Home/Frameworks/PCI DSS
Payments
Payments

PCI DSS

The mandatory security standard for handling card data. PCI DSS applies to every organisation that stores, processes, or transmits payment card information — and non-compliance carries real financial and operational consequences.

The standard

What PCI DSS is.

The Payment Card Industry Data Security Standard, now at version 4.0, sets twelve core requirements covering network security, data protection, vulnerability management, access control, monitoring, and security policy.

How you validate depends on how much card data you handle: smaller merchants complete a Self-Assessment Questionnaire, while larger volumes require a Qualified Security Assessor and a formal Report on Compliance.

It is maintained by the PCI Security Standards Council, and non-compliance can mean heavy fines, raised transaction fees, or loss of card-processing privileges altogether.

Who it's for

Is this you?

E-commerce & merchants

Anyone accepting card payments online or in person.

Payment platforms & fintech

Businesses that process or route cardholder data as part of their service.

SaaS touching card data

Vendors whose systems transmit or store payment information.

How we deliver

From kickoff to done,
in five stages.

Delivered through our specialist network. We determine your merchant level and the right validation path, close the gaps against all twelve requirements, and prepare the SAQ or coordinate the QSA assessment — so you validate cleanly rather than scrambling at renewal.

01

Scope & kickoff

We define the boundary of your programme — systems, locations, and teams in scope — and agree the timeline and responsibilities up front, so there are no surprises later.

02

Gap diagnostic

A structured assessment of your current posture against every requirement, producing a prioritised remediation plan with realistic effort estimates.

03

Build

We write the policies, procedures, and controls, and work alongside your engineering team on a weekly cadence to implement them — not a stack of templates left for you to figure out.

04

Operate

The management system runs and generates evidence. We drive the internal audit and management review so the programme is demonstrably working before any external scrutiny.

05

Audit support

We prepare the evidence package and sit alongside you through assessment, answering the assessor's questions directly rather than leaving you to defend the work alone.

Questions

Frequently asked.

It depends on your transaction volume. Lower volumes validate through a Self-Assessment Questionnaire; higher volumes require an on-site assessment by a Qualified Security Assessor. We confirm your level and the correct path before any work starts.

Often, yes — by tokenising card data or routing it through a compliant payment processor, you can take large parts of your environment out of scope entirely. Scope reduction is usually the highest-value first move, and we plan for it early.

Explore more

Other frameworks.

Ready when you are

Let's get you
PCI DSS ready.

Book a free advisory session and we'll map your fastest credible route to compliance.

Book a free advisory session