PCI DSS v4 raised the bar: future-dated requirements are now mandatory, and the customised approach demands real security judgement rather than checkbox compliance. We scope, build and evidence PCI DSS programmes that satisfy your acquirer, your QSA and your customers, without gold-plating what the standard does not ask of you.
Scoping is the decision that determines the cost of everything that follows in PCI DSS. We start there, and we are honest about it, because a well-segmented environment can shrink your compliance burden dramatically.
Cardholder data environment mapped, segmentation validated, SAQ type or RoC path determined, and your current position benchmarked against all twelve requirements of v4, with the gaps costed and prioritised.
Controls built and embedded: policies, technical measures, targeted risk analyses for the customised approach, and the evidence trail your assessor will ask for, inside your existing ways of working.
Support through your SAQ or QSA assessment, then the quarterly scans, periodic reviews and evidence upkeep that keep compliance continuous rather than an annual scramble.
PCI DSS punishes ambiguity: every requirement must be evidenced in a form an assessor will accept. Our consultants audit management systems professionally, so evidence discipline is not an afterthought bolted on before the assessment; it is how the programme is built from day one. Where you also carry ISO 27001, we align the two so one control set and one evidence library serve both.
Segmentation and tokenisation guidance that shrinks the assessed environment without shrinking security.
Future-dated requirements, targeted risk analyses and the customised approach handled as core, not add-ons.
The right assessment path for your transaction volumes and channels, agreed with your acquirer.
Senior Lead Implementer and Senior Lead Auditor credentials on every engagement. No juniors, no hand-offs.
Every place cardholder data is captured, transmitted, processed or stored, mapped, and the assessed environment defined and, where possible, reduced.
Current controls benchmarked against PCI DSS v4's twelve requirements, with an honest reading of the distance to compliance and the cost of closing it.
Controls, policies and technical measures deployed with your team, evidence captured as you go rather than reconstructed at assessment time.
SAQ completion or QSA assessment support, with no surprises because the mock walkthrough already happened.
Quarterly scans, periodic control validation and evidence upkeep on a calendar, so next year's attestation is routine.
It depends on your transaction volumes, channels and what your acquirer demands. Many merchants can self-assess with the right SAQ; service providers and larger merchants need a QSA-led Report on Compliance. We determine the path at scoping and prepare you for whichever applies.
Materially: the future-dated requirements are now mandatory, multi-factor authentication and password expectations tightened, targeted risk analyses arrived, and the customised approach lets mature organisations meet objectives their own way, with more evidence, not less. If your programme was built for v3.2.1, it has gaps.
Substantially. The control families overlap heavily, and running one integrated control set with one evidence library serves both, which is exactly how we build when a client carries both obligations.
Scope. Segmentation, tokenisation, and outsourcing payment capture to compliant providers can move most of your environment out of assessment. The cheapest control is the cardholder data you never touch.
A 30-minute scoping call with a senior consultant, and an honest reading of your PCI DSS position.