We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

PCI DSS · QSA-led assessment

PCI DSS assessment and validation

QSA-led PCI DSS v4.0 assessment and validation that protects cardholder data, reduces fraud exposure and holds regulatory confidence — for fintechs, merchants, payment aggregators and technology service providers.

CyberSigma is a PCI SSC Qualified Security Assessor, listed on the official PCI SSC QSA directory as Cybersigma Consulting Services LLP, and a CERT-In empanelled auditor. We assess and validate compliance; the validation is evidenced in the Report on Compliance and Attestation of Compliance.

Get a free readiness snapshot →Talk to an expert

Not sure how close you are to a clean ROC?

Get a free PCI DSS v4.0.1 readiness snapshot from a listed QSA — share your work email and we map your gaps and scope before the assessment.

Why PCI DSS matters

The Payment Card Industry Data Security Standard sets the controls that protect cardholder data wherever it is stored, processed or transmitted. Meeting it lowers the risk of a breach, reduces fraud exposure, and is a condition of doing business with banks, acquirers and payment partners.

Validated compliance does more than satisfy a requirement. It secures your payment environment, smooths onboarding with processors and enterprise customers, and gives your board and regulators evidence that cardholder data is genuinely protected.

Who needs PCI DSS

PCI DSS applies to any organisation that stores, processes or transmits cardholder data, or can affect its security:

  • Fintech companies, NBFCs and payment aggregators handling card transactions.
  • Merchants and e-commerce businesses taking card payments.
  • Payment processors, gateways and card networks.
  • Technology and cloud service providers that handle or influence cardholder data.

CyberSigma’s role

We are your Qualified Security Assessor. We run the gap analysis and readiness assessment, support remediation, then conduct the formal assessment and validate your controls against PCI DSS v4.0 — a single team from readiness through to a validated compliance position.

What QSA validation means

A QSA-led assessment produces a Report on Compliance and an Attestation of Compliance — the evidence acquirers and payment brands rely on. CyberSigma does not issue certificates; we assess and validate compliance against the standard set by the PCI Security Standards Council.

How we deliver

Gap analysis

We map your current security posture against every PCI DSS requirement across the cardholder data environment, and give you a prioritised gap list — what is in place, what is missing, and what has to change before a QSA-led assessment.

Readiness assessment

We assess how ready you are for formal assessment and validation, confirm the scope of your cardholder data environment, and set out clear findings and prioritised recommendations so remediation effort goes where it matters.

Implementation support

We give hands-on guidance through remediation and control implementation — network and configuration hardening, cardholder data protection, access governance, logging and monitoring — so the environment genuinely meets the standard, not just on paper.

QSA-led assessment and validation

Our Qualified Security Assessors conduct the formal assessment against PCI DSS v4.0, validate the controls with evidence, and produce the Report on Compliance and Attestation of Compliance — or confirm the correct self-assessment questionnaire for your environment.

What you receive

  • PCI DSS gap analysis mapping your posture to each requirement
  • Readiness assessment with prioritised findings and scope confirmation
  • Report on Compliance (ROC) and Attestation of Compliance (AOC) for QSA-led assessments
  • Guidance on the correct self-assessment questionnaire (SAQ) where applicable
  • Remediation plan to close gaps and strengthen cardholder data controls
  • Evidence pack supporting the validated compliance position

Indicative timeline

A typical engagement runs about two to four months from gap analysis to a validated assessment, depending on the size of the cardholder data environment, the number of systems in scope, and how mature your current controls are.

Timelines vary with scope and readiness; we confirm a schedule after the gap analysis.

What the standard requires

PCI DSS spans the technical and organisational controls that protect cardholder data, including:

Network and system security

Firewalls, segmentation and secure configurations that block unauthorised access to the cardholder data environment.

Cardholder data protection

Storage, retention, masking and deletion controls, with strong encryption of data in transit across systems and third parties.

Vulnerability and patch management

Scanning, patching and remediation cycles that reduce exploitable weaknesses across in-scope systems.

Identity and access governance

Least privilege, access approvals, role management and multi-factor authentication on privileged and remote access.

Logging and security monitoring

Event records, audit trails and alerts that support threat detection, investigation and continuous validation.

Secure software and change control

Secure coding, testing and change controls that prevent application breaches in payment systems.

PCI DSS compliance levels

PCI DSS defines four levels by annual card transaction volume. Your level sets how rigorous the assessment is and how you validate.

Level 1

Organisations processing over six million card transactions a year — an on-site QSA-led assessment with continuous monitoring.

Level 2

Entities processing one to six million transactions a year, with validation requirements that vary by acquirer or processor.

Level 3

Businesses processing 20,000 to one million e-commerce transactions a year, typically validating through SAQs and network scans.

Level 4

Smaller merchants with fewer than 20,000 e-commerce transactions, or up to one million total transactions, a year.

Representative engagement

A payment aggregator needed validated PCI DSS compliance to satisfy its sponsor bank and enterprise customers. We ran the gap analysis across its cardholder data environment, confirmed scope, supported remediation of access, encryption and monitoring gaps, then conducted the QSA-led assessment and produced the Report on Compliance and Attestation of Compliance. Named client references are available under NDA on request.

Who leads your engagement

Your engagement is led by a Qualified Security Assessor with deep experience across payment environments — supported by application, infrastructure and network specialists. Every finding passes independent quality review before the report reaches you. We introduce your named lead on the first call.

PCI DSS v4.0.1 — what is mandatory now

PCI DSS v4.0 has been retired; v4.0.1 is the only active version. Of the 64 new requirements introduced in v4.x, 13 applied immediately and 51 were future-dated — those became effective on 31 March 2025 and are now assessed like any other requirement. There is no remaining transition phase.

In assessments we see the same handful fail repeatedly:

6.4.3 — payment page scripts

A managed inventory of every script on the payment page, each authorised and integrity-assured. Usually answered with a spreadsheet that is stale the week after it is written.

11.6.1 — change detection

Alerting on unauthorised change to payment page content and HTTP headers. A weekly scan does not catch a script swapped in on Tuesday and removed on Thursday.

8.4.2 — MFA scope

MFA for all non-console access into the CDE, any role, any location. The gap is internal, non-admin access from inside the office.

11.3.1.2 — authenticated scanning

Internal vulnerability scans must be credentialed. Expect the finding count to jump on the first honest run.

12.3.1 — targeted risk analysis

A TRA has to be an argument, not a restatement of the interval you already run. Identical wording across several controls is obvious to an assessor.

SAQ A eligibility

For e-commerce merchants, 6.4.3 and 11.6.1 left SAQ A but returned as a condition of using it: you must confirm your site is not susceptible to script attacks.

We have written these up in detail, including the SAQ A eligibility trap and what a QSA asks for as evidence: PCI DSS v4.0.1 — what is actually failing in assessments.

Which SAQ applies to you

Most merchants validate through a Self-Assessment Questionnaire rather than a full Report on Compliance. Picking the wrong one is common, and it is expensive — an ineligible SAQ means the validation does not stand. The right questionnaire follows from how card data reaches you.

SAQ A

Card-not-present, payment fully outsourced to a compliant third party. Note the revised eligibility criteria: embedded (iframe) payment pages now carry a script-protection condition; full redirects do not.

SAQ A-EP

E-commerce where your site affects the payment transaction but does not receive card data directly. Substantially more requirements than SAQ A.

SAQ B / B-IP

Imprint machines or standalone terminals, with no electronic cardholder data storage. B-IP covers IP-connected terminals.

SAQ C / C-VT

Payment application systems connected to the internet, or web-based virtual terminals.

SAQ D

Merchants and service providers not covered by another SAQ. The full requirement set.

Report on Compliance

Required for Level 1 merchants and most service providers — a QSA-led assessment producing a signed RoC and Attestation of Compliance.

If you are unsure which applies, we will tell you on the first call — and we will tell you if the answer is a smaller scope than you expected.

What drives the cost of PCI DSS compliance

Assessment fees are rarely the largest line. Scope is. Two organisations of the same size can differ several-fold in total cost depending on how much of their estate touches cardholder data, so the first lever is almost always scope reduction rather than negotiation.

Scope size

Every system that stores, processes or transmits card data — plus anything connected to it — is in scope. Segmentation and tokenisation are the biggest cost levers available to you.

Validation route

A self-assessment questionnaire costs a fraction of a QSA-led Report on Compliance. Your merchant level and acquirer set which applies.

Remediation gap

The distance between current state and requirement. A gap assessment first means you spend on fixes rather than on discovering them during the assessment.

Testing obligations

Requirement 11 mandates internal and external penetration testing, and segmentation testing where you rely on segmentation to reduce scope.

Evidence maturity

Organisations with continuous evidence collection spend far less assessment time than those assembling artefacts in the final weeks.

Annual cycle

PCI DSS is annual, with quarterly scanning where applicable. Budget for the cycle, not a one-off project.

We scope before we quote. If tokenisation or segmentation would materially reduce what has to be assessed, we will say so — even when it reduces the engagement.

Related services

PCI DSS certification in MumbaiPCI DSS certification in HyderabadPCI PIN security assessmentSWIFT CSP assessmentRBI PSS payment system auditISO 27001 — ISMS implementation & readiness
Free resource

The evidence a QSA will ask you for, requirement by requirement

All 12 requirements mapped to the specific artefact, screenshot or export that satisfies each one \u2014 plus what invalidates a screenshot, so evidence is accepted first time.

Excel \u00b7 60+ evidence items \u00b7 v4.0.1
Email me the checklist

Frequently asked questions

What is PCI DSS compliance?

PCI DSS compliance means meeting the Payment Card Industry Data Security Standard — a framework of controls for organisations that store, process or transmit payment card data. It reduces fraud risk, helps prevent data breaches and is contractually required by the card schemes and acquiring banks.

Who must comply with PCI DSS?

Any organisation that stores, processes or transmits payment card information must comply — merchants, fintechs, payment processors, banks, NBFCs, SaaS platforms and service providers. In India, RBI-regulated entities handling card data must also maintain PCI DSS compliance.

What are PCI DSS compliance services?

PCI DSS compliance services cover scoping and readiness, gap assessment, remediation support, documentation, QSA-led assessment, and ongoing compliance monitoring. CyberSigma delivers PCI DSS assessment and validation as a PCI SSC-qualified and listed QSA Company and CERT-In empanelled firm.

How long does PCI DSS assessment and validation take?

PCI DSS assessment and validation typically takes 60 to 180 days, depending on your current security posture, remediation scope, infrastructure complexity and merchant or service provider level. A structured readiness programme shortens the timeline by fixing gaps before the QSA-led assessment begins.

What is the cost of PCI DSS compliance services in India?

Cost depends on your organisation's size, merchant level, the scope of your cardholder data environment and the remediation workload. CyberSigma scopes PCI DSS packages for Indian fintechs, merchants and payment processors. Contact us for a scoped estimate.

What is PCI DSS v4.0?

PCI DSS v4.0 is the current version of the standard and applies to all assessments. Compared with v3.2.1, it adds stronger authentication controls, continuous monitoring requirements, risk-based validation, a customisable approach and tighter governance.

Do Indian companies need PCI DSS compliance?

Yes. Indian fintechs, payment aggregators, NBFCs, banks and merchants handling card data must maintain PCI DSS compliance, as required by the card schemes (Visa, Mastercard, RuPay) and acquiring banks. The RBI's cybersecurity guidelines also align with PCI DSS controls for regulated entities.

What is a Qualified Security Assessor (QSA)?

A QSA Company is an independent security organisation qualified by the PCI Security Standards Council to assess and validate an entity's adherence to PCI DSS. QSAs conduct the assessment, review evidence and issue the Report on Compliance (RoC) or Attestation of Compliance (AoC) required by banks and card schemes. CyberSigma Consulting Services LLP is listed on the official PCI SSC QSA directory, authorised for CEMEA, Asia Pacific and the USA.

Can PCI DSS compliance be maintained continuously?

Yes. PCI DSS v4.0 emphasises continuous compliance rather than a point-in-time check. CyberSigma provides managed compliance services — periodic reviews, vulnerability assessments, change-impact assessments and ongoing monitoring — to sustain compliance year-round.

Ready to discuss your PCI DSS requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.