PCI DSS Assessment
Scope, assess, and remediate against PCI DSS requirements for cardholder data environments.
PCI DSS v4.0.1 compliance requires precise scoping, control implementation, and evidence collection. All future-dated v4.0 requirements became mandatory from March 31, 2025. Mitigence brings both technical and QSA-adjacent expertise to PCI DSS programmes — helping organisations scope correctly, remediate efficiently, and maintain compliance across annual assessment cycles.
Engagement Phases
CDE Scoping
3–5 daysDefine the cardholder data environment boundary, identify all in-scope systems and data flows, and explore scope reduction opportunities.
Gap Assessment
1–2 weeksAssess current controls against all applicable PCI DSS requirements for your merchant/service provider level.
Control Testing
1–2 weeksTechnical testing of controls: network segmentation validation, penetration testing, ASV scanning, and log review.
Remediation Support
1–2 weeksWork alongside your team to close identified gaps and document remediation evidence.
Evidence Pack & SAQ/ROC Preparation
4–6 daysCompile and quality-check the evidence pack for SAQ self-assessment or QSA audit submission.
What You Receive
- CDE scope definition and data flow diagrams
- PCI DSS gap assessment report
- Penetration test and ASV scan results
- Remediation evidence documentation
- SAQ or ROC supporting evidence pack
- Ongoing compliance monitoring recommendations
Ready to scope this engagement?
Tell us about your environment and objectives — we'll map the approach to your context.