Scope and data-flow mapping
Every system, flow, integration and third party that touches card data, mapped and then challenged. The single largest determinant of what compliance will cost you.
Governance, Risk & Compliance
Most of what PCI DSS costs you comes from systems that never needed to touch a card number in the first place. We cut the cardholder data environment down, prove the segmentation actually holds, and then close what genuinely remains — in that order, because it is the order that costs least.
If you store, process or transmit cardholder data, the card brands require PCI DSS, and your acquirer expects it to be maintained rather than achieved once. The current version is v4.0.1, released in June 2024. Version 3.2.1 was retired on 31 March 2024, and the 51 future-dated requirements introduced in v4.0 became mandatory on 31 March 2025 (as of August 2026) — which brought in tighter authentication, targeted risk analyses, and quarterly external scanning for many e-commerce merchants who had not previously needed it.
The counter-intuitive part is that the fastest route to lower PCI cost is not buying more controls. It is removing systems from scope. Every server, laptop, container and micro-service that can reach the cardholder data environment inherits the full requirement set. Competent segmentation routinely takes an assessment covering three hundred systems down to thirty, and the saving recurs every single year.
We test the segmentation rather than drawing it. If a supposedly out-of-scope host can route to the cardholder data environment, it is in scope — and it is considerably cheaper to discover that with us than with an assessor halfway through fieldwork.
Coverage
Validation route depends on your merchant level, your acquirer and how you handle card data. We establish that before quoting anything, because it changes the shape of the whole engagement.
Every system, flow, integration and third party that touches card data, mapped and then challenged. The single largest determinant of what compliance will cost you.
Network isolation designed and then tested. Requirement 11 expects segmentation to be verified, not asserted, and an untested boundary is not a boundary.
Whether you validate through a self-assessment questionnaire — A, A-EP, B-IP, C, C-VT, P2PE or D — or a QSA-led Report on Compliance, driven by transaction volume and your acquirer’s requirements.
External and internal vulnerability scanning, segmentation penetration testing, and application testing mapped to Requirements 6 and 11.
Annual scope confirmation under 12.5.2, targeted risk analyses, and the roles-and-responsibilities evidence introduced in the current version.
SemperWise is not a QSA and not an ASV. We do the scoping, testing, remediation and readiness. Where a QSA signature or an ASV-branded quarterly scan is formally required, we work alongside a certified partner — and we tell you which you need before you spend anything.
Approach
Scope first, always. Assessing an environment before reducing it means paying to assess systems you were about to remove.
Map every system, flow and third party touching card data, then challenge each one. Everything that can be removed from scope is removed before anything else happens.
Gap analysis against all twelve requirements at v4.0.1, including the future-dated items that are now in force rather than upcoming.
External and internal vulnerability scanning, segmentation testing and application penetration testing against the reduced environment.
Prioritised fixes with owners and dates — not a two-hundred-row spreadsheet handed to your team with no sequencing.
Assemble the SAQ or the RoC evidence pack, retest anything that failed, and confirm the segmentation still holds after remediation.
Quarterly scanning and annual scope confirmation, so the following year is a review rather than a repeat of the whole programme.
Deliverables
The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.
What is in scope and, more valuably, what we removed from it — with the reasoning recorded for your assessor.
All twelve requirements at v4.0.1, with the future-dated items assessed as current obligations.
Evidence that the isolation you rely on actually holds, in the form Requirement 11 expects.
External and internal results with reproduction detail and remediation guidance, ready to hand to an assessor.
Owners, dates and sequencing, ordered by what unblocks validation soonest.
Assembled and organised, plus the quarterly cadence that keeps it valid between assessments.
Is this for you?
If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.
Book a scoping callHow we work
The same engagement model applies to every piece of work we take on, so you always know what happens next.
A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.
Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.
Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.
One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.
A walkthrough call with your engineers. We answer questions on the fix, not just the finding.
A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.
Questions
The questions clients actually ask during scoping. If yours is not here, ask it directly.
Version 4.0.1, released in June 2024 (as of August 2026). Version 3.2.1 was retired on 31 March 2024, and the 51 future-dated requirements introduced in v4.0 became mandatory on 31 March 2025 — so they are current obligations, not upcoming ones. Any assessment or guidance still written against v3.2.1 is out of date.
It depends on your merchant or service provider level, your transaction volume and what your acquirer requires. Many merchants validate through a self-assessment questionnaire; larger volumes typically require a QSA-led Report on Compliance. Your acquirer is the authority on this, and we confirm it with you before scoping so you are not sold an assessment you did not need.
No, and we would rather say so than blur it. We perform equivalent external and internal vulnerability scanning, and the remediation work behind it. Where an ASV-branded quarterly scan is formally required for your validation route, we coordinate with a certified ASV partner. Likewise, we are not a QSA — where a QSA signature is required, we prepare you for it and work alongside the firm you appoint.
Every system that can reach the cardholder data environment inherits the full requirement set. Systems properly isolated from it fall out of scope entirely. Reducing scope therefore reduces the number of assets carrying controls, the volume of evidence, and the assessment effort — every year, not once. It is the highest-return work in a PCI programme, which is why we do it first.
Usually you are in a much lighter SAQ category rather than out of scope entirely. It depends on how the payment page is delivered: a fully hosted redirect or iframe is treated very differently from a page you serve that posts card data onward, even if you never store it. Getting this determination right is worth doing carefully, because the difference in obligation is substantial.
External and internal vulnerability scanning runs quarterly and after significant change. Penetration testing runs at least annually and after significant infrastructure or application change, and segmentation testing runs on the same cadence for merchants — more frequently for service providers. We set the calendar up front so nothing lapses quietly between assessments.
Next step
A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.