The challenge behind the engagement.
This service is for a merchant or service provider that must validate against PCI DSS and wants the smallest defensible cardholder data environment first. We map every system that stores, processes, or transmits payment card data, everything connected to it, and the segmentation between them, then look for ways to shrink that scope before anything is assessed. We confirm your validation path, whether that is a self-assessment questionnaire or a full Report on Compliance, with your acquiring bank. We assess your environment against every current requirement, including those that recently became mandatory, and write each gap with a fix. You receive the data-flow and network diagrams, the gap report, and an evidence index. Validation belongs to your assessor or your own self-assessment; we sign neither the report nor its attestation.
Payment and platform leads at e-commerce merchants, SaaS companies that handle account data for their customers, and hospitality or healthcare businesses with card terminals, usually when the acquirer asks for a current attestation or the latest version of the standard exposes a flat network.
What we do.
What you can use.
Shrink the cardholder data environment first
We trace payment card data through every channel: hosted or embedded payment pages, the call center, terminals, and batch files, plus the systems that connect to them. We draw the data-flow and network diagrams, then look for tokenization, encryption, and segmentation changes that lift systems out of scope before any requirement is assessed.
Assess all twelve requirements as they read today
Working from the requirements that apply to your validation path, we inspect firewalls, cloud accounts, payment application settings, key management, and logging by hand rather than from a scanner report. Each gap is written against the requirement it fails, with a fix, and we prepare the targeted risk analyses the standard now expects you to document.
Prove segmentation and package the evidence
We plan and run a segmentation test by hand, because the standard requires testing to prove your boundaries hold, not just a scan report, then key the evidence index to each requirement with its sampled data. You receive the scope document, the gap report, the risk-analysis templates, and a readiness memo, and we stay available during the assessment.
Who it’s for.
When you need it.
- E-commerce merchants and platforms that store, process, or transmit account data
- Service providers handling cardholder data on behalf of their own customers
- Payment leads facing a flat network with no segmentation boundaries
- Hospitality or healthcare businesses running card terminals alongside other systems
- An acquirer or brand demands a current, signed Attestation of Compliance
- The move to v4.0.1 exposed newly mandatory requirements you do not meet
- You added an embedded payment form affected by the SAQ A change
- A merchant level changed and now requires a Report on Compliance
What the scope can include.
- 01
Account data discovery across every payment channel, with cardholder data-flow and network diagrams
- 02
Connected and security-impacting systems identified, with segmentation boundaries drawn and documented
- 03
Merchant level and validation path confirmed with your acquirer, from self-assessment through full Report on Compliance
- 04
Gap assessment against all twelve requirement areas, including the controls that recently became mandatory
- 05
Targeted risk analyses prepared for the requirements that call for them, plus any customized approach
- 06
Segmentation testing planned and performed by hand to confirm the boundaries actually hold
What it typically costs.
One rate: $150/hour.
Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and the final deliverables included. Find the size closest to yours.
Online or single-store merchant using a hosted payment page or standalone terminals
About 30–60 hoursSeveral stores, a call center, or a website that touches card data directly
About 70–140 hoursHigh-volume merchant or service provider needing a full assessor report, multiple payment channels
About 140–280 hours- Number of payment channels and systems that handle card data
- Whether segmentation or tokenization can shrink the scope
- Self-assessment questionnaire versus full assessor report
- Number of locations and outside payment providers
3–6 weeks for self-assessment merchants; 2–4 months ahead of a full assessor-led report
A Qualified Security Assessor's report on compliance is paid separately, typically $30,000–$100,000+ for Level 1 entities; quarterly external scans and penetration tests are also separate.
Get a fixed quote for your scopeRanges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.
What you take forward.
- Scope document with data-flow and network diagrams and the list of systems removed from scope
- Validation-path memo to confirm with your acquirer, with the prerequisites your assessor will expect
- Gap report by requirement with prioritized fixes, plus the completed risk-analysis templates
- Evidence index keyed to the requirements, with segmentation test results and a readiness memo
Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.
Before we get started.
Which self-assessment applies to us, and did that change in the latest version?
It depends on your payment channels and how much you outsource. Merchants that never touch card data because a compliant provider handles all of it sit in the simplest self-assessment; those whose own site can still affect a payment, even without receiving card data, fall into a stricter one. Since April 2025, merchants with embedded payment forms have to show the page is protected against tampering, or hold written confirmation from their processor. We draft the eligibility memo and the reasoning behind it; your acquiring bank has the final say on which path you file.
Can you act as our assessor and sign the Report on Compliance?
No. Only an assessor employed by a firm formally listed for this standard can perform that assessment and sign the report, and the merchant or service provider signs its own self-assessment and attestation. Our role is the readiness work in front of that step: scoping, gap assessment, remediation, and the evidence index your assessor works from. The separation matters in the standard itself, because whoever designs a custom control is not allowed to assess it. If you already have an assessor, we hand over to them and stay available for findings.
- 2017 Trust Services Criteria (With Revised Points of Focus – 2022) | Resources | AICPA & CIMA
- The Security Rule | HHS.gov
- Guidance on Risk Analysis | HHS.gov
- NIST SP 800-66 Rev. 2: Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide
- PCI Data Security Standard (PCI DSS)
- New Information Supplement: PCI DSS Scoping and Segmentation Guidance for Modern Network Architectures
- ISO/IEC 27001:2022 - Information security management systems
