Governance and compliance
PCI DSS
First we shrink the scope. Then we protect what is left.
What this work consists of
The biggest win in PCI DSS is rarely a new control: it is taking systems out of scope. Before protecting anything, we map where cardholder data flows, with a network diagram, and shrink the territory the standard reaches. Every system that leaves the scope is a control you do not have to implement or evidence every year.
With the scope reduced, we close the gaps in what remains and organize the evidence file. You do not need to know in advance which self-assessment questionnaire applies to your case: we identify it from your payment flow. We also deliver the responsibility matrix between you, your customers, and your vendors, because in card payments almost no requirement belongs to a single company.
On your side, the project needs access to the people who know the architecture, to the existing diagrams and contracts, and to the actual payment flow. You choose how far we go: just the gap assessment with an action plan, full remediation, or support through the end, with a rehearsal before formal validation. The certificate or the formal report on compliance is always issued by the QSA, hired by you.
How we conduct it, stage by stage
The stages and deliverables below describe the Full compliance work modality. The other modalities appear when you request the proposal.
Scope definition
We agree in writing what is in and what is out, and why. A badly defined scope is the most common cause of a project running over.
Scope reduction
Before protecting anything, we take out of scope everything that does not need to be there. That is where the biggest saving lives, and almost nobody does it first.
Gap assessment
We compare what exists today with what the reference requires, item by item, and classify each gap by risk and by effort to fix. The result comes out in order of attack: what to do first and why, instead of an inventory of everything that is wrong.
Implementation
We stand the controls up together with your team, write down what needs to exist on paper and train the people who will operate them. Nothing counts as implemented until it works in practice and someone on your side can sustain it.
Evidence routine
We set out how each control proves it worked, with an owner and a frequency, so the audit does not turn into a scramble.
What is not included
- Issuing the certificate or the formal report on compliance, which belongs to the QSA
- The mandatory quarterly scanning, which only a vendor approved by the card brands can sign off on
- Negotiating with your acquirer or the card brands, which remains yours
- Hiring the QSA and the scanning vendor, which is yours and preserves the independence of the validation
- Penetration tests, which are not part of this scope and can be contracted as a separate service
- Executing the network and architecture changes that scope reduction recommends, which stays with your team or vendor, with our plan in hand
- Fines, fees, and contract terms with acquirers or card brands, which belong to the business relationship between you
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.