PCI DSS — the Payment Card Industry Data Security
Standard — is the PCI Security Standards Council's framework for every
organisation that stores, processes or transmits
cardholder data or
sensitive authentication data. The current version is
v4.0.1 (June 2024), and every v4.0 requirement has been
enforceable since 31 March 2025. No more future dates
to hide behind.
The cost of PCI is not really the number of controls — it is the
size of the scope. So that is where we start. Cardholder
data flows, segmentation, tokenization, iframe redirects, data
minimization. When the Cardholder Data Environment
is bounded properly, the 12 requirements land on a much smaller
estate, and the programme becomes affordable to run year on year.
We are an implementation and readiness partner, not a QSA — and we
think that distinction matters. We build, document, evidence
and accompany, but the Report on Compliance
is signed by a QSA accredited by the PCI SSC. If you have not
engaged a QSA yet, we will help you shortlist one and stand the
relationship up cleanly.
Plainly put:
Around 80% of the cost and risk of a PCI DSS programme is set in
the first few weeks, when scope is drawn. What you get wrong
there, you pay for every year after.
Scope is the lever, not the checklist
Most PCI programs are expensive because the Cardholder Data Environment was never properly bounded. We start with network flows, segmentation and tokenization so the 12 requirements land on a fraction of the estate.
Controls mapped to your stack, not a template
Every requirement in PCI DSS v4.0.1 is tied to a control owner, a technical implementation and a recurring piece of evidence on your platform — AWS, Azure, GCP, hybrid or on-prem. No PowerPoint shields, no 'see appendix' cop-outs.
Evidence the QSA can actually use
Logs, tickets, configuration baselines, change records and test results gathered as you run — not rebuilt the week before assessment. What a QSA wants to see, already in the shape they want to see it.
Customized Approach — only when it earns its keep
v4.0 opened the door to a Customized Approach. It is powerful but documentation-heavy. We use it where the default control genuinely does not fit your architecture, and we produce the Appendix E worksheets that survive a QSA review.