1. Home
  2. Services
  3. PCI DSS consulting

PCI DSS consultant for merchants, processors and banks.

I've delivered 30 PCI DSS engagements across five countries, from SAQ guidance for merchants to full Reports on Compliance. I help you scope tightly, fix what matters and reach a clean assessment under PCI DSS v4.0.1.

PCI DSS engagements
30
Countries
5
Current standard
v4.0.1

What I do

End-to-end PCI DSS support.

Scoping and segmentation

Map the cardholder data environment, connected systems and what is genuinely out of scope. A tighter scope is the fastest way to cut the cost of compliance.

v4.0.1 gap assessment

A requirement-by-requirement review against PCI DSS v4.0.1, including the requirements that became mandatory on 31 March 2025, such as payment page script controls and targeted risk analyses.

Remediation roadmap

Every gap turned into a fix with an owner and a date, prioritised by risk and assessment impact, plus the policies and procedures the standard expects.

SAQ selection and completion

Choosing the right Self-Assessment Questionnaire (SAQ A, C-VT, D and others) for how you actually accept cards, then completing it with evidence that stands up to your acquirer.

RoC and AoC delivery

Evidence review, testing and interviews leading to the Report on Compliance and Attestation of Compliance for Level 1 merchants and service providers.

Staying compliant

Quarterly and annual activities, targeted risk analysis reviews and evidence discipline, so next year's assessment is not a scramble.

How an engagement runs

From first workshop to attestation.

  1. Scoping workshop

    Walk through card flows, systems and third parties to agree the scope and the right validation route: SAQ or RoC.

  2. Gap assessment

    Review each applicable v4.0.1 requirement against current controls and evidence, and record what is in place, partial or missing.

  3. Remediation roadmap

    Agree a prioritised plan with your technical and business owners, with realistic dates tied to the assessment window.

  4. Remediation support

    Answer implementation questions, review fixes and build the evidence pack as controls go live.

  5. Assessment and attestation

    Validate the controls and complete the SAQ or the Report on Compliance and Attestation of Compliance.

Where

PCI DSS work across five countries.

  • United Arab Emirates12
  • South Africa8
  • United States6
  • India2
  • Vietnam2

Number of PCI DSS client engagements per country. Client names stay confidential.

FAQ

PCI DSS questions I hear most.

Which PCI DSS SAQ do I need?

It depends on how your business accepts cards. E-commerce that fully outsources the payment page (a redirect or an iframe to a compliant provider) usually fits SAQ A. If your own website controls how card data reaches the provider, SAQ A-EP is more likely. Businesses that only key payments into a provider's virtual terminal often use SAQ C-VT. If you store, process or transmit card data on your own systems, expect SAQ D.

Your acquirer makes the final call, so confirm the choice with them before you start.

What changed with PCI DSS v4.0.1?

v4.0.1 is a limited revision of v4.0 that clarifies wording and guidance without adding new requirements. v4.0 was retired at the end of 2024, so v4.0.1 is now the version assessed.

The bigger change for most organisations is that the future-dated requirements introduced in v4.0 became mandatory on 31 March 2025. They include controls on payment page scripts, targeted risk analyses and broader multi-factor authentication.

How long does it take to become PCI DSS compliant?

It depends on your scope and how mature your controls already are. A focused gap assessment usually takes a few weeks. Remediation can take anything from weeks to several months. Getting the scope right at the start is what keeps the timeline under control.

Do I need a QSA and a Report on Compliance?

Level 1 merchants and service providers generally need an onsite assessment and a Report on Compliance by a Qualified Security Assessor. Lower levels can often self-assess with an SAQ. Your level depends on your transaction volumes and the requirements of your acquirer and the card brands.

Which regions do you work in?

Most of my PCI DSS work has been in the UAE, South Africa, the United States, India and Vietnam, delivered remotely with onsite work where the assessment requires it.

Next step

Planning a PCI DSS assessment?

Tell me how you accept cards and when your assessment is due. I'll tell you honestly what it takes.