CyberFinance

PCI DSS & Payment Security Advisory

Scope reduction first, compliance second, cost third.

The situation

PCI DSS v4.0 requirements that were best practice became mandatory on 31 March 2025, and most merchants and service providers are still paying to protect data they never needed to hold.

We start with scope reduction — tokenisation, redirect and hosted-field patterns, network segmentation — because every system removed from scope is a permanent reduction in cost and risk, then take the residual estate to full compliance.

What the client receives

Schedule of deliverables

  1. 01Cardholder data discovery and flow mapping
  2. 02Scope reduction strategy and segmentation design
  3. 03Gap assessment against PCI DSS v4.0.1
  4. 04Self-assessment questionnaire support and evidence preparation
  5. 05QSA audit preparation and remediation
  6. 06Segmentation penetration testing

Frameworks and standards

Assessment is carried out against named references, so a conclusion can be traced back to the requirement it was measured against.

  • PCI DSS v4.0.1
  • PCI SSC guidance
  • PSD2

Discuss this engagement

Tell us about your payment flows and the assessment level that applies and we will set out the scope, the method and the reporting format.

Contact us