PCI DSS
Achieve and maintain PCI DSS compliance with expert support from scoping through to formal assessment.
0
0 +
0 +
PCI DSS and Integrity360
Integrity360 helps merchants, service providers, financial institutions and other organisations understand their PCI DSS obligations, reduce unnecessary scope, identify compliance gaps and complete the appropriate assessment process.
Our Qualified Security Assessors provide practical guidance across PCI DSS v4.0.1, helping organisations build sustainable payment security programmes rather than treating compliance as a once-a-year exercise.
We offer compliance in three steps:
-
PCI DSS Scope Analysis Review
-
PCI DSS Gap Analysis Review
-
PCI DSS Formal Assessment of Compliance
Speak to an expert
Find out how more about our reviews and assessments such as:
-
PCI DSS Scope Analysis Review
-
PCI DSS Gap Analysis Review
-
PCI DSS Formal Assessment of Compliance
London: +44 20 3397 3414
Sofia: +359 2 491 0110
Cape Town: +27 08 606 25673
Johannesburg: +27 08 606 25673
Compliance in 3 steps
PCI DSS Scope Analysis Review
For many organisations it is a challenge to identify which PCI DSS controls are applicable and which systems need to be protected. Before business make changes to protect Cardholder Data (CHD) in a PCI DSS compliant manner, it’s important to understand the scope of the compliance efforts.
PCI DSS Gap Analysis Review
To achieve PCI DSS compliance, an organisation must meet all applicable PCI DSS requirements. Our PCI DSS Gap Analysis Review defines a realistic and cost-efficient remediation program by helping uncover any security and compliance deficiencies or shortcomings. Our consultants will identify suitable remediation options through products, solutions and outsourcing providers.
Once gaps are uncovered and potential solutions identified, it becomes easier to quantify and estimate the work effort that will be required. Prioritise your effort so the greatest gap can be addressed first.
PCI DSS Formal Assessment of Compliance
Merchants, Service Providers, Issuers or Acquirers that store, process or transmit payment card information must demonstrate on an annual basis that they comply with the requirements and testing procedures of the Payment Card Industry Data Security Standard (PCI DSS).
PCI 3DS
PCI SSF/PA DS
PCI P2PE
PCI PIN
PCI ASV
PCI TSP
PCI CPP
Swift CSP Assessment
PCI DSS FAQs
What is PCI DSS?
PCI DSS, or the Payment Card Industry Data Security Standard, is a global security standard designed to protect payment account data. It applies to organisations that store, process or transmit cardholder data, as well as entities that can affect the security of the cardholder data environment.
Who needs to comply with PCI DSS?
Organisations that store, process or transmit payment card data may be required to comply with PCI DSS. This can include merchants, service providers, financial institutions and technology providers. The exact validation requirements depend on factors such as the organisation's role, transaction volumes and the requirements of the relevant acquiring bank or payment brand.
What is PCI DSS v4.0.1?
PCI DSS v4.0.1 is the current version of the PCI Data Security Standard. It includes requirements covering areas such as authentication, access control, vulnerability management, monitoring, security testing, e-commerce security and targeted risk analysis.
How do I know which PCI DSS requirements apply to my organisation?
The requirements that apply depend on your payment environment, how cardholder data is handled and the systems, people and processes that can affect its security. A PCI DSS scoping exercise can help identify the cardholder data environment and determine which systems and controls fall within scope.
What is a Qualified Security Assessor (QSA)?
A Qualified Security Assessor, or QSA, is a security professional qualified through the PCI Security Standards Council to assess organisations against PCI DSS requirements. QSAs can support scoping, gap analysis, remediation planning and formal PCI DSS assessments.
What is a PCI DSS Scope Analysis?
A PCI DSS Scope Analysis identifies where payment account data is stored, processed or transmitted and determines which systems, networks, people and processes fall within the cardholder data environment. Accurate scoping can help reduce unnecessary compliance complexity and ensure relevant controls are properly assessed.
What is a PCI DSS Gap Assessment?
A PCI DSS Gap Assessment compares an organisation's current security controls against applicable PCI DSS requirements. It identifies areas of non-compliance and provides recommendations to help prioritise remediation before a formal assessment or self-assessment is completed.
What is a PCI DSS formal assessment?
A formal PCI DSS assessment evaluates whether an organisation meets the applicable requirements of the standard. Depending on the organisation and its validation requirements, this may involve a Qualified Security Assessor completing a Report on Compliance or an eligible organisation completing a Self-Assessment Questionnaire.
What is a Report on Compliance (ROC)?
A Report on Compliance, or ROC, is a detailed assessment report used to document an organisation's compliance with PCI DSS. It is typically completed by a Qualified Security Assessor where an assessor-led validation is required.
What is an Attestation of Compliance (AOC)?
An Attestation of Compliance, or AOC, is an official PCI SSC form used to confirm the result of a PCI DSS assessment. The appropriate AOC depends on the type of assessment completed, such as a Report on Compliance or Self-Assessment Questionnaire.
How often does PCI DSS compliance need to be assessed?
PCI DSS compliance is generally validated on a recurring basis, but the exact frequency and assessment method depend on the organisation and requirements set by the relevant acquiring bank, payment brand or other compliance-accepting entity. Some security activities, such as vulnerability scanning, may also need to be performed more frequently.
What happens if an organisation fails a PCI DSS assessment?
If gaps are identified during an assessment, the organisation will normally need to remediate the relevant issues before compliance can be validated. The actions required will depend on the findings, the assessment type and any requirements set by the organisation's acquiring bank or payment brand.
