PCI DSS
Compliance

Help to achieve and maintain PCI DSS — gap analysis, scope reduction and segmentation guidance, SAQ and RoC preparation, remediation, and QSA coordination for any organisation handling cardholder data.

Overview

Protect cardholder data, prove it.

Any organisation that stores, processes, or transmits payment-card data must meet PCI DSS. We help you scope it correctly, reduce that scope where possible, and build the controls and evidence to satisfy your acquirer or a QSA.

We run a gap analysis against PCI DSS v4.0, advise on segmentation to shrink your cardholder data environment, prepare your SAQ or Report on Compliance, drive remediation, and coordinate with your QSA — and deliver the segmentation and penetration testing PCI DSS requires.


Scope

What we deliver.

From scoping and segmentation to validation.

Framework: PCI DSS v4.0 SAQ & RoC Requirement 11.4 QSA coordination

FAQ

PCI DSS FAQ

The questions we're asked most about scope, cost, and timing.

How much does PCI DSS compliance cost?
PCI DSS support is typically €2,500–4,000 per month over a 2–4 month engagement, depending on merchant level, scope, and SAQ vs RoC. Use our estimator for a tailored figure.
How long does PCI DSS compliance take?
Most organisations reach validation in 2–4 months, depending on the size of the cardholder data environment and remediation required.
What is the difference between an SAQ and a RoC?
An SAQ is a self-validation route for eligible merchants. A Report on Compliance (RoC) is a formal assessment by a QSA, required for higher transaction volumes. We support both.
Do you provide the required penetration and segmentation testing?
Yes — PCI DSS requirement 11.4 mandates penetration and segmentation testing. We deliver both; see our PCI DSS segmentation testing service.
Can you reduce our PCI scope?
Often, yes — segmentation and tokenisation can dramatically shrink your cardholder data environment, reducing effort and risk.
Which PCI DSS version do you work to?
PCI DSS v4.0 (and v4.0.1), including the future-dated requirements you should plan for now.
How do we know our merchant level?
It depends on annual card transaction volume; we help you determine your level and the right validation route (SAQ or RoC).
Can you help reduce our PCI scope?
Yes — segmentation and tokenisation can dramatically shrink your cardholder data environment, cutting cost and risk.
Do you coordinate with a QSA?
Yes — we prepare you and work directly with your QSA through validation; we can recommend one if needed.
Does PCI require penetration testing?
Yes — requirement 11.4 mandates penetration and segmentation testing, which we deliver.

Related services

Explore more.

Ready to tackle PCI DSS?

A 30-minute scoping call costs nothing. A card-data breach costs considerably more.

Book a meeting Send an email