Any merchant or service provider that stores, processes, or transmits payment card data, regardless of company size; the validation burden scales with transaction volume, but the underlying requirements apply to everyone in scope.
12 core requirements spanning network security, cardholder data protection (including encryption), vulnerability management, strong access control, monitoring and testing, and a formal information security policy.
Cardholder data environment scope directly determines audit burden, so network segmentation isolating payment systems from the rest of your infrastructure is often the single highest-leverage control.
Cardholder data environment scoping and network segmentation review, gap assessment against the 12 requirements, and validation-method determination (SAQ vs. formal Report on Compliance with a QSA).
Map the cardholder data environment and confirm segmentation.
Close gaps against the 12 requirements, prioritizing encryption and access control.
Complete the appropriate SAQ or support a QSA-led Report on Compliance.
Network diagrams showing cardholder data flow and segmentation, encryption and key management documentation, vulnerability scan results, and access control logs.
Under-scoping the cardholder data environment, which looks favorable short-term but creates real exposure and audit risk; treating quarterly vulnerability scans as sufficient without addressing findings between scan cycles.
Map your cardholder data environment and see where your controls stand.
Request a Gap Assessment →