Commercial & Industry / FOCUSED SERVICE

PCI DSS Readiness

Scope reduction, validation-path selection, and a gap assessment against every PCI DSS requirement before your assessor arrives.

WHAT THIS SERVICE ADDRESSES

The challenge behind the engagement.

This service is for a merchant or service provider that must validate against PCI DSS and wants the smallest defensible cardholder data environment first. We map every system that stores, processes, or transmits payment card data, everything connected to it, and the segmentation between them, then look for ways to shrink that scope before anything is assessed. We confirm your validation path, whether that is a self-assessment questionnaire or a full Report on Compliance, with your acquiring bank. We assess your environment against every current requirement, including those that recently became mandatory, and write each gap with a fix. You receive the data-flow and network diagrams, the gap report, and an evidence index. Validation belongs to your assessor or your own self-assessment; we sign neither the report nor its attestation.

WHEN THIS IS THE RIGHT FIT

Payment and platform leads at e-commerce merchants, SaaS companies that handle account data for their customers, and hospitality or healthcare businesses with card terminals, usually when the acquirer asks for a current attestation or the latest version of the standard exposes a flat network.

THE WORK BEHIND THE SERVICE

What we do.
What you can use.

Shrink the cardholder data environment first

We trace payment card data through every channel: hosted or embedded payment pages, the call center, terminals, and batch files, plus the systems that connect to them. We draw the data-flow and network diagrams, then look for tokenization, encryption, and segmentation changes that lift systems out of scope before any requirement is assessed.

Assess all twelve requirements as they read today

Working from the requirements that apply to your validation path, we inspect firewalls, cloud accounts, payment application settings, key management, and logging by hand rather than from a scanner report. Each gap is written against the requirement it fails, with a fix, and we prepare the targeted risk analyses the standard now expects you to document.

Prove segmentation and package the evidence

We plan and run a segmentation test by hand, because the standard requires testing to prove your boundaries hold, not just a scan report, then key the evidence index to each requirement with its sampled data. You receive the scope document, the gap report, the risk-analysis templates, and a readiness memo, and we stay available during the assessment.

IS THIS THE RIGHT ENGAGEMENT?

Who it’s for.
When you need it.

BEST SUITED FOR
  • E-commerce merchants and platforms that store, process, or transmit account data
  • Service providers handling cardholder data on behalf of their own customers
  • Payment leads facing a flat network with no segmentation boundaries
  • Hospitality or healthcare businesses running card terminals alongside other systems
WHEN IT’S TIME TO ENGAGE
  • An acquirer or brand demands a current, signed Attestation of Compliance
  • The move to v4.0.1 exposed newly mandatory requirements you do not meet
  • You added an embedded payment form affected by the SAQ A change
  • A merchant level changed and now requires a Report on Compliance
AGREED AROUND YOUR ENVIRONMENT

What the scope can include.

  • Account data discovery across every payment channel, with cardholder data-flow and network diagrams

  • Connected and security-impacting systems identified, with segmentation boundaries drawn and documented

  • Merchant level and validation path confirmed with your acquirer, from self-assessment through full Report on Compliance

  • Gap assessment against all twelve requirement areas, including the controls that recently became mandatory

  • Targeted risk analyses prepared for the requirements that call for them, plus any customized approach

  • Segmentation testing planned and performed by hand to confirm the boundaries actually hold

TRANSPARENT PRICING

What it typically costs.
One rate: $150/hour.

Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and the final deliverables included. Find the size closest to yours.

Small
$4,500–$9,000

Online or single-store merchant using a hosted payment page or standalone terminals

About 30–60 hours
Mid-size
$10,500–$21,000

Several stores, a call center, or a website that touches card data directly

About 70–140 hours
Large
$21,000–$42,000

High-volume merchant or service provider needing a full assessor report, multiple payment channels

About 140–280 hours
WHAT MOVES THE PRICE
  • Number of payment channels and systems that handle card data
  • Whether segmentation or tokenization can shrink the scope
  • Self-assessment questionnaire versus full assessor report
  • Number of locations and outside payment providers
TYPICAL TIMELINE

3–6 weeks for self-assessment merchants; 2–4 months ahead of a full assessor-led report

A Qualified Security Assessor's report on compliance is paid separately, typically $30,000–$100,000+ for Level 1 entities; quarterly external scans and penetration tests are also separate.

Get a fixed quote for your scope

Ranges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.

TANGIBLE DELIVERABLES

What you take forward.

  • Scope document with data-flow and network diagrams and the list of systems removed from scope
  • Validation-path memo to confirm with your acquirer, with the prerequisites your assessor will expect
  • Gap report by requirement with prioritized fixes, plus the completed risk-analysis templates
  • Evidence index keyed to the requirements, with segmentation test results and a readiness memo

Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.

SERVICE-SPECIFIC QUESTIONS

Before we get started.

Which self-assessment applies to us, and did that change in the latest version?

It depends on your payment channels and how much you outsource. Merchants that never touch card data because a compliant provider handles all of it sit in the simplest self-assessment; those whose own site can still affect a payment, even without receiving card data, fall into a stricter one. Since April 2025, merchants with embedded payment forms have to show the page is protected against tampering, or hold written confirmation from their processor. We draft the eligibility memo and the reasoning behind it; your acquiring bank has the final say on which path you file.

Can you act as our assessor and sign the Report on Compliance?

No. Only an assessor employed by a firm formally listed for this standard can perform that assessment and sign the report, and the merchant or service provider signs its own self-assessment and attestation. Our role is the readiness work in front of that step: scoping, gap assessment, remediation, and the evidence index your assessor works from. The separation matters in the standard itself, because whoever designs a custom control is not allowed to assess it. If you already have an assessor, we hand over to them and stay available for findings.

REFERENCE POINTS
START AT THE SOURCE

Let’s find your next move.

A focused conversation. A clear scope. A practical path to stronger security.

Let’s talk security