Home / Trust Certifications / PCI DSS

Trust Certifications

PCI DSS

Protect payment card data and reach PCI DSS v4.0.1 compliance with a smaller scope and fewer surprises.

Payments team reviewing a cardholder data flow diagram
Image placeholder: Payments team reviewing a cardholder data flow diagram

Overview

What it is and who needs it

The Payment Card Industry Data Security Standard (PCI DSS) applies to every organisation that stores, processes or transmits payment card data, and to service providers that can affect its security. The current version is 4.0.1.

Most of the effort in PCI DSS is decided by scope. We start by mapping where card data really flows and reducing the systems in scope. Then we assess the gaps, support the fixes and prepare you for self-assessment or the formal assessment.

Who needs it

  • Merchants that accept card payments online or in person
  • Payment aggregators, gateways and fintech companies
  • Service providers that host or manage systems handling card data
  • Organisations whose acquirer or card brand has asked for evidence of compliance
Network diagram marking the cardholder data environment
Image placeholder: Network diagram marking the cardholder data environment

Scope

What is covered

Scoping and scope reduction

Data flow mapping, segmentation review and options such as tokenisation to shrink the environment in scope.

Gap assessment

Your controls compared with each of the 12 requirements of PCI DSS v4.0.1.

Remediation support

Practical help with configurations, policies, logging, testing and evidence.

SAQ support

Choosing the right self-assessment questionnaire and completing it accurately.

Assessment readiness

A pre-assessment review so the formal assessment holds no surprises.

Sustaining compliance

A calendar for the recurring tasks: scans, reviews, tests and training.

The standard

Six goals, twelve requirements

The gap assessment covers every requirement that applies to your environment.

Build and maintain a secure network and systems

  • 1 Network security controls
  • 2 Secure configurations

Protect account data

  • 3 Protect stored account data
  • 4 Encrypt card data sent over open networks

Maintain a vulnerability management programme

  • 5 Protect against malicious software
  • 6 Secure systems and software

Implement strong access control measures

  • 7 Restrict access by need to know
  • 8 Identify users and authenticate access
  • 9 Restrict physical access

Regularly monitor and test networks

  • 10 Log and monitor all access
  • 11 Test security regularly

Maintain an information security policy

  • 12 Policies and programmes

Our approach

How we work, step by step

01

Scoping workshop

We map card data flows, systems, people and third parties.

02

Scope reduction

We recommend segmentation, tokenisation or outsourcing to cut the systems in scope.

03

Gap assessment

Each applicable requirement is tested and the gaps are documented.

04

Remediation

We work with your teams to close gaps and collect evidence.

05

SAQ or readiness review

We support the self-assessment questionnaire or run a full pre-assessment.

06

Formal assessment support

We stay with you during the assessment and help to resolve queries.

Deliverables

What you receive

  • Cardholder data flow diagrams and scope document
  • Gap assessment report against the 12 requirements
  • Remediation plan and tracker
  • Self-assessment questionnaire support pack
  • Readiness report ahead of the formal assessment
  • Compliance calendar for recurring activities
Gap assessment tracker against the 12 requirements
Image placeholder: Gap assessment tracker against the 12 requirements

Why iSecurify

Three reasons customers choose us

01

Scope first

Reducing scope early saves more effort than any other step.

02

Hands-on remediation

We help to implement the fixes and do not stop at listing them.

03

Assessment without surprises

A readiness review tests your evidence before the assessor sees it.

Questions

Frequently asked questions

Which version applies now?

PCI DSS v4.0.1 is the current version. Version 4.0 was retired at the end of 2024, and the requirements that were future-dated in version 4.0 became mandatory on 31 March 2025.

Do we need a self-assessment questionnaire or a Report on Compliance?

That depends on your transaction volume, how you accept cards and what your acquirer or the card brands require. We confirm the validation route with you during scoping.

Is iSecurify a Qualified Security Assessor?

The formal assessment is carried out by a Qualified Security Assessor (QSA) company. iSecurify prepares you for that assessment. [QSA arrangement to be confirmed]

We use a payment gateway. Does PCI DSS still apply?

Usually yes, with a smaller scope. Outsourcing reduces what you must do yourself, but you remain responsible for the parts of the payment flow you control and for managing your provider.

How often must compliance be validated?

Every year, with recurring activities in between, such as quarterly external vulnerability scans.

Customer stories

What our customers say

  • Outsourcing our cybersecurity operations to iSecurify has been a strategic advantage. From real-time threat monitoring to compliance assistance, their managed services have brought us peace of mind and enabled our internal team to focus on business growth.

    Swapon Adhikary

    Director · The Hird

  • Following the launch of our website in both Dubai and India, we required immediate security validation to ensure platform integrity. iSecurify delivered a rapid yet comprehensive application security assessment, providing detailed and actionable findings. Their expert team collaborated directly with our developers to swiftly remediate vulnerabilities, enabling us to go live with confidence and security.

    Krutarth Pandya

  • We deployed iSecurify’s iSIEM-based monitoring with automated IP blocking, and the results were immediate. Malicious IPs targeting our systems were detected and blocked in real time. The integration was seamless, and the improvement in our threat response has been significant.

    Nandeep Mehta

Organisations we work with

Talk to us about PCI DSS.

Share a few details and a consultant will come back with a scope and next steps.

info@isecurify.co