PCI DSS

PCI DSS compliance consulting for merchants and service providers

We help you shrink your cardholder data environment, close gaps against PCI DSS v4.0.1 and produce the testing evidence your assessor or acquiring bank expects, whether you file a self-assessment questionnaire or undergo a QSA assessment.

  • Scoping and gap assessment against v4.0.1
  • Segmentation and PCI penetration testing
  • Remediation by our engineers or yours
Pharmacist helping a customer at the counter

Human-led PCI testing

Penetration and segmentation tests by certified ethical hackers

Retail experience

Security across stores and e-commerce for a multi-national retailer

Controls we can operate

Managed firewalls, MDR, logging and vulnerability management

Engineer working on network cabling in a rack

What PCI DSS requires

Twelve requirements, and scope decides the effort

The Payment Card Industry Data Security Standard applies to any organization that stores, processes or transmits cardholder data. PCI DSS v4.0.1 is the current version, and the requirements that v4.0 marked as future-dated became mandatory on March 31, 2025.

The most useful early work is scoping. Every system that touches cardholder data, or can reach one that does, is in scope. Segmentation, tokenization and outsourced payment pages can shrink that environment and the effort that goes with it. Triden is not a QSA. We prepare you for your self-assessment questionnaire or your QSA’s assessment.

What’s included

PCI compliance consultant services

How it works

From scope to validation

1

Scope

Map how card data moves and look for ways to reduce the environment in scope.

2

Assess

Compare your controls with the applicable PCI DSS v4.0.1 requirements and document the gaps.

3

Remediate and test

Close gaps, then run penetration and segmentation tests to confirm the fixes hold.

4

Validate

Complete your SAQ or support your QSA’s assessment with organized evidence.

FAQ

PCI DSS compliance questions

PCI DSS v4.0.1 is the current version. It clarified v4.0 without adding requirements, and the requirements v4.0 marked as future-dated have been mandatory since March 31, 2025.

It depends on your transaction volume and your acquiring bank or card brand requirements. Many smaller merchants validate with a self-assessment questionnaire, while larger merchants and many service providers need a QSA assessment. Confirm your validation level with your acquirer.

Segment cardholder systems from the rest of the network, avoid storing card data you don’t need, and consider tokenization or hosted payment pages. Segmentation must be tested to count.

Yes. The standard requires internal and external penetration testing and, where segmentation reduces scope, testing to confirm it works. Our penetration testing team performs both.

Cost depends on the size of your cardholder data environment, the number of locations and payment channels, your validation type and how much remediation is needed. We scope it on a short call and give you a fixed proposal.

Talk to a PCI expert

Get your PCI DSS scope and gaps under control

Tell us how you accept payments and an advisor will reply by email to scope your PCI DSS work.

  • A first view of how to reduce your scope
  • A fixed proposal for assessment and testing

Prefer email? Write to [email protected] or call (858) 712-0040.

Send us a message