PCI DSS v4.0.1

If you touch card data, one gap can stop you taking payments.

Failed assessments, acquirer penalties and the cost of a card data breach land on the business. We shrink your PCI scope, build the controls into your cloud and prepare the evidence your QSA will ask for.

What it's costing you

Card data mistakes are expensive and public.

REVENUE

Payments at risk

Acquirers can levy penalties or restrict processing after a failed assessment or breach.

COST

Scope creep inflates audits

Every system that can reach card data comes into scope — and into the audit bill.

DEADLINE

v4.0 requirements are live

The future-dated PCI DSS v4.0 requirements took effect in March 2025.

We make your cardholder data environment smaller, safer and provable.

How we help

From gap to evidence.

Assessment, implementation on your cloud, testing and the documentation to prove it.

01

Scope reduction

Tokenisation, segmentation and architecture changes that take systems out of scope.

02

Gap assessment

Requirement-by-requirement review against PCI DSS v4.0.1.

03

Control implementation

Encryption, access control, logging, file integrity monitoring and hardening on your cloud.

04

Testing

Internal and external vulnerability scans and penetration tests.

05

Evidence pack

Organised evidence and policies ready for your QSA or self-assessment.

What you get

Clear answers, working controls

01

Reduced scope

Fewer systems to secure and audit.

02

Remediation plan

Each gap with an owner and a fix.

03

QSA-ready evidence

Everything your assessor will request, in one place.

Get in touch

What is it costing you to wait?

Tell us what's hurting and how soon it needs fixing. A senior engineer — not a salesperson — will reply within one business day with a first view.

Free 30-min review

No spam. We reply within one business day.

✓

Thanks — we've got it.

Our team will get back to you within one business day.