestation of compliance and help you keep controls running between assessments. Activities: Support QSA fieldwork and finding resolution; Finalise the attestation of compliance; Set the quarterly scan and review calendar; Monitor control drift between assessments. Hands over Attestation of Compliance. Each phase begins from the artefact the phase before it produced.
Phase 01 Scoping and Cardholder Data Flow
We map how card data moves through your environment and define the systems in scope. Reducing scope is the fastest way to cut effort.
What Happens In This Phase
- Trace cardholder data flows end to end
- Identify systems that store, process, or transmit card data
- Assess segmentation and tokenisation options
- Confirm your merchant or service provider level
The Handover
Scope Definition and Cardholder Data Flow Diagram
The next phase starts from this.
Phase 01 Scoping and Cardholder Data Flow
We map how card data moves through your environment and define the systems in scope. Reducing scope is the fastest way to cut effort.
What Happens In This Phase
- Trace cardholder data flows end to end
- Identify systems that store, process, or transmit card data
- Assess segmentation and tokenisation options
- Confirm your merchant or service provider level
The Handover
Scope Definition and Cardholder Data Flow Diagram
The next phase starts from this.
- 01
Scoping and Cardholder Data Flow
We map how card data moves through your environment and define the systems in scope. Reducing scope is the fastest way to cut effort.
OutputScope Definition and Cardholder Data Flow DiagramActivities
- Trace cardholder data flows end to end
- Identify systems that store, process, or transmit card data
- Assess segmentation and tokenisation options
- Confirm your merchant or service provider level
- 02
Gap Assessment
We measure your environment against the PCI DSS requirements and give you a prioritised remediation list.
OutputPCI DSS Gap Assessment ReportActivities
- Assess controls against the 12 PCI DSS requirements
- Review firewall rules, encryption, and logging
- Check authentication against version 4.0 changes
- Rank gaps by remediation effort and audit risk
- 03
Control Remediation
We help you implement the missing controls, from network segmentation to strong authentication and logging.
OutputRemediated Control EnvironmentActivities
- Implement network segmentation around card data
- Roll out multi-factor authentication
- Configure logging and file integrity monitoring
- Schedule quarterly ASV scans and penetration tests
- 04
Evidence Collection
We gather the evidence each requirement needs, so the assessment is a review, not a scramble.
OutputEvidence Package Indexed by RequirementActivities
- Map each requirement to its evidence artefacts
- Collect scan results, configs, and policy records
- Verify evidence covers the assessment period
- Index the package for the assessor
- 05
Assessment Preparation
We prepare you for the SAQ or the QSA-led Report on Compliance, depending on your level.
OutputCompleted SAQ or Assessment Readiness PackActivities
- Select the correct SAQ type or ROC path
- Run a dry-run walkthrough of assessor questions
- Brief control owners on interview expectations
- Fix last-mile issues before the assessment
- 06
Attestation and Maintenance
We support the attestation of compliance and help you keep controls running between assessments.
OutputAttestation of ComplianceActivities
- Support QSA fieldwork and finding resolution
- Finalise the attestation of compliance
- Set the quarterly scan and review calendar
- Monitor control drift between assessments
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
Built by SecureRoot
TrustGrid
Our own GRC platform. Control mapping, evidence collection, policy workflow and third-party risk, all in one place.
What Is Examined, and What it Is Measured Against
Map
Map of the PCI DSS scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: Qualys, Tenable Nessus, Rapid7 InsightVM, Splunk, AWS Config, Jira, Confluence, Vanta. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 4 published standards: PCI DSS v4.0.1, PCI SAQ, PA-DSS, NIST SP 800-53.
What We Run
8 tools
- AWS Config
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
4 standards
- PA-DSSPCI SSC
Deliverables
What You Receive
- Scope and data flow diagram
- Gap assessment report
- Remediation plan
- Evidence package
- SAQ or Report on Compliance support
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
Do I need a QSA or can I self-assess?
It depends on your merchant or service provider level and transaction volume. Smaller volumes often use a self-assessment questionnaire; larger ones need a QSA-led Report on Compliance.
How can we reduce our PCI DSS scope?
By segmenting card data away from the rest of your network and using tokenisation or a compliant payment provider. Less scope means fewer controls to prove.
What changed in PCI DSS 4.0?
It adds stronger authentication, more continuous controls, and a customised approach option. We help you meet the new requirements before they become mandatory.
Keep Moving Through Compliance
Service 6 of 13 in this practice area
Practice Area
More in Compliance
- ISO 27001Build and certify your information security management system.
- ISO 27701Extend your ISMS into a privacy information management system.
- ISO 22301Certify how your business keeps running through disruption.
- ISO 42001Govern your AI systems with the first AI management standard.
- DPDP ActGet ready for India's Digital Personal Data Protection Act.
- HIPAAProtect health information and meet HIPAA requirements.
- SOC 2Earn a SOC 2 report your customers can trust.
- CCPAMeet California's consumer privacy requirements.
- GDPRMeet Europe's data protection standard with confidence.
- NEN 7510Certify information security for Dutch healthcare.
- EU AI ActPrepare for Europe's risk-based AI regulation.
- Third Party Risk Assessment (TPRM)Understand and manage the risk your vendors bring.