FramewiseCOMPLIANCE
Practice

PCI DSS

The card brand requirement for anyone who stores, processes, or transmits cardholder data.

What it is

PCI DSS v4.0 sets twelve requirement groups covering network security, cardholder data protection, vulnerability management, access control, monitoring, and policy. Validation depends on merchant or service provider level: a self-assessment questionnaire for lower volumes, a Report on Compliance from a Qualified Security Assessor for higher ones. Scope is defined by the cardholder data environment, and reducing that scope is usually the highest-value work in the program.

Who typically needs it

  • Fintech and payments companies validating as service providers
  • Merchants whose acquirer has escalated them to a higher validation level
  • Platforms whose customers inherit compliance obligations from them
  • Companies whose card data footprint grew faster than their segmentation
  • Organizations facing the v4.0 future-dated requirements

What the engagement looks like

Baseline. We define the cardholder data environment, map data flows, and assess against the applicable SAQ or Report on Compliance requirements. Scope reduction analysis comes first, because every requirement applies to everything in scope.

Build. We work through segmentation, key management, logging and monitoring, and the access control requirements, and author the policy and procedure set. Where tokenization or a hosted payment page can remove systems from scope, we design that path.

Build, continued. The v4.0 customized approach allows alternative implementations with documented risk analysis. We use it where it genuinely fits and avoid it where it adds assessor scrutiny without benefit.

Audit Sprint. We mock the QSA assessment, complete segmentation and penetration testing readiness, and manage the assessor relationship through fieldwork and the Report on Compliance.

Steady State. PCI is a continuous requirement with quarterly scanning, annual testing, and ongoing evidence obligations. We run the calendar so the annual validation is a formality.

Common failure modes

  • Scope defined by system inventory rather than by data flow, which understates the environment
  • Segmentation asserted but never tested, which fails at the assessor stage
  • Quarterly scans run but failing scans not remediated and rescanned within the window
  • Treating v4.0 future-dated requirements as optional past their effective date

Price range

Programs typically run between $40,000 and $90,000 for the Build phase, varying considerably by merchant or service provider level.

Related frameworks

Talk to us about your PCI DSS.

Thirty minutes on the calendar, an honest read on where you stand, and a plain answer on what your next framework actually takes.

Book a consultation