Book a Security Assessment enquiry@cybersecuritylondon.com · London Bridge
Service 12 / 12

PCI DSS
compliance.

If you take card payments, PCI DSS applies to you. We help you understand your scope, reduce it where possible and meet the requirements without unnecessary cost.

  • Scope reduction
  • SAQ support
  • PCI scanning
  • Remediation

Last reviewed

Rack of network equipment in a server room
01 — Overview

What it is,
and why it matters.

PCI DSS is the security standard set by the card brands. Your bank or payment provider will expect you to show compliance, usually through a self-assessment questionnaire (SAQ).

The quickest win is often reducing scope, so fewer systems touch card data. We help you choose the right SAQ, close the gaps and keep the evidence your acquirer asks for.

A good fit if…

  • Your payment provider has asked for PCI compliance
  • You are unsure which SAQ applies to you
  • You are being charged non-compliance fees
  • You are changing how you take payments
02 — What's included

Everything you need,
nothing you don't.

01

Scope review

Where card data flows and which systems are in scope.

02

Scope reduction

Advice on payment setups that reduce your PCI burden.

03

SAQ support

Choosing and completing the right self-assessment questionnaire.

04

PCI scanning

External vulnerability scanning where your SAQ requires it.

05

Remediation

Practical help closing the gaps.

06

Evidence pack

Documentation ready for your acquirer.

03 — How it works

Four clear
steps.

  1. Step 1

    Scope

    Map card data flows and systems.

  2. Step 2

    Reduce

    Simplify scope where possible.

  3. Step 3

    Remediate

    Close the gaps against the requirements.

  4. Step 4

    Validate

    Complete the SAQ and supporting evidence.

04 — Options

Support options

A

PCI readiness review

A clear view of your scope and gaps.

B

SAQ completion support

Guidance through the right questionnaire for your setup.

C

PCI DSS scanning

Quarterly external scans where required.

D

PCI DSS v4.0 transition

Help adapting to the latest version of the standard.

05 — Cost

What affects
the cost.

1

Payment setup

How you take payments affects scope and effort.

2

SAQ type

Some questionnaires are short; others cover hundreds of requirements.

3

Scanning

Whether quarterly external scans are needed.

4

Remediation

How much needs fixing to meet the standard.

We quote a fixed price after reviewing how you take payments.

Get a quote
06 — FAQs

Questions,
answered.

If you accept, process, store or transmit card payments, yes. The amount of work depends on how you take payments.

It depends on your payment setup, for example whether you use a hosted payment page, card terminals or process cards on your own systems. We help you confirm the right one.

Quarterly external vulnerability scans required for some merchants, carried out by an approved scanning vendor. We arrange and manage these where needed.

Often, yes. Using hosted payment pages or point-to-point encrypted terminals can take many of your systems out of scope.

Next step

Let's talk about
PCI DSS.

A short call, no obligation. We'll listen, ask a few questions and suggest a sensible first step.

Contact

Start with
an assessment.

Tell us a little about your business. We'll arrange a short, no-obligation conversation and suggest a sensible first step.

Studio

The Leather Market
London Bridge

Dealing with a live incident? Put “urgent” in your message or email enquiry@cybersecuritylondon.com. We use your details only to reply, see our privacy notice.