PCI DSS QSA Assessments & Compliance Services

PCI DSS is the global standard for protecting cardholder data. Every organisation that stores, processes, or transmits payment card information must comply, from corner-shop merchants to global payment service providers. Non-compliance is not optional: fines, increased transaction costs, and acquiring bank action follow quickly after a missed assessment.

As a PCI SSC Qualified Security Assessor (QSA) Company, RedSecLabs delivers PCI DSS v4.0.1 services across the full programme lifecycle: scope definition, gap analysis, remediation support, Report on Compliance (ROC) assessment, Self-Assessment Questionnaire (SAQ) validation, and ongoing compliance management.

Our in-house QSAs and PCI specialists bring deep experience across merchant, service provider, payment gateway, and processor environments, from level-4 SAQ-A merchants to level-1 service providers.

CREST Member Company CREST Penetration Testing Provider PCI SSC Qualified Security Assessor (QSA) Company ISO 27001 Certified UKAS Accredited Certification AICPA SOC 2

Get Your Fixed-Fee Quote

Tell us what needs testing. You’ll get a scoped, fixed-fee quote back the same business day, from a senior assessor, not a sales rep. No obligation, no spam.

✓ Same-day response✓ Fixed-fee, no surprises✓ Senior testers only✓ Retest included

We reply within one business day with next steps. Your details are used only to scope your enquiry, never shared or sold.

✓ PCI SSC QSA Company · ✓ CREST accredited · ✓ UKAS-certified ISO 27001 & 9001 · ✓ IASME Certification Body · ✓ Same-day scoping response
Who this is for

This service is a fit if you’re..

1
Merchants storing card data
E-commerce platforms, retailers, and merchants processing payments who need to demonstrate PCI DSS compliance.
2
Service providers
SaaS or infrastructure providers whose customers ask for PCI DSS attestation as part of procurement.
3
Pre-QSA preparation
Organisations preparing for a formal PCI DSS assessment who need gap analysis and readiness support first.

PCI DSS Compliance, Quick Facts

Last reviewed: 2026-05-21
Current standard
PCI DSS v4.0.1, the version in force for all current assessments (all future-dated v4.x requirements became mandatory on 31 March 2025)
Compliance paths
SAQ (Self-Assessment Questionnaire) or ROC (Report on Compliance) depending on merchant level
Merchant levels
Level 1: 6M+ transactions/year (ROC required). Levels 2-4: typically SAQ
Validation cadence
Annual for ROC; annual SAQ self-attestation for lower levels
Required testing
Quarterly ASV scans (Req 11.3.2), annual penetration testing (Req 11.4)
Coverage
UK, USA, Saudi Arabia, UAE, PCI SSC QSA Company, consistent methodology across jurisdictions
v4.0.1
Current standard
QSA
Qualified Security Assessors
Levels 1-4
All merchant and SP tiers
Lifecycle
Gap-to-annual-renewal

What is PCI DSS?

The Payment Card Industry Data Security Standard (PCI DSS) is the global security standard maintained by the PCI Security Standards Council. It applies to every organisation that stores, processes, or transmits cardholder data, whether merchant, service provider, payment gateway, or processor.

PCI DSS v4.0.1, published in June 2024, is the current version; v4.0 was retired on 31 December 2024 and v3.2.1 on 31 March 2024. The v4.x series introduced the customised approach to control implementation, requirements around authenticated scanning and targeted risk analyses, and tighter expectations on scoping accuracy. Since 31 March 2025, every formerly future-dated requirement is fully mandatory, so there is no longer a transition runway: assessments now test the complete v4.0.1 control set.

What PCI DSS compliance delivers:

Eligibility to accept card payments under acquiring bank agreements

Reduced exposure to fines following any card data breach

Lower transaction fees with major card schemes

Cyber insurance coverage eligibility

Customer and partner trust around payment data handling

Evidence reusable for SOC 2, ISO 27001, and broader compliance programmes

Compliance is annual, and the bar continues to rise. v4.0.1 makes scoping accuracy and continuous control operation far more material than under previous versions.

Why PCI DSS matters

Card data breaches remain among the most damaging and costly cyber incidents an organisation can experience. Beyond direct fraud costs, breached merchants face card scheme fines, mandatory forensic investigation by PFI-approved investigators, increased transaction processing fees, and lasting customer trust damage.

PCI DSS is not optional, it is a contractual requirement under every major acquiring bank agreement. Non-compliance can result in fines starting from £5,000 per month, escalating significantly after a breach, and ultimately to suspension of card-acceptance privileges.

Common consequences of weak PCI DSS programmes:

Card scheme fines from £5,000 to £100,000+ per month

Mandatory PFI investigation after any suspected breach

Increased transaction processing fees

Acquiring bank termination of merchant agreements

Direct breach costs averaging £3.4M in the UK in 2025

Brand and customer trust damage following public incidents

Strong PCI DSS programmes reduce breach probability, limit financial exposure when incidents occur, and become a strategic asset rather than an annual overhead.

Who needs PCI DSS compliance?

PCI DSS applies to every organisation that interacts with cardholder data. RedSecLabs delivers across all merchant and service provider tiers:

E-commerce merchants (all levels)

Retail and in-person POS merchants

Payment service providers and gateways

Card processors and acquirers

Cloud hosting providers handling cardholder data

Contact centres processing phone payments

Software providers in PCI scope (payment apps)

Logistics and fulfilment where card data flows

Our PCI DSS Methodology

An eight-stage methodology covering the full PCI DSS compliance lifecycle, from initial scoping through annual renewal.

01

Scope Definition

We map cardholder data environments (CDE) and confirm which systems are in scope, in connected scope, or out of scope through network segmentation.

02

Merchant Level Determination

We confirm your merchant or service provider level and identify the correct assessment route. SAQ type or full Report on Compliance (ROC).

03

Gap Analysis

Comprehensive review against all 12 PCI DSS requirements with control-by-control evidence sampling and remediation prioritisation.

04

Remediation Support

Hands-on guidance on common weak areas: network segmentation, encryption key management, authenticated scanning, audit logging, secure development.

05

Quarterly ASV Scanning

External vulnerability scanning by approved scanning vendor (ASV) on a quarterly basis, with remediation support between scans.

06

Annual Penetration Testing

Network and application penetration testing meeting PCI DSS requirements 11.4.1-11.4.5, including segmentation validation.

07

Compliance Validation

QSA-led ROC or SAQ validation depending on your assessment route, producing the documentation acquirers require.

08

Annual Renewal & Continuous Compliance

Year-round programme management to keep controls operational, not just compliant at audit point.

Most clients reach first-time compliance in 3-9 months depending on starting maturity and CDE complexity, with annual renewal cycles thereafter.

What you receive

Every PCI DSS engagement with RedSecLabs includes:

  • Scope analysis and cardholder data environment documentation
  • Merchant level determination and assessment route confirmation
  • Gap analysis report against all 12 PCI DSS v4.0.1 requirements
  • Prioritised remediation roadmap with effort estimates
  • Quarterly ASV scan reports and remediation guidance
  • Annual penetration test report meeting requirements 11.4.1-11.4.5
  • QSA-validated ROC or signed SAQ with attestation of compliance
  • Ongoing compliance management and acquirer reporting support

Industries We Serve

We deliver this service across these industries:

E-commerce
Retail & POS
Payment Providers
Acquirers & Processors
Cloud Hosting
Contact Centres
Travel & Hospitality
Petroleum & Fuel

Why RedSecLabs for PCI DSS

QSA-led assessments across all merchant levels
Scoping and segmentation expertise (v4.0.1)
ASV-grade quarterly vulnerability scanning
PCI DSS penetration testing to 11.4 standards
Annual renewal and continuous compliance support
Acquirer reporting and dispute support

Get PCI DSS v4.0.1 Compliant

Book a free 30-minute scoping call. Merchant level confirmation, SAQ recommendation, and fixed-fee quote within a week.

Three engagement routes

Most PCI providers quote after discovery calls and bill scope creep as it appears. We do it the other way round: route first, fixed fee second, no surprise invoices.

SAQ, verified
For merchants and providers who self-assess. We confirm the right SAQ type from your real payment flows, evidence every answer, and countersign the AOC.
  • ✓SAQ type confirmed with written rationale
  • ✓QSA verification and countersigned AOC
  • ✓1–3 weeks depending on SAQ type
  • ✓If your flows support a simpler SAQ, we quote down, not up
Confirm my SAQ route
MOST CHOSEN
Readiness → ROC
For first ROCs and step-ups from SAQ. Gap assessment first while fixing is cheap, then the formal QSA assessment on the same evidence base.
  • ✓Scope validation and gap register first
  • ✓Remediation sequenced to your assessment date
  • ✓QSA-signed ROC and AOC
  • ✓Re-verification of fixed items included
Plan readiness to ROC
Level 1 programme
For Level 1 merchants and service providers on an annual cycle: assessment, evidence upkeep and the relationship your acquirer expects, year over year.
  • ✓Annual ROC with a consistent assessor team
  • ✓Evidence index maintained between cycles
  • ✓Interim change reviews after platform moves
  • ✓Post-breach revalidation support if the worst happens
Build the annual programme
The no-surprise-invoices policy
INCLUDED IN THE FIXED FEE
Scoping and dataflow confirmation • evidence index per requirement • assessor-led interviews • remediation debrief • re-verification of fixed items • countersigned AOC • same-day flagging of critical findings
PRICED SEPARATELY, NAMED UP FRONT
Quarterly ASV scans (delivered with our SSC-approved partner) • Requirement 11 penetration testing days • new scope added mid-engagement, quoted before work, never billed after
What happens after you get in touch
1
Same-day scoping call
Merchant level, channels and dataflows in 20 minutes. Route recommendation and fixed quote follow the same business day.
2
Assessment plan agreed
Dates, evidence list and interview schedule locked before anything starts. Your team knows exactly what’s coming.
3
Assessed and signed
ROC or verified SAQ delivered, AOC countersigned, re-verification letter after fixes. Your acquirer gets what they asked for, first time.

Frequently Asked Questions

Levels are set by your annual card transaction volume across all card schemes. Level 1 (over 6M transactions/year) requires QSA-led ROC; Level 2 (1-6M) requires QSA or internal security assessor ROC or SAQ-D; Levels 3 and 4 typically use SAQs. We confirm your level and the right SAQ type at the start of every engagement.

The v4.x series (mandatory since 31 March 2024, with v4.0.1 the current release) introduced the customised approach to control implementation, authenticated vulnerability scanning, targeted risk analyses for several controls, and tighter scoping accuracy requirements. The transitional grace period ended on 31 March 2025, so every previously future-dated control is now assessed in full, and we help you evidence each one, including the newer requirements around e-commerce script management (6.4.3) and anti-phishing controls.

Yes, every organisation with externally-accessible systems in PCI scope must run quarterly ASV scans by an approved scanning vendor. We provide ASV-aligned scanning as part of our compliance programme, with rescans included after remediation.

PCI DSS Requirements 11.4.1-11.4.5 mandate annual network and application penetration testing, plus segmentation validation testing. Our PCI penetration tests meet all five sub-requirements and produce the formal report acquirers require.

For SAQ-eligible merchants, total consultancy typically £8,000-£35,000 annually. For ROC assessments (Level 1 merchants and service providers), £35,000-£150,000+ depending on CDE complexity, sites, and starting maturity. We provide fixed-fee quotes after scoping.

Major card schemes typically mandate engagement of a PCI Forensic Investigator (PFI) within hours of suspected breach. Card scheme fines apply, your acquiring bank may impose increased scrutiny or terminate your agreement, and remediation costs are largely uninsured under standard policies. Strong PCI programmes materially reduce both probability and severity.
What you receive

Every engagement includes

  • ✓ Scoping call. A 30-minute call to define scope, timeline, and authorisation boundaries.
  • ✓ Assessment plan. Written plan covering scope, evidence requirements, and assessment schedule.
  • ✓ Findings report. Control-by-control findings with evidence references and remediation guidance.
  • ✓ Executive summary. Board-ready 1-2 page summary with risk ratings and business impact.
  • ✓ Audit-ready evidence. Findings letter formatted for auditors, customers, and supervisory authorities.
  • ✓ Re-verification letter. Remediated gaps re-verified within an agreed window. Confirmation letter included.
  • ✓ Remediation call. A call with our lead assessor to walk through findings and remediation strategy.
How we deliver

Our process, end to end

  1. 1
    Scoping call & fixed-scope quote
    A 30-minute call. We define scope, targets, timeline. You get a fixed-scope quote within one working day. No surprise invoices.
  2. 2
    Assessment plan & authorisation
    Written assessment plan covering scope, evidence requirements and schedule. Authorisation and NDA in place before any work begins.
  3. 3
    Assessor-led execution
    A senior assessor runs the engagement. Material gaps flagged as they are found, not saved for the report. Daily updates if you want them.
  4. 4
    Technical + executive report
    Detailed technical findings with reproduction steps. Board-ready executive summary. Delivered within agreed working days.
  5. 5
    Remediation call & re-verification
    Walkthrough with our lead assessor. Re-verification of remediated gaps within the agreed window. Confirmation letter for your auditors.
Engagement scope

What shapes the quote

Small scope
Single environment, one framework, limited system count. 5-7 working days.
Medium scope
Multiple systems or sites, several control owners, integrations. 8-12 working days.
Enterprise scope
Complex estate, multiple entities or locations, full audit-grade evidence. 12-25 working days.
Fixed-scope quote within 1 working day
No surprise invoices, no scope-creep. We commit to a number before you commit to us.
Sample report
See exactly what we deliver
Download a redacted RedSecLabs report. Same structure, depth and clarity as the deliverables your team will receive.
Download sample report
Why RedSecLabs

Grounded reasons clients choose us

⚑
UK-based team
Testers based in the UK. Data stays within UK/EU jurisdiction for sensitive engagements.
❄
CREST member company
CREST-accredited methodology. Senior testers hold CREST CRT or CCT certifications.
⚙
Practitioners, not checklists
Assessments run by practitioners who also test systems hands-on, findings reflect how controls actually operate.
✎
Clear executive reporting
Reports your board can read and your developers can act on. No jargon padding.
♚
Compliance-aware delivery
PCI, SOC 2, ISO 27001, DORA, GDPR. We map findings to your compliance framework.
↺
Retest support included
Free retest of remediated findings within agreed window. Confirmation letter for auditors.
Related services

Often paired with this engagement

PCI DSS SAQ Assessment →
QSA-verified SAQ and countersigned AOC.
PCI DSS Singapore →
QSA assessments for Singapore and APAC.
PCI DSS Penetration Testing →
Requirement 11.4 testing by CREST testers.
PCI DSS Level 1 →
Level 1 merchant and service provider assessments.
ROC Assessment →
QSA Report on Compliance, end to end.
Service Providers →
SaaS, fintech, PSP and gateway validation.
Readiness & Gap →
Gap register and evidence index pre-assessment.
Scoping & Segmentation →
CDE definition and scope reduction.
PCI DSS QSA (UK) →
Formal QSA assessment in the UK.
PCI DSS QSA (US) →
Formal QSA assessment in the US.
PCI ASV Scanning →
External quarterly scans (via ASV partner).
Network Pentesting →
Required under Requirement 11.
Web App Pentesting →
For payment applications.
📞 Call us Book a call