What PCI DSS actually is
The Payment Card Industry Data Security Standard is a contractual requirement imposed by the card brands and enforced through your acquirer. Version 4.0 organises 12 requirements covering network security, data protection, access control, monitoring and policy. How you validate depends on volume and how you handle card data: a Self-Assessment Questionnaire for most, a Report on Compliance from a Qualified Security Assessor at higher volumes.
Who needs it
Merchants and service providers handling payment cards. If you use a hosted payment page or a provider like Stripe and never touch raw card data, your obligations are far lighter — usually SAQ A — and knowing that early saves a great deal of unnecessary work.
How long it takes
Scoping comes first, because reducing scope is worth more than any control you could implement. Where a QSA assessment is required, the timeline includes their availability. We will tell you which validation route actually applies to you before you start buying things you do not need.
What we do for your PCI DSS program
- Establish your cardholder data environment and cut the scope down to what genuinely belongs in it
- Determine the validation route that applies — which SAQ, or whether you need a QSA
- Draft the policies and procedures the twelve requirements call for
- Monitor segmentation, configuration, logging and access continuously rather than annually
- Assemble the evidence for your assessment and deal with the assessor's requests
PCI DSS questions we get asked
- We use Stripe. Does PCI DSS still apply to us?
- Yes, but usually at the lightest level. If card data never touches your systems, you are typically eligible for SAQ A, which is a small fraction of the full standard. Confirming that early is one of the most valuable things scoping does.
- What changed in v4.0?
- Version 4.0 adds a customised implementation approach, strengthens authentication requirements, expands scripting and phishing protections, and makes several previously best-practice items mandatory. If you were assessed against v3.2.1, expect real work to move across.
- Do we need a QSA?
- It depends on your transaction volume and merchant level, and on what your acquirer requires. Many companies can self-assess. We determine which applies to you during scoping rather than assuming the most expensive route.
- Can PCI DSS share evidence with SOC 2?
- A good deal of it, yes — access control, logging, vulnerability management and change control overlap substantially. Running both together avoids collecting the same evidence twice.
