Assessment against PCI DSS v4.0 led by a Qualified Security Assessor — from cardholder-data scoping through to the Report on Compliance and Attestation of Compliance.
Organisations that store, process or transmit cardholder data must validate compliance with PCI DSS. For many, that means a formal assessment by a Qualified Security Assessor.
We define your cardholder data environment, test each requirement, help close gaps, and produce the Report on Compliance and Attestation of Compliance your acquirer or card brand requires.
Defining and minimising the cardholder data environment.
All twelve PCI DSS requirement areas.
Validated and documented where applicable.
Across people, process and technology.
Formal reporting for your acquirer or card brand.
Who this engagement is designed to support.
Organisations above defined transaction volumes, or required by their acquirer, must validate PCI DSS compliance through a Qualified Security Assessor; the assessment produces the formal evidence acquirers and card brands rely on.
A rigorous lifecycle that gives you a result you can stand behind.
Defining the cardholder data environment and connected systems.
Assessing current state against the PCI DSS requirements.
Validating controls across the twelve PCI DSS requirements.
Sampling systems and testing evidence of compliance.
Tracking remediation of gaps through to closure.
Issuing the Report on Compliance and Attestation of Compliance.
Everything here is aligned to your applicable standards and obligations.
What to have in place before we begin.
Explore this offering in detail.
Learn more →Explore this offering in detail.
Learn more →Explore this offering in detail.
Learn more →Back to the full pillar.
View pillar →Give us the picture, and we’ll put together a scope that fits.