Govern & Assure

PCI DSS Assessments

Formal PCI DSS assessment delivered by experienced QSAs, covering the appropriate validation route for your organisation and the evidence needed to support it.

  • QSA-led assessment
  • The right reporting outcome
  • Evidence-based validation
  • Clear assessment planning
  • Clear handling of findings

A formal PCI DSS assessment is where your compliance position is validated against the requirements that apply to the agreed scope. It is different from readiness or gap work: the QSA must obtain and assess sufficient evidence, apply appropriate sampling, and document the assessment to support the required reporting outcome.

The exact route depends on your environment and reporting requirements. That may mean a Report on Compliance and Attestation of Compliance, a QSA-validated Self-Assessment Questionnaire, or another recognised reporting route where appropriate. For merchants, the reporting method is ultimately driven by the organisation managing the compliance programme, such as the acquirer or payment brand, so we work within those requirements rather than assuming one route fits every client.

We plan the assessment around the agreed scope, applicable PCI DSS requirements, relevant locations, people, systems, and third parties. Evidence is reviewed through a combination of documentation, interviews, observation, and sampling, with the level of work driven by the size and complexity of the environment.

Where issues are identified, we explain them clearly and work with you through the assessment process so there is no ambiguity about what still needs to be demonstrated. The objective is a defensible assessment based on sufficient evidence, not simply getting through a checklist.

Get a quote for PCI DSS Assessments

Tell us your scope and objectives, and we’ll come back with a clear, fixed proposal, usually the same working day.

Get a Quoteor call +44 (0) 203 393 7795
  • CREST-accredited
  • UK-based specialists
  • Crown Commercial Service supplier

How it works

  1. 01

    Establish the assessment basis

    We start with the agreed PCI DSS scope, applicable requirements, and the reporting expectations that apply to the organisation.

  2. 02

    Plan the assessment

    We agree the assessment approach, key stakeholders, documentation requests, locations, interviews, and any sampling that will be needed.

  3. 03

    Review evidence

    We assess relevant policies, procedures, technical evidence, and other supporting documentation against the applicable PCI DSS requirements.

  4. 04

    Validate controls in practice

    We use interviews, observation, and appropriate sampling to confirm that controls are implemented and operating as required.

  5. 05

    Resolve outstanding issues

    Where the assessment identifies gaps or insufficient evidence, we explain what remains outstanding and work with you through the relevant remediation and evidence process.

  6. 06

    Complete reporting

    Once the assessment is complete, we prepare the appropriate PCI DSS reporting and attestation, complete our quality assurance process, and issue the final assessment documents.

More than a compliance decision

A formal PCI DSS assessment has to reach a clear compliance conclusion, but the quality of the work matters just as much as the outcome.

Our QSAs take time to understand how the environment really operates, how responsibilities are divided, and whether the evidence being presented is representative of normal practice. Sampling is applied where appropriate, evidence is tested in context, and conclusions are based on what can be demonstrated rather than what is assumed.

That matters in complex environments. Payment channels change, responsibilities are shared with service providers, and apparently simple controls can operate differently across teams, locations, or platforms. Good assessment work identifies those nuances without turning the process into unnecessary bureaucracy.

The result should be more than completed reporting. You should finish with a compliance position that is clear, properly evidenced, and defensible, with no ambiguity about what was assessed and why.

When standard reporting does not fit

Not every PCI assurance question fits neatly into a standard SAQ or ROC route. Where a customer, company, or other relying party needs independent QSA assurance on a specific PCI DSS position, we carry out a defined review and provide a written Statement of Opinion.

This can also be used where you need QSA input before making a decision, for example when reviewing a proposed new solution, architecture, or service model and you want an independent view of the likely PCI DSS implications before committing to it.

The scope, evidence, and conclusion are agreed up front, and the opinion is limited to the question being asked. It does not replace formal PCI DSS validation where that is required, but it can provide a clear, independent view where standard reporting does not address the situation.

What you get

QSA-led assessment

Your assessment is carried out by qualified QSAs with experience across different payment models, merchant environments, and service providers.

The right reporting outcome

We support the appropriate PCI DSS validation route, including ROC and AOC reporting and QSA-validated SAQs where applicable.

Evidence-based validation

Compliance conclusions are supported by appropriate documentation, interviews, observation, and sampling rather than relying on statements alone.

Clear assessment planning

We agree the scope, stakeholders, evidence needs, locations, and assessment activities up front so your teams know what to expect.

Clear handling of findings

Where requirements are not yet fully demonstrated, we explain the issue, the evidence gap, and what needs to happen next.

Support beyond the assessment

After validation, our ongoing support service covers change advice, recurring compliance activities, and preparation for the next assessment cycle.

Frequently asked questions

Straight answers to what prospective clients ask us most.

Do we need a Report on Compliance?

Not always. The required validation route depends on your reporting obligations and payment environment. For merchants, those requirements are normally driven by the organisation managing the compliance programme, such as the acquirer or payment brand.

What is the difference between a gap analysis and a formal PCI DSS assessment?

A gap analysis is advisory: a show-and-tell exercise using discussion, demonstrations, and higher-level evidence review to identify weaknesses and show whether you appear ready. A formal assessment requires the QSA to validate compliance through appropriate evidence, sampling, interviews, and documented assessment procedures. A good gap analysis is a strong readiness signal, but it is not evidence of compliance.

What evidence will you need?

That depends on the requirements being assessed and how the control is implemented. Evidence may include policies, procedures, configuration information, logs, records, screenshots, reports, and other documentation, supported by interviews and observation where required.

What happens if you identify a gap during the assessment?

We explain what has not yet been demonstrated and what evidence or remediation is needed. Depending on the issue and the assessment circumstances, there may be an opportunity to remediate and provide further evidence before reporting is completed.

The important distinction is that we cannot mark a requirement compliant until sufficient evidence supports that conclusion.

Do you assess service providers as well as merchants?

Yes. We assess a wide range of service providers as well as merchants, including organisations supporting payment processing, infrastructure, payment devices, software, and other payment-related services.

Service provider assessments can involve more complex scope and shared-responsibility questions, particularly where one service supports multiple customers or environments.

Can we go straight into formal assessment?

Sometimes, but we normally recommend some readiness activity first. If you have been compliant previously, the environment is stable, and confidence is high, that preparation may be relatively light. If scope, controls, or evidence are uncertain, a gap or readiness assessment is usually the safer route.

Ready to talk about pci dss assessments?

Get a fixed-scope quote, usually the same working day.