Scoping and segmentation
Map the cardholder data environment, connected systems and what is genuinely out of scope. A tighter scope is the fastest way to cut the cost of compliance.
I've delivered 30 PCI DSS engagements across five countries, from SAQ guidance for merchants to full Reports on Compliance. I help you scope tightly, fix what matters and reach a clean assessment under PCI DSS v4.0.1.
What I do
Map the cardholder data environment, connected systems and what is genuinely out of scope. A tighter scope is the fastest way to cut the cost of compliance.
A requirement-by-requirement review against PCI DSS v4.0.1, including the requirements that became mandatory on 31 March 2025, such as payment page script controls and targeted risk analyses.
Every gap turned into a fix with an owner and a date, prioritised by risk and assessment impact, plus the policies and procedures the standard expects.
Choosing the right Self-Assessment Questionnaire (SAQ A, C-VT, D and others) for how you actually accept cards, then completing it with evidence that stands up to your acquirer.
Evidence review, testing and interviews leading to the Report on Compliance and Attestation of Compliance for Level 1 merchants and service providers.
Quarterly and annual activities, targeted risk analysis reviews and evidence discipline, so next year's assessment is not a scramble.
How an engagement runs
Walk through card flows, systems and third parties to agree the scope and the right validation route: SAQ or RoC.
Review each applicable v4.0.1 requirement against current controls and evidence, and record what is in place, partial or missing.
Agree a prioritised plan with your technical and business owners, with realistic dates tied to the assessment window.
Answer implementation questions, review fixes and build the evidence pack as controls go live.
Validate the controls and complete the SAQ or the Report on Compliance and Attestation of Compliance.
Where
Number of PCI DSS client engagements per country. Client names stay confidential.
FAQ
It depends on how your business accepts cards. E-commerce that fully outsources the payment page (a redirect or an iframe to a compliant provider) usually fits SAQ A. If your own website controls how card data reaches the provider, SAQ A-EP is more likely. Businesses that only key payments into a provider's virtual terminal often use SAQ C-VT. If you store, process or transmit card data on your own systems, expect SAQ D.
Your acquirer makes the final call, so confirm the choice with them before you start.
v4.0.1 is a limited revision of v4.0 that clarifies wording and guidance without adding new requirements. v4.0 was retired at the end of 2024, so v4.0.1 is now the version assessed.
The bigger change for most organisations is that the future-dated requirements introduced in v4.0 became mandatory on 31 March 2025. They include controls on payment page scripts, targeted risk analyses and broader multi-factor authentication.
It depends on your scope and how mature your controls already are. A focused gap assessment usually takes a few weeks. Remediation can take anything from weeks to several months. Getting the scope right at the start is what keeps the timeline under control.
Level 1 merchants and service providers generally need an onsite assessment and a Report on Compliance by a Qualified Security Assessor. Lower levels can often self-assess with an SAQ. Your level depends on your transaction volumes and the requirements of your acquirer and the card brands.
Most of my PCI DSS work has been in the UAE, South Africa, the United States, India and Vietnam, delivered remotely with onsite work where the assessment requires it.
Next step
Tell me how you accept cards and when your assessment is due. I'll tell you honestly what it takes.