PCI DSS V4 · Payment Card Security

Cardholder data, defended and demonstrated.

PCI DSS v4 raised the bar: future-dated requirements are now mandatory, and the customised approach demands real security judgement rather than checkbox compliance. We scope, build and evidence PCI DSS programmes that satisfy your acquirer, your QSA and your customers, without gold-plating what the standard does not ask of you.

We hold ourselves to the standards we audit: Cybercontrols is certified to
ISO/IEC 27001:2022Certified · SANCERT ISO/IEC 42001:2023Certified · SANCERT Cyber EssentialsCertified Government Commercial AgencyApproved Supplier · G-Cloud 15
What we deliver

Scope it right, and everything else gets cheaper.

Scoping is the decision that determines the cost of everything that follows in PCI DSS. We start there, and we are honest about it, because a well-segmented environment can shrink your compliance burden dramatically.

01

Scoping & Gap Assessment

Cardholder data environment mapped, segmentation validated, SAQ type or RoC path determined, and your current position benchmarked against all twelve requirements of v4, with the gaps costed and prioritised.

02

Remediation & Implementation

Controls built and embedded: policies, technical measures, targeted risk analyses for the customised approach, and the evidence trail your assessor will ask for, inside your existing ways of working.

03

Assessment Support & Maintenance

Support through your SAQ or QSA assessment, then the quarterly scans, periodic reviews and evidence upkeep that keep compliance continuous rather than an annual scramble.

Why Cybercontrols

Built by people who know what assessors accept.

PCI DSS punishes ambiguity: every requirement must be evidenced in a form an assessor will accept. Our consultants audit management systems professionally, so evidence discipline is not an afterthought bolted on before the assessment; it is how the programme is built from day one. Where you also carry ISO 27001, we align the two so one control set and one evidence library serve both.

Scope minimised, honestly

Segmentation and tokenisation guidance that shrinks the assessed environment without shrinking security.

v4-native

Future-dated requirements, targeted risk analyses and the customised approach handled as core, not add-ons.

SAQ or RoC, settled

The right assessment path for your transaction volumes and channels, agreed with your acquirer.

Senior-led, always

Senior Lead Implementer and Senior Lead Auditor credentials on every engagement. No juniors, no hand-offs.

How it works

From data flows to attestation, without surprises.

Step 1

Data flows & scoping

Every place cardholder data is captured, transmitted, processed or stored, mapped, and the assessed environment defined and, where possible, reduced.

Step 2

Gap analysis

Current controls benchmarked against PCI DSS v4's twelve requirements, with an honest reading of the distance to compliance and the cost of closing it.

Step 3

Remediate & embed

Controls, policies and technical measures deployed with your team, evidence captured as you go rather than reconstructed at assessment time.

Step 4

Assess

SAQ completion or QSA assessment support, with no surprises because the mock walkthrough already happened.

Step 5

Maintain

Quarterly scans, periodic control validation and evidence upkeep on a calendar, so next year's attestation is routine.

Questions we hear most

PCI DSS, answered plainly.

Do we need a QSA, or can we self-assess?

It depends on your transaction volumes, channels and what your acquirer demands. Many merchants can self-assess with the right SAQ; service providers and larger merchants need a QSA-led Report on Compliance. We determine the path at scoping and prepare you for whichever applies.

What changed in v4?

Materially: the future-dated requirements are now mandatory, multi-factor authentication and password expectations tightened, targeted risk analyses arrived, and the customised approach lets mature organisations meet objectives their own way, with more evidence, not less. If your programme was built for v3.2.1, it has gaps.

Can PCI DSS align with our ISO 27001 ISMS?

Substantially. The control families overlap heavily, and running one integrated control set with one evidence library serves both, which is exactly how we build when a client carries both obligations.

How do we reduce the cost of compliance?

Scope. Segmentation, tokenisation, and outsourcing payment capture to compliant providers can move most of your environment out of assessment. The cheapest control is the cardholder data you never touch.

Ready to know exactly where you stand?

A 30-minute scoping call with a senior consultant, and an honest reading of your PCI DSS position.