Payment security
without the complexity.
We guide businesses through PCI DSS certification — from audit to the final compliance report. Protect your customers' data and build trust in your brand.
Gap Analysis
Full assessment of current infrastructure
Roadmap
Prioritised remediation plan
QSA Audit
Formal audit & Report on Compliance (ROC)
Certified
PCI DSS Level 1 achieved
The payment data security standard
PCI DSS (Payment Card Industry Data Security Standard) is an international security standard developed by Visa, Mastercard, American Express, Discover and JCB.
The standard sets mandatory requirements for any company that accepts, processes, stores or transmits payment card data — regardless of size or transaction volume.
Why do you need certification?
Without PCI DSS, you risk fines from payment networks, losing acquiring rights, customer data breaches and reputational damage. Certified businesses demonstrate responsible data handling and gain competitive advantage.
Who must comply with PCI DSS?
The compliance level is determined by annual transaction volume. More transactions — stricter verification requirements.
Over 6M transactions/year
Annual QSA on-site audit and quarterly ASV network scanning. Formal ROC required.
Our specialisation1–6M transactions/year
Annual SAQ self-assessment and quarterly ASV network scanning.
We cover this too20K–1M transactions/year
Annual SAQ and quarterly scanning where required.
Advisory availableUnder 20K transactions/year
Annual SAQ and scanning per acquirer requirements.
Self-service guidanceWhat does PCI DSS cover?
The standard consists of 12 core requirements grouped into 6 security objectives.
Network protection
Firewall, routing and network segmentation controls.
Card data protection
Encryption of cardholder data at rest and in transit.
Vulnerability management
Software patching and antivirus protection of systems.
Access control
Least-privilege access; unique IDs for every user.
Monitoring & testing
Logging all network access; regular security testing.
Information security policy
Corporate IS policy, staff training, risk management.
Default passwords
Mandatory change of all default credentials on hardware and software.
Physical security
Physical access control to card data storage systems.
Encryption in transit
TLS protection for cardholder data over open networks.
Penetration testing
Regular pentest of external and internal CDE perimeter.
ASV scanning
Quarterly external IP scanning by an authorised ASV.
Third-party management
Accountability for PCI DSS compliance of service providers.
How we guide you to certification
Step-by-step support from first audit to Attestation of Compliance (AoC).
Gap Analysis
Assessment of current IT infrastructure and identification of PCI DSS non-conformities. Detailed report with recommendations.
Roadmap Development
Remediation road map with priorities, timelines and responsible parties.
Implementation of security controls
Technical and organisational preparation: system configuration, IS policy development, staff training.
Audit & Testing
ASV scanning, penetration testing, internal audit. For Level 1 — QSA engagement for formal ROC audit.
Certification
Preparation and signing of Attestation of Compliance (AoC), submission to acquirer and payment networks.
Full PCI DSS consulting spectrum
We support businesses at every stage — from initial assessment to post-certification maintenance.
Gap analysis & risk assessment
Detailed analysis of infrastructure against PCI DSS. CDE scope definition and opportunities to reduce scope.
SAQ preparation
Assistance selecting the correct SAQ type, completing and reviewing the questionnaire for Levels 2–4.
QSA audit support
Coordination during official QSA audit for Level 1. Preparation of Report on Compliance (ROC).
ASV scanning
Mandatory quarterly external IP scanning by an authorised provider. Remediation of identified vulnerabilities.
Penetration testing
Internal and external pentest of CDE to PCI DSS v4.0 requirements. Detailed vulnerability report.
Staff training
Training for IT teams on PCI DSS requirements, social engineering and safe payment data handling.
PCI DSS in cloud
Compliance consulting for AWS, Azure, GCP. Responsibility matrices, cloud security configuration, scoping.
Post-certification support
Year-round compliance monitoring, support for quarterly scans, preparation for the next certification cycle.
IS policy development
Full documentation: security policy, incident response procedures, BCP/DRP plans — to PCI DSS requirements.
Our advantages
Experience, expertise and results — the three pillars of our work.
Certified QSA
Our auditors hold Qualified Security Assessor certification from PCI SSC.
Fast start
Gap analysis and first report within 5 business days of contract signing.
International experience
Projects in Ukraine, EU, USA and the Middle East across various sectors.
Fixed price
Clear scope and fixed budget — no hidden extras at any stage.
NDA & confidentiality
Non-disclosure agreement signed before any analysis begins.
24/7 support
Dedicated project manager and technical support throughout the engagement.
Frequently asked questions
Answers to the most common questions about PCI DSS and the certification process.
How long does PCI DSS certification take?
Level 4 (SAQ) — 4 to 8 weeks; Level 1 (ROC audit) — 3 to 6 months. A gap analysis establishes precise timelines at the start of the project.
Do we need certification if we use a third-party payment gateway?
Even with a payment gateway, you remain in scope if your site or systems interact with payment data in any way. The requirements depend on the integration method.
What is an SAQ and how does it differ from an ROC?
An SAQ (Self-Assessment Questionnaire) is a self-assessment form for Levels 2–4. An ROC (Report on Compliance) is prepared by an independent QSA auditor; mandatory for Level 1.
What happens if we fail certification?
Non-compliance can lead to fines of $5,000–$100,000 per month, higher interchange rates, and in the event of a breach — fines up to $500,000 per incident and disconnection from payment networks.
PCI DSS v3.2.1 or v4.0 — which version is current?
Since 31 March 2024, PCI DSS v3.2.1 has been retired. All certifications are conducted under PCI DSS v4.0, which significantly expands authentication and monitoring requirements.
How much does PCI DSS consulting cost?
Cost depends on certification level, infrastructure complexity and scope of work. We offer a fixed price after a free initial consultation. Contact us for a personalised proposal.
Ready to start your path to certification?
Get a free initial consultation and scope assessment from our certified specialists.