Compliance & certification

PCI DSS

PCI DSS v4.0 program from SAQ scoping through ROC, including ASV scans and segmentation testing.

v4.0
Current standard version
SAQ/ROC
Both pathways supported

Certification & audits

In plain terms DSS

What this is

PCI DSS v4.0 program from SAQ scoping through ROC, including ASV scans and segmentation testing.

Why it can hurt you

Cardholder-data scope creeps into systems nobody meant to include, and that’s where the ROC ends up failing.

Certification & audits

Why it matters to you DSS

The problem

Cardholder-data scope creeps into systems nobody meant to include, and that’s where the ROC ends up failing.

Acquirer relationship protected

Stay compliant with the standard your payment processor requires.

Breach-cost reduction

Segmentation and logging controls that also limit real breach impact.

Certification & audits

How we do it DSS

CDE scoping

Define the true cardholder-data environment boundary before anything else.

Gap assessment

All 12 requirements assessed against current controls.

ASV & segmentation testing

Quarterly external scans and segmentation validation coordinated in-house.

Certification & audits

What we typically find DSS

Scope creep

Cardholder data flowing into systems outside the defined CDE.

Weak segmentation

CDE not effectively isolated from the rest of the network.

Incomplete logging

Requirement 10 audit trails missing required event coverage.

No surprises on audit day.

We check what the auditor will check, first — so the audit is a formality.

Certification & audits

What lands on your desk DSS

SAQ or ROC package

Completed self-assessment or Report on Compliance per your merchant level.

ASV scan reports

Quarterly passing scans from an Approved Scanning Vendor process.

Remediation tracker

Every gap tied to an owner and a deadline.

Certification & audits

What you get out of it DSS

Acquirer relationship protected

Stay compliant with the standard your payment processor requires.

Breach-cost reduction

Segmentation and logging controls that also limit real breach impact.

Certification & audits

Step by step DSS

1. CDE scoping

Define the true cardholder-data environment boundary before anything else.

2. Gap assessment

All 12 requirements assessed against current controls.

3. ASV & segmentation testing

Quarterly external scans and segmentation validation coordinated in-house.

Find out what we would find.

A scoping call is thirty minutes, costs nothing, and ends with a fixed price and a date. If we are not the right people for the job, we will tell you that too.