PCI Compliance

PCI DSS Readiness

Merchant-focused PCI DSS readiness covering scope determination, SAQ selection (A, A-EP, D), control gap analysis, ASV scan coordination, and evidence package preparation so you arrive at QSA assessment ready.

Scope & CDE DeterminationSAQ SelectionControl Gap AnalysisASV Scan CoordinationQSA Handoff
$3,500fixed project+ taxes
Process
6
phases
AI
4
tools
You get
7
deliverables

How it runs

  1. 01

    Scope & CDE Determination

    Map all systems, processes, and people that store, process, or transmit cardholder data. Define the cardholder data environment and identify connected systems within scope.

  2. 02

    SAQ Selection

    Determine the correct SAQ based on payment acceptance channels: SAQ A for fully outsourced e-commerce, A-EP for redirect or iframe with merchant-controlled site, D for everything else.

  3. 03

    Control Gap Analysis

    Assess current controls against the relevant PCI DSS v4.0 requirements. Document gaps, customised controls where applicable, and the evidence each control will need.

  4. 04

    ASV Scan Coordination

    Coordinate quarterly external vulnerability scans by an Approved Scanning Vendor. Triage results, drive remediation, and obtain a passing scan report ahead of assessment.

  5. 05

    Evidence Package Preparation

    Build the evidence package: policies, procedures, configuration baselines, network diagrams, data flow diagrams, training records, and operational artefacts mapped to each requirement.

  6. 06

    QSA-Ready Handoff

    Deliver a clean readiness package, walk through it with internal stakeholders, and support the QSA assessment with clarifications and evidence as the formal assessment progresses.

AI assist

ai-toolkit.sh
AI-Assisted
$ cat tools.list
01
Scope Boundary AnalysisAnalyse network and data flows to surface unintended in-scope systems
02
Control Mapping AIMap existing controls and evidence to PCI DSS v4.0 requirements consistently
03
Evidence Gap DetectionIdentify missing or stale evidence before the QSA does
04
ASV Finding TriagePrioritise ASV scan findings by remediation effort and pass-or-fail impact
$ _

What you receive

  • Cardholder data environment scope document
  • SAQ selection rationale and worksheet
  • Control gap analysis with remediation plan
  • Network and data flow diagrams
  • Coordinated ASV scan with passing report
  • Evidence package mapped to PCI DSS v4.0
  • QSA-ready readiness pack and walkthrough

Ready to scope this engagement?

Every engagement is scoped individually. Get a tailored quote within 24 hours.

Request a Quote
PCI DSS ReadinessContact us