Governance. Risk. Compliance. Cybersecurity.
FAQs

FAQs — PCI DSS v4.0

Common questions buyers and boards ask before commissioning a PCI DSS v4.0 programme.

  • ISO/IEC 27001 Certified
  • ISO/IEC 27701 Certified
  • ISO 9001 Certified

Delivered by an ISO/IEC 27001, 27701 & 9001 certified organisation

How long does PCI DSS v4.0 take?

Most mid-size organisations complete the programme in 12 to 16 weeks. Large multi-entity scopes typically take four to six months.

What does PCI DSS v4.0 cost?

Implementation fees vary by scope, headcount, geographies and parallel frameworks. Certification or assessor fees are separate. We share a fixed-fee proposal after a free 30-minute scoping call.

Do you provide policy and evidence templates?

Yes — every engagement starts with our template library, refined across hundreds of programmes and aligned to current versions of every framework we cover.

Can MAST act as our auditor and implementer?

No — independence rules prohibit it. We deliver implementation, internal audit and management review; an accredited external body performs PCI DSS v4.0 certification.

What happens after certification?

We hand over a 90-day operating playbook and offer a Managed Compliance Service to keep the programme audit-ready year on year.