Protect cardholder data. Reduce risk. Pass PCI DSS v4.0 with confidence
We help merchants and service providers scope, implement, and evidence the controls required by PCI DSS v4.0—from discovery and segmentation to policies, tech safeguards, and audit/SAQ support. Our approach is practical, sales-friendly, and auditor-ready.
Why PCI DSS matters
- Avoid fines & brand damage — Reduce breach risk and card scheme penalties
- Win enterprise customers — Demonstrate strong protection for CHD/SAD (cardholder and sensitive auth data)
- Streamline operations — Right-size scope and automate evidence to lower ongoing effort
What we do (end-to-end)
1) Scope, Roles & Readiness
- Define merchant vs service provider scope; map CDE (cardholder data environment).
- Identify data flows, storage, transmission, and third parties; create a scope reduction plan
2) Scope Reduction & Architecture
- Network segmentation, tokenization, vaulting, and P2PE/EMV options
- E-commerce patterns (SAQ-A/A-EP) and hosted payments to minimize CDE
3) Control Design & Implementation (v4.0)
- Access & Authentication: least privilege, MFA, password standards
- Vulnerability & Patch: quarterly ASV scans, internal scans, risk-based patch SLAs, change control
- Secure Coding & App Security: SAST/DAST, WAF, code reviews, dependency control
- Logging & Monitoring: centralized logs, time sync, alerting, incident response runbooks
- Network Security: FW rules, IDS/IPS, secure configurations, anti-malware/EDR/XDR
- Crypto & Key Management: strong encryption in transit/at rest, key rotation and custody
- Physical & Operational: media handling, backup/restore testing, vendor oversight
- Targeted Risk Analyses & Customized Approach (where appropriate under v4.0)
4) Policies, Training & Governance
- Full policy library (access, crypto, change, IR, vulnerability mgmt, AUP, vendor)
- RACI, awareness training, quarterly reviews, KPI dashboards
5) Testing & Evidence
- Penetration testing (CDE & segmentation), remediation, re-tests
- Evidence pack: configs, tickets, screenshots, logs, scan reports, pen-test reports
6) SAQ/ROC & Attestation
- Select the right SAQ type (A, A-EP, B, B-IP, C, C-VT, P2PE, D)
- Prepare for ROC/AOC with a QSA or guide you through SAQ attestation
- Manage third-party AOC collection and contract clauses
7) Continuous Compliance
- Build “business-as-usual” tasks, automation/integrations (SSO, SIEM, ticketing, CI/CD, cloud)
- Quarterly ASV scans, semi-annual reviews, annual exercises—on autopilot
Deliverables you receive
- Scope & Data-Flow Diagrams and CDE inventory
- Scope Reduction & Segmentation Plan
- Policy & Procedure Library (audit-ready)
- Control Matrix (v4.0) mapped to your environment
- Risk Register & targeted risk analyses (v4.0)
- Vulnerability & Pen-Test Reports (incl. segmentation tests)
- Evidence Workbook (logs, scans, tickets, configs)
- SAQ/ROC Preparation Pack and AOC draft
- Quarterly Compliance Calendar & dashboards
Who it’s for
- Merchants (e-commerce, retail, fintech, subscription/SaaS) and service providers handling CHD/SAD
- Teams seeking first-time certification/attestation or upgrading to PCI DSS v4.0
- Organizations wanting PCI mapped to ISO 27001, SOC 2, DPDP, GDPR to avoid duplicate work
A right-sized, resilient PCI program that reduces scope and risk, passes SAQ/ROC smoothly, and earns customer trust—with repeatable evidence collection for renewals.
Contact Us Today to book a PCI readiness workshop and receive a tailored v4.0 implementation plan.
Frequently Asked Questions — PCI DSS Compliance
PCI DSS (Payment Card Industry Data Security Standard) is a mandatory security standard for any organisation that stores, processes, or transmits cardholder data. Version 4.0 fully replaced 3.2.1 in 2025 and introduces stronger authentication, more granular risk-based testing, and expanded scoping requirements. If you accept card payments in any form — online, in-app, or in-person — PCI DSS applies to you, regardless of company size.
A Self-Assessment Questionnaire (SAQ) is a self-administered validation used by smaller merchants with lower transaction volumes, while a Report on Compliance (ROC) is a formal assessment conducted by a Qualified Security Assessor (QSA), required for Level 1 merchants (typically over 6 million transactions annually) and mandated by some card brands or acquiring banks regardless of volume. Your acquiring bank determines which applies to you.
Scope reduction means minimising the number of systems that touch cardholder data — through network segmentation, tokenisation, or outsourcing card handling entirely to a PCI-compliant payment processor. A smaller scope means fewer systems to secure, test, and evidence, which directly reduces both compliance cost and ongoing audit burden.
You need a QSA if your card brand or acquiring bank requires a formal ROC — typically for Level 1 merchants or service providers. Smaller merchants completing an SAQ can self-assess, though many still engage a consultant to prepare evidence and avoid gaps that would fail a later ROC or breach investigation.
Consequences range from fines levied by your acquiring bank (which can escalate monthly until resolved) to increased transaction fees, and in the event of a breach while non-compliant, liability for fraud losses and forensic investigation costs that would otherwise be limited. Repeated non-compliance can result in losing the ability to accept card payments altogether.
Frequently Asked Questions
How much does PCI DSS compliance cost in India?
Cost depends heavily on scope — how many systems touch cardholder data, your SAQ level, and whether you need a full Report on Compliance (ROC) with a Qualified Security Assessor (QSA) or a self-assessment (SAQ). Scope reduction (tokenisation, network segmentation) is usually the biggest lever to bring cost down before the assessment itself.
PCI DSS vs ISO 27001 — do I need both?
They're complementary, not redundant. PCI DSS specifically protects cardholder data; ISO 27001 is a broader information security management system covering all sensitive data. Many controls overlap (access management, encryption, incident response), so organisations needing both should map them to a single control framework rather than running separate programmes.