Home / Trust Certifications / PCI DSS
Trust Certifications
PCI DSS
Protect payment card data and reach PCI DSS v4.0.1 compliance with a smaller scope and fewer surprises.

Overview
What it is and who needs it
The Payment Card Industry Data Security Standard (PCI DSS) applies to every organisation that stores, processes or transmits payment card data, and to service providers that can affect its security. The current version is 4.0.1.
Most of the effort in PCI DSS is decided by scope. We start by mapping where card data really flows and reducing the systems in scope. Then we assess the gaps, support the fixes and prepare you for self-assessment or the formal assessment.
Who needs it
- Merchants that accept card payments online or in person
- Payment aggregators, gateways and fintech companies
- Service providers that host or manage systems handling card data
- Organisations whose acquirer or card brand has asked for evidence of compliance

Scope
What is covered
Scoping and scope reduction
Data flow mapping, segmentation review and options such as tokenisation to shrink the environment in scope.
Gap assessment
Your controls compared with each of the 12 requirements of PCI DSS v4.0.1.
Remediation support
Practical help with configurations, policies, logging, testing and evidence.
SAQ support
Choosing the right self-assessment questionnaire and completing it accurately.
Assessment readiness
A pre-assessment review so the formal assessment holds no surprises.
Sustaining compliance
A calendar for the recurring tasks: scans, reviews, tests and training.
The standard
Six goals, twelve requirements
The gap assessment covers every requirement that applies to your environment.
Build and maintain a secure network and systems
- 1 Network security controls
- 2 Secure configurations
Protect account data
- 3 Protect stored account data
- 4 Encrypt card data sent over open networks
Maintain a vulnerability management programme
- 5 Protect against malicious software
- 6 Secure systems and software
Implement strong access control measures
- 7 Restrict access by need to know
- 8 Identify users and authenticate access
- 9 Restrict physical access
Regularly monitor and test networks
- 10 Log and monitor all access
- 11 Test security regularly
Maintain an information security policy
- 12 Policies and programmes
Our approach
How we work, step by step
01
Scoping workshop
We map card data flows, systems, people and third parties.
02
Scope reduction
We recommend segmentation, tokenisation or outsourcing to cut the systems in scope.
03
Gap assessment
Each applicable requirement is tested and the gaps are documented.
04
Remediation
We work with your teams to close gaps and collect evidence.
05
SAQ or readiness review
We support the self-assessment questionnaire or run a full pre-assessment.
06
Formal assessment support
We stay with you during the assessment and help to resolve queries.
Deliverables
What you receive
- Cardholder data flow diagrams and scope document
- Gap assessment report against the 12 requirements
- Remediation plan and tracker
- Self-assessment questionnaire support pack
- Readiness report ahead of the formal assessment
- Compliance calendar for recurring activities

Why iSecurify
Three reasons customers choose us
01
Scope first
Reducing scope early saves more effort than any other step.
02
Hands-on remediation
We help to implement the fixes and do not stop at listing them.
03
Assessment without surprises
A readiness review tests your evidence before the assessor sees it.
Questions
Frequently asked questions
Which version applies now?
PCI DSS v4.0.1 is the current version. Version 4.0 was retired at the end of 2024, and the requirements that were future-dated in version 4.0 became mandatory on 31 March 2025.
Do we need a self-assessment questionnaire or a Report on Compliance?
That depends on your transaction volume, how you accept cards and what your acquirer or the card brands require. We confirm the validation route with you during scoping.
Is iSecurify a Qualified Security Assessor?
The formal assessment is carried out by a Qualified Security Assessor (QSA) company. iSecurify prepares you for that assessment. [QSA arrangement to be confirmed]
We use a payment gateway. Does PCI DSS still apply?
Usually yes, with a smaller scope. Outsourcing reduces what you must do yourself, but you remain responsible for the parts of the payment flow you control and for managing your provider.
How often must compliance be validated?
Every year, with recurring activities in between, such as quarterly external vulnerability scans.
Customer stories
What our customers say
-
Outsourcing our cybersecurity operations to iSecurify has been a strategic advantage. From real-time threat monitoring to compliance assistance, their managed services have brought us peace of mind and enabled our internal team to focus on business growth.
Swapon Adhikary
Director · The Hird
-
Following the launch of our website in both Dubai and India, we required immediate security validation to ensure platform integrity. iSecurify delivered a rapid yet comprehensive application security assessment, providing detailed and actionable findings. Their expert team collaborated directly with our developers to swiftly remediate vulnerabilities, enabling us to go live with confidence and security.
Krutarth Pandya
-
We deployed iSecurify’s iSIEM-based monitoring with automated IP blocking, and the results were immediate. Malicious IPs targeting our systems were detected and blocked in real time. The integration was seamless, and the improvement in our threat response has been significant.
Nandeep Mehta
Organisations we work with
Talk to us about PCI DSS.
Share a few details and a consultant will come back with a scope and next steps.
