MDR Services

Our Managed Detection and Response Services provide continuous monitoring from a team who’ll neutralise any breaches at speed...

Incident Response

Gain access to malware experts to quickly contain threats and reduce future exposure to attacks...

Gartner Recognised

Integrity360 has been recognised as a Gartner Representative Vendor.

Download our CyberFire MDR ebook

Many organisations are choosing CyberFire MDR to strengthen their defences. Discover how it can protect your business in our brochure.

The hidden human costs of a cyber attack

Cyber attacks often seem faceless, but hidden behind the headlines of financial loss and technical details there are very real human stories. 

The reality of ransomware in 2025: What you need to know

In 2025, we’re witnessing a shift in how ransomware operates, who it targets, and the consequences of falling victim.

Your guide to 2026: Trends and Predictions

Stay ahead of the latest cybersecurity industry developments, advancements and threats, and understand how you can best protect your organisation.

Cybersecurity testing services

Do you know what your company’s network vulnerabilities are? Businesses that invest in penetration testing do.

What is PCI? Your most common questions answered

If your business handles credit card data, PCI DSS compliance isn’t optional—it’s critical. From retailers and e-commerce platforms to service providers and financial institutions, securing credit card data is critical to customer trust and preventing fraud.

Weekly Threat roundups

Stay informed with the latest cybersecurity news with our weekly threat roundups.

The A-Z Glossary of cybersecurity terms

Confused about cybersecurity? Our A-Z Glossary of terms can help you navigate this complicated industry.

Read our latest blog

For many small and mid-sized businesses, cybersecurity can feel overwhelming.

Integrity360 completes SOC 2 certification to strengthen global cyber defence ecosystem

SOC 2 certification reflects Integrity360’s continued investment in strengthening cyber resilience for clients across highly regulated and high-risk industries. 

Integrity360 expands into North America with Advantus360 Acquisition

Leading Canadian cybersecurity services provider Advantus360 joins Integrity360 creating the group’s first hub in North America

Security First 2026

See the full list of our conferences across the UK, Europe, Africa & the Caribbean
Integrity360 Emergency Incident Response button Under Attack?

PCI CPP

The security of every payment card starts in production. PCI CPP compliance is how your organization demonstrates that your environment is built to the right standard.

0  

SOCs in Ireland, Sweden, Bulgaria, Spain, Italy, South Africa & Canada (coming 2026)

0 +

security consultants, engineers and analysts

0 +

satisfied clients

What is PCI Card Production and Provisioning?

PCI Card Production and Provisioning (CPP) sets the security requirements for organizations that manufacture, personalize, provision and fulfil payment cards and payment credentials. It covers the physical security of the facilities where that work happens and the logical security of the systems, data and cryptographic keys involved.

Compliance is assessed by Card Production Security Assessors qualified by the PCI Security Standards Council. As with the other PCI standards, whether your organization is required to validate is determined by the payment brands.

Who needs to comply with PCI CPP?

The requirements apply to organizations performing card production and provisioning activities, including:

  • Card manufacturers and personalizers

  • Chip embedders and pre-personalizers

  • Data preparation and fulfilment operations

  • PIN generation and printing

  • Cloud-based and secure element provisioning service providers

  • Organizations managing over-the-air personalization and the cryptographic key lifecycle

Physical and logical: two sets of requirements

  • Physical Security Requirements cover the facilities themselves: access control, secure areas, materials handling, storage, movement of card stock and the operational controls around production activity.

  • Logical Security Requirements cover the systems and processes: cryptographic key management, EMV data preparation, pre-personalization, magnetic stripe and IC personalization, PIN generation and printing, and fulfilment data.

The two are assessed separately by assessors qualified separately in each. Most organizations are in scope for both, and getting the boundary right between them is where the scoping work earns its keep.

 

PCI CPP compliance services

Scope Assessment Review (SAR)

Identifying which systems, facilities and business processes fall within scope for the physical and logical requirements is where the work starts. SAR establishes and validates that boundary, so remediation and assessment effort go where the requirements apply.

Gap Analysis Review (GAR)

Comparing your current environment against the physical and logical requirements surfaces what needs to change. You get a clear picture of where the gaps sit, what closing them involves, and which solutions will get you there.

Formal Assessment of Compliance (FAC)

Where your organization is required to demonstrate compliance, the FAC assesses and reports on the security of your environment against the applicable requirements. Knowledge is transferred to your team throughout, so maintaining compliance between assessments sits with people who understand why each control is there.

Trusted Advisor Service (TAS)

Running alongside the above, TAS gives you a dedicated point of contact through planning, implementation and maintenance, with direct access to solution experts for questions on evolving controls and developments in the standard.

Speak to an expert

Card production environments differ enormously in what falls inside the boundary, and that boundary determines the cost of everything that follows. Talk to an advisor about scoping yours.

PCI 3DS

PCI SSF/PA DS

PCI SSF/PA DS

PCI DSS

PCI P2PE

PCI PIN

PCI ASV

Swift CSP Assessment

Swift CSP Assessment

PCI TSP

Our Certifications

  distintivo_ens_certificacion_ALTA_RD311-2022  

 

Access key insights

What is PCI DSS and Why Does It Matter?

What is new in PCI DSS 4.0?

How Managed Detection and Response can facilitate PCI DSS Compliance

Why Switching to Integrity360 Should Be Your Top Choice for PCI DSS Compliance This Data Privacy Week