Eye On Bits
Compliance · PCI DSS

PCI DSS Compliance for Payment Data

If you store, process or transmit cardholder data, PCI DSS isn't optional. We help you scope, implement and validate it.

What is PCI DSS?

The Payment Card Industry Data Security Standard (PCI DSS) is a set of technical and operational requirements for any organisation that stores, processes or transmits cardholder data - set by the major card brands, not a government body.

It covers network segmentation, encryption, access control, vulnerability management, logging and regular testing, including the penetration testing many merchants and service providers must undergo annually.

What's included

CDE Scoping & Segmentation

Cardholder Data Environment (CDE) scoping and network segmentation review.

Gap Assessment

Gap assessment against the current PCI DSS version.

SAQ / RoC Preparation

Self-Assessment Questionnaire (SAQ) support or Report on Compliance (RoC) preparation.

Pentesting & Vulnerability Scans

Required annual penetration testing and quarterly vulnerability scans.

Compensating Controls

Compensating control documentation where applicable.

Ongoing Compliance Maintenance

Ongoing compliance maintenance between assessments.

Our approach - Plan, Do, Check, Act

The same continuous-improvement cycle behind every compliance programme we run.

Plan

Identify objectives, secure management support, define the scope and method of risk assessment, and inventory the assets that need protecting.

Do

Manage risk with a treatment plan, implement the required controls and policies, and train staff to follow them.

Check

Monitor how the management system is actually running, and prepare the organisation for its certification or attestation audit.

Act

Run the audit, then keep improving through continual, corrective and preventive action.

Other compliance frameworks

SOC 2

Independent attestation of security, availability and confidentiality controls.

Learn more →

HIPAA

US standard for protecting patient health information.

Learn more →

GDPR

EU regulation governing the processing of personal data.

Learn more →

VAPT

Vulnerability assessment and penetration testing across web, mobile, API, cloud and network.

Learn more →

Questions we get asked first

Do we need a Qualified Security Assessor (QSA)?

Larger merchants and service providers typically need a QSA-led Report on Compliance; smaller merchants may qualify for a Self-Assessment Questionnaire. We help determine which applies and prepare the evidence either way.

Does PCI DSS require penetration testing?

Yes - annual penetration testing and quarterly vulnerability scans by an Approved Scanning Vendor are required for most merchant levels. Our VAPT service is scoped to meet this requirement.

What's the fastest way to reduce our PCI scope?

Reducing what touches cardholder data directly - for example, tokenising payments or outsourcing card capture to a validated third party - is usually the fastest way to shrink your compliance burden.

Ready to get audit-ready for PCI DSS?

Tell us where you're starting from and we'll come back with a scoped proposal within two working days.