Skip to content

PCI DSS

Achieve and maintain PCI DSS v4.0.1 compliance, including the requirements mandatory since March 2025.

v4.0.1 Gap Assessment

Including the requirements mandatory since March 2025

Evidence Preparation

SAQ guidance or a QSA-ready package

QSA Engagement

Supported through the formal assessment

Cardholder-Data Experts

Scope and segmentation specialists

PCI DSS compliance and audit

What it is

PCI DSS is the global security standard for organisations that store, process or transmit cardholder data, maintained by the PCI Security Standards Council. The current version is PCI DSS v4.0.1, defining 12 requirements across six control objectives, where segmentation and tokenisation are the biggest levers for cutting both risk and assessment cost.

Who must comply

Any merchant, service provider or processor that handles payment card data: e-commerce, retail, SaaS billing and payment gateways, with the validation level driven by transaction volume.

How IntelligenceX helps

Scope definition and cardholder-data flow mapping
Gap assessment against v4.0.1 including future-dated requirements
SAQ guidance or a QSA-ready evidence package
Targeted Risk Analyses and e-commerce script-control evidence
Network-segmentation and tokenisation advisory to reduce assessment scope
Remediation tracking and AOC / SAQ completion support
Gap AssessmentISMS DesignInternal AuditStage 1 & 2 SupportRemediation GuidanceCertification Readiness

Frequently Asked Questions

PCI DSS v4.0.1, with all future-dated requirements mandatory since 31 March 2025. If your last assessment treated those as best practice, you are out of date and we re-baseline you.

It depends on your merchant or service-provider level. Smaller volumes complete an SAQ, which we guide; higher tiers need a QSA-signed Report on Compliance, which we support.

By keeping cardholder data out of your environment wherever possible: outsource to compliant payment providers, tokenise, and segment networks so only a small, well-defined zone is in scope. We map the data flows first, which routinely moves clients to a simpler SAQ and a fraction of the assessment effort.

Talk to a security expert today

A penetration test, an audit, or 24/7 monitoring, our team is ready across the UK, USA, EU and India.