The mandatory security standard for handling card data. PCI DSS applies to every organisation that stores, processes, or transmits payment card information — and non-compliance carries real financial and operational consequences.
The Payment Card Industry Data Security Standard, now at version 4.0, sets twelve core requirements covering network security, data protection, vulnerability management, access control, monitoring, and security policy.
How you validate depends on how much card data you handle: smaller merchants complete a Self-Assessment Questionnaire, while larger volumes require a Qualified Security Assessor and a formal Report on Compliance.
It is maintained by the PCI Security Standards Council, and non-compliance can mean heavy fines, raised transaction fees, or loss of card-processing privileges altogether.
Anyone accepting card payments online or in person.
Businesses that process or route cardholder data as part of their service.
Vendors whose systems transmit or store payment information.
Delivered through our specialist network. We determine your merchant level and the right validation path, close the gaps against all twelve requirements, and prepare the SAQ or coordinate the QSA assessment — so you validate cleanly rather than scrambling at renewal.
We define the boundary of your programme — systems, locations, and teams in scope — and agree the timeline and responsibilities up front, so there are no surprises later.
A structured assessment of your current posture against every requirement, producing a prioritised remediation plan with realistic effort estimates.
We write the policies, procedures, and controls, and work alongside your engineering team on a weekly cadence to implement them — not a stack of templates left for you to figure out.
The management system runs and generates evidence. We drive the internal audit and management review so the programme is demonstrably working before any external scrutiny.
We prepare the evidence package and sit alongside you through assessment, answering the assessor's questions directly rather than leaving you to defend the work alone.
It depends on your transaction volume. Lower volumes validate through a Self-Assessment Questionnaire; higher volumes require an on-site assessment by a Qualified Security Assessor. We confirm your level and the correct path before any work starts.
Often, yes — by tokenising card data or routing it through a compliant payment processor, you can take large parts of your environment out of scope entirely. Scope reduction is usually the highest-value first move, and we plan for it early.
Book a free advisory session and we'll map your fastest credible route to compliance.
Book a free advisory session