Are you a QSA?
We work alongside accredited QSA firms and prepare you so the formal assessment is a confirmation, not a discovery exercise.
Extended answers to the questions buyers, boards and procurement teams ask before commissioning PCI DSS v4.0 Compliance.
Delivered by an ISO/IEC 27001, 27701 & 9001 certified organisation
We work alongside accredited QSA firms and prepare you so the formal assessment is a confirmation, not a discovery exercise.
Customised approach, expanded MFA, targeted risk analyses and stronger requirements on authenticated scanning, scripts and e-commerce.
Yes. Even with full tokenisation and a hosted payment page, you remain in scope for SAQ A or SAQ A-EP. The acquirer or scheme determines which SAQ applies.
SAQs are self-assessment questionnaires for lower-volume merchants. A RoC is a Report on Compliance written by a QSA for Level 1 merchants and service providers. An AoC is the Attestation of Compliance signed off either way.
Predictable timeline of 90 to 150 days from kickoff to QSA sign-off for mid-size environments. Complex multi-acquirer estates take 6 to 9 months.
Yes — scope reduction through tokenisation, network segmentation, P2PE and outsourcing is usually our highest-ROI workstream. Most clients see 40–70% scope reduction.
Approximately 70% of ISO 27001 Annex A controls overlap with PCI DSS requirements. We map and evidence once across both frameworks for clients running joint programmes.
We coordinate with the acquirer, card schemes and a PCI Forensic Investigator (PFI) under your incident plan and reset the validation timeline once containment is confirmed.
Every engagement is led by a partner or principal with at least 12 years in compliance & certification and supported by certified consultants (CISA, CISM, CISSP, CIPP/E, ISO 27001 Lead Auditor, ISO 42001 Lead Implementer, OSCP, CREST). You meet the actual delivery team before contracts are signed.
All client data stays within the regions you authorise. NDAs are signed before scoping calls, and we offer fully on-premise delivery for sensitive engagements. For UAE and KSA clients, evidence remains in-country by default.
Yes. We routinely collaborate with EY, Deloitte, KPMG, PwC, BDO and Grant Thornton as your implementation partner while they retain audit independence. Roles are agreed upfront in writing to preserve auditor independence rules.
Yes — our Managed Compliance Service operates the programme on a monthly subscription, covering control monitoring, evidence collection, internal audit and recertification across every framework in scope.
Success criteria are agreed in the engagement charter — typically a passed certification or regulator submission, an audit-ready evidence repository, trained control owners and a 12-month continuous-improvement plan.