Assessment & advisory
PCI DSS v4.0.1 Readiness & Assessment Support
PCI DSS readiness for merchants and service providers: scope cardholder data, assess v4.0.1 safeguards, organize recurring evidence, and coordinate validation.
Discuss your PCI DSS requirementsWhat we assess
We trace payment data flows, define the cardholder data environment, and review segmentation and third-party responsibilities. Scope affects both implementation work and the applicable validation approach. The readiness assessment connects technical safeguards, documented procedures, and recurring activities instead of relying only on a one-time configuration screenshot.
Evidence to prepare
- Payment data-flow and network diagrams, inventories, and responsibility matrices.
- Security configurations, access controls, vulnerability scans, and penetration-test records.
- Policies, targeted risk analyses where applicable, monitoring records, and recurring control evidence.
Keep design evidence separate from operating evidence. An approved procedure shows how a control is designed; dated records show whether it ran consistently over the review period. Evidence should identify its source, owner, scope, and collection date.
What you receive
- Scope recommendations and readiness gaps against applicable PCI DSS requirements.
- Remediation priorities and an evidence collection schedule.
- Support preparing for the required SAQ or independent assessment pathway.
The assessment outcome
A better-defined payment environment and organized validation evidence. A readiness review is not a QSA-issued assessment, and validation requirements must be confirmed with the responsible payment stakeholders.
Common questions
Does outsourcing payments remove every PCI obligation?
Outsourcing can reduce the data environment and applicable requirements, but merchant and service-provider responsibilities remain. Review the actual payment integration and provider responsibilities before deciding scope.
What determines the engagement timeline and cost?
The system boundary, number of entities and locations, existing control maturity, evidence availability, and assessment pathway determine the effort. Share your customer requirements and target milestone so we can define a realistic scope before proposing a schedule.
Framework reference: PCI Security Standards Council — document library. Guidance reviewed October 4, 2026; confirm current requirements when scoping an engagement.
