Get Your PCI DSS Quote
Annual validation that keeps your card processing switched on
Your acquirer has asked for an Attestation of Compliance and set a date. PCI DSS applies to anyone who stores, processes or transmits cardholder data, through the contract with the acquiring bank rather than through law. Validation is annual, the effort depends on your merchant level, and non-compliance ends in fines or withdrawn processing.
You need PCI DSS if…
- !Your acquirer has set a date for the Attestation of Compliance and started charging non-compliance fees.
- !Transaction volumes have crossed a merchant level threshold and a self-assessment questionnaire no longer suffices.
- !A card data compromise has triggered a forensic investigation and mandatory validation by a qualified assessor.
- !Call centre agents take card numbers over the phone and the recordings are being stored.
- !A new booking engine or payment page has changed how card data moves through your network.
- !You have taken on card processing for another brand and inherited its cardholder environment.
A prescriptive security standard for cardholder data, set by the payment card brands. It covers network segmentation, encryption, access control, logging, vulnerability management and testing, and applies to every system that stores, processes or transmits card data, plus anything connected to them.
Validation is not certification. Larger merchants receive a Report on Compliance from a Qualified Security Assessor; smaller ones complete a Self-Assessment Questionnaire. Both end in an Attestation of Compliance.
Validation is annual. Between attestations, quarterly external scans by an approved scanning vendor and defined testing intervals keep the status current.
Merchants of any size that accept cards, plus service providers, payment processors, hosting firms and call centres that touch cardholder data on someone else’s behalf.
Where this certification is demanded
PCI DSS is applicable across 3 of the 25 industries SIS covers. The pages below set out the specific reason it comes up in each one.
What PCI DSS Actually Requires
The backbone an implementer has to build, in the order it usually gets built.
A documented map of where card data enters, is stored, processed and leaves, covering every channel - terminals, web, phone, batch files and third parties.
The cardholder data environment separated from the corporate network by controls you can test, so the scope of everything else stays small and affordable.
Strong cryptography for card data in transit over open networks and at rest, with documented key custody, rotation and split knowledge for anyone handling keys.
Unique IDs, least privilege justified by job role, multi-factor authentication into the cardholder environment, and periodic reviews that actually remove access.
Audit trails from every in-scope system, daily review of security events, time synchronisation, and retention long enough to investigate a compromise months later.
Quarterly internal and external scanning, annual internal and external penetration testing, segmentation testing, and patching within defined windows for critical issues.
How PCI DSS Validation Works
No black box. A defined, time-bound route from first call to Attestation of Compliance.
Scoping & Level Confirmation
We confirm annual transaction volumes, channels and acquirer requirements to establish merchant or service provider level, and therefore whether you need a Report on Compliance or a questionnaire.
3–5 daysGap Analysis & Scope Reduction
Someone always finds card numbers where they should not be: a spreadsheet finance built years ago and still emails monthly. Each discovery widens the environment before segmentation narrows it again.
2–4 weeksRemediation & Evidence Period
Controls are implemented and left running long enough to produce evidence - scan results, log reviews, access reviews, penetration test and retest reports the assessor can sample.
1–6 months by gapAssessment & Attestation
The signed Attestation of Compliance goes to your acquirer, who records the date and starts counting twelve months. Quarterly scans keep running in between, and a missed one shows later.
Annual; scans quarterlyIndustries That Need PCI DSS
Commonly taken alongside
Not Sure Which Certification You Need?
Three questions. The selector reads the same industry-to-standard mapping this whole site is built on, then shortlists what applies to you.
Which sector best describes your organisation?
Most of the cost is decided at scoping
PCI budgets go wrong in one place: a flat network nobody has segmented yet. Settle where the cardholder data actually stops and the rest of the estimate follows.
Get My Free Quote →What PCI DSS Changes for Your Business
Certification is not a certificate on the wall. It is a working system that pays for itself.
Processing agreement protected
Acquirers escalate from monthly non-compliance fees to withdrawal of processing. A current attestation removes that pressure and the fees attached to it.
Smaller scope, lower cost
Tokenisation, redirection and segmentation take systems out of scope entirely. The cheapest requirement is always the one that no longer applies to you.
Breach liability reduced
After a card compromise the schemes examine whether you were compliant at the time. Evidence of validated controls materially changes what follows.
Enterprise contracts unblocked
Large merchants require an attestation from any service provider touching their card flows, and will not onboard a supplier without one on file.
Discipline that lasts twelve months
Quarterly scans, daily log review and periodic access reviews turn the annual scramble into routine work that also serves other audits.
One standard, every market
The scheme rules are global. A single validated environment covers card acceptance across countries instead of a separate exercise in each.
Knowledge Base - Downloads
Practical documents prepared by our auditors. Fill the short form once and every download on the page unlocks.
Scope reduction checklist for card data
Where card data hides - call recordings, mailboxes, spreadsheets, legacy terminals - and what taking each one out of scope is worth.
Merchant levels and which validation applies
How transaction volume and channel decide whether you need a Report on Compliance or a self-assessment questionnaire, and who sets the level.
Cardholder data flow diagram template
A structured diagram and inventory covering every entry point, store and transmission path, in the format assessors expect to receive.
Staying compliant between annual attestations
The quarterly scans, log reviews and access reviews that keep validation honest, and what typically lapses by month four.
Frequently Asked Questions
Straight answers to what buyers ask before they commit to PCI DSS.
Is PCI DSS a law?
Do we need a Qualified Security Assessor?
We use a hosted payment page. Are we out of scope?
How long is validation valid for?
What about card details taken over the phone?
Does ISO/IEC 27001 certification cover PCI DSS?
Start work on this year’s attestation
The acquirer’s date does not move. What can move is how much of your network is still inside the cardholder environment when the assessor arrives.
Get My Free Quote → WhatsApp Us