PCI DSS
The card brand requirement for anyone who stores, processes, or transmits cardholder data.
What it is
PCI DSS v4.0 sets twelve requirement groups covering network security, cardholder data protection, vulnerability management, access control, monitoring, and policy. Validation depends on merchant or service provider level: a self-assessment questionnaire for lower volumes, a Report on Compliance from a Qualified Security Assessor for higher ones. Scope is defined by the cardholder data environment, and reducing that scope is usually the highest-value work in the program.
Who typically needs it
- Fintech and payments companies validating as service providers
- Merchants whose acquirer has escalated them to a higher validation level
- Platforms whose customers inherit compliance obligations from them
- Companies whose card data footprint grew faster than their segmentation
- Organizations facing the v4.0 future-dated requirements
What the engagement looks like
Common failure modes
- Scope defined by system inventory rather than by data flow, which understates the environment
- Segmentation asserted but never tested, which fails at the assessor stage
- Quarterly scans run but failing scans not remediated and rescanned within the window
- Treating v4.0 future-dated requirements as optional past their effective date
Price range
Programs typically run between $40,000 and $90,000 for the Build phase, varying considerably by merchant or service provider level.
Talk to us about your PCI DSS.
Thirty minutes on the calendar, an honest read on where you stand, and a plain answer on what your next framework actually takes.