Governance, Risk & Compliance

Shrink the scope first. Then pass PCI DSS.

Most of what PCI DSS costs you comes from systems that never needed to touch a card number in the first place. We cut the cardholder data environment down, prove the segmentation actually holds, and then close what genuinely remains — in that order, because it is the order that costs least.

Flat network 24 systems in scope segment Segmented 4 systems in the CDE The cheapest control is the data you never touch and the saving recurs every year, not once
v4.0.1Current standard
12Core requirements
51Future-dated items now in force
ScopeThe largest cost lever

The cheapest control is the data you never touch

If you store, process or transmit cardholder data, the card brands require PCI DSS, and your acquirer expects it to be maintained rather than achieved once. The current version is v4.0.1, released in June 2024. Version 3.2.1 was retired on 31 March 2024, and the 51 future-dated requirements introduced in v4.0 became mandatory on 31 March 2025 (as of August 2026) — which brought in tighter authentication, targeted risk analyses, and quarterly external scanning for many e-commerce merchants who had not previously needed it.

The counter-intuitive part is that the fastest route to lower PCI cost is not buying more controls. It is removing systems from scope. Every server, laptop, container and micro-service that can reach the cardholder data environment inherits the full requirement set. Competent segmentation routinely takes an assessment covering three hundred systems down to thirty, and the saving recurs every single year.

We test the segmentation rather than drawing it. If a supposedly out-of-scope host can route to the cardholder data environment, it is in scope — and it is considerably cheaper to discover that with us than with an assessor halfway through fieldwork.

Coverage

What we cover, and where the honest boundary sits

Validation route depends on your merchant level, your acquirer and how you handle card data. We establish that before quoting anything, because it changes the shape of the whole engagement.

Scope and data-flow mapping

Every system, flow, integration and third party that touches card data, mapped and then challenged. The single largest determinant of what compliance will cost you.

Segmentation and its validation

Network isolation designed and then tested. Requirement 11 expects segmentation to be verified, not asserted, and an untested boundary is not a boundary.

Validation route determination

Whether you validate through a self-assessment questionnaire — A, A-EP, B-IP, C, C-VT, P2PE or D — or a QSA-led Report on Compliance, driven by transaction volume and your acquirer’s requirements.

Technical testing

External and internal vulnerability scanning, segmentation penetration testing, and application testing mapped to Requirements 6 and 11.

Documentation and the v4.x additions

Annual scope confirmation under 12.5.2, targeted risk analyses, and the roles-and-responsibilities evidence introduced in the current version.

Where we are not the right party

SemperWise is not a QSA and not an ASV. We do the scoping, testing, remediation and readiness. Where a QSA signature or an ASV-branded quarterly scan is formally required, we work alongside a certified partner — and we tell you which you need before you spend anything.

Approach

How a PCI DSS engagement runs

Scope first, always. Assessing an environment before reducing it means paying to assess systems you were about to remove.

  1. 01 · Scope

    Map every system, flow and third party touching card data, then challenge each one. Everything that can be removed from scope is removed before anything else happens.

  2. 02 · Assess

    Gap analysis against all twelve requirements at v4.0.1, including the future-dated items that are now in force rather than upcoming.

  3. 03 · Test

    External and internal vulnerability scanning, segmentation testing and application penetration testing against the reduced environment.

  4. 04 · Remediate

    Prioritised fixes with owners and dates — not a two-hundred-row spreadsheet handed to your team with no sequencing.

  5. 05 · Validate

    Assemble the SAQ or the RoC evidence pack, retest anything that failed, and confirm the segmentation still holds after remediation.

  6. 06 · Sustain

    Quarterly scanning and annual scope confirmation, so the following year is a review rather than a repeat of the whole programme.

Run against recognised standards

  • PCI DSS v4.0.1The current standard, released June 2024
  • PCI SSC scoping guidanceSegmentation and scope determination
  • OWASP Top 10 & ASVSApplication testing under Requirement 6
  • NIST SP 800-115Testing methodology under Requirement 11
  • ISO/IEC 27001:2022Cross-mapped where an ISMS also exists

Deliverables

What you actually receive.

The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.

Cardholder data environment scope and data-flow map

What is in scope and, more valuably, what we removed from it — with the reasoning recorded for your assessor.

Requirement-by-requirement gap report

All twelve requirements at v4.0.1, with the future-dated items assessed as current obligations.

Segmentation test results

Evidence that the isolation you rely on actually holds, in the form Requirement 11 expects.

Scan and penetration test evidence

External and internal results with reproduction detail and remediation guidance, ready to hand to an assessor.

Prioritised remediation plan

Owners, dates and sequencing, ordered by what unblocks validation soonest.

SAQ or RoC evidence pack

Assembled and organised, plus the quarterly cadence that keeps it valid between assessments.

Is this for you?

Talk to us if any of these are true.

If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.

Book a scoping call
  • Your acquirer has asked for validation and you are not certain which SAQ applies to you.
  • You are still working to v3.2.1, or nobody has assessed you against the future-dated v4 requirements.
  • Your cardholder data environment has grown to include systems nobody can justify.
  • You have network segmentation on a diagram but it has never been tested.
  • You are being quoted for a full QSA-led assessment and want to know whether you actually need one.

How we work

Six steps, and no surprises.

The same engagement model applies to every piece of work we take on, so you always know what happens next.

01

Scope

A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.

02

Authorise

Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.

03

Test

Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.

04

Report

One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.

05

Remediate

A walkthrough call with your engineers. We answer questions on the fix, not just the finding.

06

Retest

A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.

Questions

PCI DSS — answered.

The questions clients actually ask during scoping. If yours is not here, ask it directly.

What is the current version of PCI DSS?

Version 4.0.1, released in June 2024 (as of August 2026). Version 3.2.1 was retired on 31 March 2024, and the 51 future-dated requirements introduced in v4.0 became mandatory on 31 March 2025 — so they are current obligations, not upcoming ones. Any assessment or guidance still written against v3.2.1 is out of date.

Do we need a QSA, or can we self-assess?

It depends on your merchant or service provider level, your transaction volume and what your acquirer requires. Many merchants validate through a self-assessment questionnaire; larger volumes typically require a QSA-led Report on Compliance. Your acquirer is the authority on this, and we confirm it with you before scoping so you are not sold an assessment you did not need.

Are SemperWise scans ASV scans?

No, and we would rather say so than blur it. We perform equivalent external and internal vulnerability scanning, and the remediation work behind it. Where an ASV-branded quarterly scan is formally required for your validation route, we coordinate with a certified ASV partner. Likewise, we are not a QSA — where a QSA signature is required, we prepare you for it and work alongside the firm you appoint.

How does segmentation actually lower cost?

Every system that can reach the cardholder data environment inherits the full requirement set. Systems properly isolated from it fall out of scope entirely. Reducing scope therefore reduces the number of assets carrying controls, the volume of evidence, and the assessment effort — every year, not once. It is the highest-return work in a PCI programme, which is why we do it first.

We use a payment provider and never see card numbers. Are we out of scope?

Usually you are in a much lighter SAQ category rather than out of scope entirely. It depends on how the payment page is delivered: a fully hosted redirect or iframe is treated very differently from a page you serve that posts card data onward, even if you never store it. Getting this determination right is worth doing carefully, because the difference in obligation is substantial.

How often do we need to test?

External and internal vulnerability scanning runs quarterly and after significant change. Penetration testing runs at least annually and after significant infrastructure or application change, and segmentation testing runs on the same cadence for merchants — more frequently for service providers. We set the calendar up front so nothing lapses quietly between assessments.

Next step

Get a written scope and a fixed price.

A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.