Englishالعربية Soon
Under attack?
PCI DSS · Level 1 assessment

A Report on Compliance is the deliverable. Knowing your scope is the work.

A consultative Level 1 assessment of your cardholder data environment: which controls are met, where the weaknesses and gaps are, and a ROC and AOC that hold up, with per-control status visible throughout rather than revealed at the end.

QSA-led
Qualified Security Assessor on every engagement
Real time
Per-control status throughout the engagement
Quarterly
Business-as-usual reviews across the term
ROC + AOC
Report and attestation, QA’d before release
Approach

Consultative, not adversarial

The assessment works alongside you to examine the cardholder data environment and the PCI DSS scope, identifying which controls meet the requirements and where the weaknesses, vulnerabilities and missing controls sit within the infrastructure.

Where a requirement cannot be met directly, applicable controls are reviewed with your compliance owner to identify compensating controls that satisfy it. Progress and control status are transparent throughout, so remediation starts during the engagement rather than after the report lands.

An internal compliance council interprets the intent of the standard where a scenario is genuinely complicated, which is what keeps judgements consistent between assessors rather than dependent on who you drew.

Assessment activities

Five phases, from kickoff to closeout

Phase 0
Engagement planning
A kickoff meeting agrees timeframes, critical milestones and resources; reviews architecture designs, data flow and network diagrams; and captures the asset inventory covering facilities, people, systems, devices and applications. An engagement plan is issued afterwards and maintained for the term, including the update schedule, weekly status reporting and the escalation path for both sides.
Phase 1
Technology and organisational review
A team including at minimum a Qualified Security Assessor examines the cardholder data environment, its segmentation and the assessment scope. Policies, procedures, asset inventory, network diagrams and cardholder data flows are reviewed to establish how the CDE actually operates. Sampling is decided and evidence sets created where applicable, a tracked task list is published, and the personnel interview schedule is set up.
Phase 2
Control analysis and reporting
The captured information is analysed against the PCI DSS control set. Where a requirement is not met directly, compensating controls are reviewed with your compliance owner. Progress and per-control status are visible in real time throughout, separating what is compliant from what needs remediation. A Report on Compliance is written and an Attestation of Compliance signed where applicable.
Phase 3
Quality assurance
Every deliverable passes an internal quality assurance programme before release, so what reaches you has already been checked against the standard rather than checked by you.
Phase 4
Presentation and closeout
A closeout meeting with your decision makers covers the assessment overview, any changes to PCI DSS and related standards, findings and recommendations, and the areas you may want to address next.
Control coverage

Six control groups, assessed and reported on

The control set is governed by the PCI Security Standards Council and updated from time to time. Applicable changes are covered at closeout and in the ongoing reviews.

01

Build and maintain a secure network and systems

Firewall configuration protecting cardholder data; no vendor-supplied defaults for system passwords and security parameters.

02

Protect cardholder data

Stored cardholder data protected; transmission encrypted across open, public networks.

03

Maintain a vulnerability management program

All systems protected against malware with anti-virus kept current; secure systems and applications developed and maintained.

04

Implement strong access control measures

Access to cardholder data restricted by business need-to-know; access to system components identified and authenticated; physical access restricted.

05

Regularly monitor and test networks

All access to network resources and cardholder data tracked and monitored; security systems and processes tested regularly.

06

Maintain an information security policy

A policy addressing information security maintained for all personnel.

Ongoing

Maturity scoring

Beyond pass and fail, each reviewed control receives a maturity rating for how it is implemented, so you can prioritise what to strengthen next rather than treating every gap as equivalent.

Risk assessment →

Ongoing

Business-as-usual reviews

Quarterly review meetings across the term monitor whether the processes keeping you compliant are actually operating, which is what prevents the annual scramble from becoming annual.

Governance and compliance →

Included

Deliverables and included activities

Report on Compliance (ROC)
Attestation of Compliance (AOC), where applicable
External vulnerability scanning to ASV requirements
Security maturity scores per reviewed control
Engagement plan, maintained for the term
Weekly status reporting and escalation path
Tracked task list with live progress
Quarterly business-as-usual review meetings
Updates on changes to PCI DSS and related standards
Closeout presentation to your decision makers
Related

Work that reduces the cost of the next one

PCI-S3

If you develop payment software, the secure software standard is a separate validation.

Penetration testing

Regular testing of the CDE is a requirement, not an optional extra.

Vulnerability management

Quarterly scanning is the minimum. A running cycle is what keeps the environment assessable.

Scope it before you price it.

Scope determines everything about a PCI DSS assessment. We establish the CDE boundary first and look for what can be taken out of it.