PCI DSS

PCI DSS Compliance Consultancy

Protects cardholder data to the level acquirers and card schemes enforce.

  • Card Brand Fines Avoided
  • Acquirer Relationship Kept
  • Scope Deliberately Reduced
  • Basket Abandonment
Practice area
Cyber Security
Industries
4
Delivery
Onsite, remote, hybrid

Get a quotation

Tell us who is asking for the certification and by when.

What are you looking for?

We reply within one working day. Your details stay with our consultants.

Why expert advice is worth having

Organisations rarely fail PCI DSS because the standard is hard. They fail because the evidence does not match what the auditor asks for.

1

Your team already has a day job

Running PCI DSS in house means taking your most capable people off revenue work for months. For most organisations that hidden cost is larger than the fee for doing it properly.

2

Auditors ask for particular evidence

Someone who has sat through hundreds of PCI DSS audits knows which records get requested first and which answers collapse under a follow up question. That knowledge is only earned in the room.

3

The standard says what, never how

PCI DSS is written to apply to every organisation on earth, which is exactly why it never tells you what to do in yours. Turning a clause into your process, on your sites, with your people, is the actual work.

4

Surveillance never stops

A PCI DSS certificate is the start of a three year cycle, not the end of a project. Building for the surveillance audits from day one costs far less than rebuilding before each one.

Prefer to just ask someone about PCI DSS rather than fill in a form?

What PCI DSS is worth to you

Certification is a commercial decision before it is a technical one. This is where the return usually shows up.

Card Brand Fines Avoided

Non compliance discovered after a cardholder data breach brings acquirer penalties that dwarf whatever the compliance work would have cost.

Acquirer Relationship Kept

Banks can raise transaction charges or withdraw merchant facilities altogether from businesses that cannot evidence their compliance status.

Scope Deliberately Reduced

Segmenting and tokenising cardholder data shrinks what you are obliged to protect, which lowers your cost every year that follows.

Basket Abandonment

Visible payment security reduces the hesitation that makes first time online buyers walk away from a basket they have already filled.

Industries where PCI DSS applies

Open a sector to see every standard it is usually asked for.

Want PCI DSS costed properly rather than guessed at?

Send us the details

See the documentation

Look at how it is structured before you commit

Most people picture a filing cabinet when they hear documentation. What we build for PCI DSS is a working structure: a short manual, procedures written in the words your team already uses, and record formats that get filled in because they fit the job. In a demo we open a real set and walk you through how each clause is answered.

PCI DSS in detail

The rules that come with accepting card payments

PCI DSS is the security standard maintained by the payment card brands for anyone who stores, processes or transmits cardholder data. It covers network segmentation and firewalls, encryption, vulnerability management, access control, monitoring and logging, security testing, and an information security policy people actually follow. Version 4 sharpened requirements around authentication, scripts running on payment pages and targeted risk analysis. Compliance is contractual rather than statutory, enforced by your acquiring bank and the card brands behind it.

It applies to merchants, gateways, processors, and increasingly to service providers who never see a card number but can affect the payment page. How you validate depends on volume and channel: larger merchants and service providers face an annual assessment by a qualified security assessor, smaller ones complete a self assessment questionnaire chosen to match their setup. Picking the wrong questionnaire is common and quietly invalidates the whole exercise. Quarterly external scanning by an approved vendor applies to most.

Shrinking the scope before hardening what is left

The first job is scope, and it repays doing properly because everything after it costs money. We map every flow where card data enters, moves and rests, including call recordings, email attachments, backups and third party integrations nobody documented. Then we look at what can be removed altogether through tokenisation, redirect or hosted fields, and how segmentation can cut the remaining environment down. A smaller scope is cheaper to secure and cheaper to assess, and it stays cheaper every year.

What remains gets hardened against the requirements: configuration standards, key management, patching and vulnerability handling, multi factor authentication into the cardholder data environment, file integrity monitoring, log retention with daily review, and change control that records what changed and who approved it. We run internal readiness testing, coordinate approved scanning and penetration testing, and organise evidence by requirement so the assessor reviews a file instead of interviewing your engineers on the spot.

Attestation, and keeping it true for twelve months

You end up with a defined and documented cardholder data environment, network and data flow diagrams that match reality, the policy and procedure set, evidence organised requirement by requirement, scan and test reports, and either a completed self assessment questionnaire with its attestation of compliance or a report on compliance produced by an independent qualified security assessor. MSCi prepares and advises throughout. The formal assessment is signed by the assessor, never by the consultant.

The change worth having is that compliance stops being an annual panic. Because the daily, weekly and quarterly activities are assigned, logged and reviewed through the year, the assessment window becomes a collection exercise rather than a rebuild. Acquirer questions get short answers. And the segmentation work usually pays for itself outside payments too, since the same discipline limits what an intruder can reach anywhere in the network. Fewer systems in scope means fewer systems to argue about.

The route to your PCI DSS certificate

  1. 1Gap analysis
  2. 2Documentation
  3. 3Training
  4. 4Implementation
  5. 5Internal audits
  6. 6Closure of gaps
  7. 7Management review
  8. 8Certification audit
  9. 9Surveillance audits

Want an honest view of where you stand on PCI DSS?

PCI DSS questions we are asked most

What does PCI DSS actually require from us?

You will need a defined scope, documentation that reflects actual practice rather than intent, evidence the system has been operating for a reasonable period, trained staff, and at least one internal audit and management review on file.

What is a realistic timeline for PCI DSS?

Most PCI DSS projects run three months or so. The single biggest variable is not the standard, it is how fast your team can be freed up for training and internal audit alongside their normal work.

Do you issue the PCI DSS certificate yourselves?

No, and no consultant should. The certificate comes from an independent accredited certification body after their own audit. We prepare you to pass it and we are there on the day to close findings. That separation is exactly what makes the certificate worth holding.

What does PCI DSS consultancy cost?

It depends on your headcount, how many sites are in scope and how much of a system already exists, so we quote after a short conversation rather than publishing a figure that would be wrong for most readers. Scope, timeline and fees come to you in writing first.

Which industries need PCI DSS?

We map PCI DSS to 4 sectors and it sits in our cyber security practice. Organisations usually arrive because a specific buyer, regulator or tender committee has asked. Tell us who is asking and we will confirm whether this is the standard that satisfies them.

Do you have to visit our premises?

Remote delivery covers most of a PCI DSS project comfortably. We recommend onsite presence for the initial assessment and for the certification audit, where being in the room genuinely changes the outcome.

Quick question about PCI DSS? Message us and get an answer today.

Insights, news and know-how

Guidance from our consultants, with anything about this standard first in each column.

All articles →

Blogs22

Working notes from the consultants.

News

What has changed, and when it bites.

Nothing here yet. Anything published as news appears in this column.

Articles

Longer pieces on one subject.

Nothing here yet. Anything published as articles appears in this column.

Knowledge base

How things are actually done.

Nothing here yet. Anything published as knowledge base appears in this column.

Ready to start on PCI DSS?

Book a short session and we will tell you what is involved, how long it takes and what it costs.