Deutsch: această pagină nu e încă tradusă. Textul de mai jos e în English.
Nearly everyone focuses on the twelve requirements. The experienced practitioner knows that 80% of the risk and effort sits before them, in a single question: what is actually in scope? The cardholder data environment (CDE) is everything that stores, processes or transmits card numbers, plus connected systems that can affect it — and it is much larger than most believe. A scope declared too small is the most frequent cause of failure at a real assessment. That is why we start with scope validation and reduction through segmentation, not with ticking requirements.
What changed with v4.0.1
- From 31 March 2025, requirements previously considered “best practice” became mandatory — there is no more grace period
- A requirement can be met through the defined approach (the classic prescribed control) or the customised approach (new in v4.x): you meet the security objective with your own controls, supported by a targeted risk analysis. It is not an easier path — it must provide at least equivalent protection
- Changes that catch organisations off guard: extended MFA, stronger passwords and payment-page script integrity controls (requirements 6.4.3 and 11.6.1) — the defence against browser-based skimming attacks
How we work and what you get
Scope and segmentation validation → gap analysis → remediation → formal assessment (SAQ or RoC) → Attestation of Compliance (AoC). We test control design and operating effectiveness, with samples and evidence. You receive scope validation, the gap analysis, a roadmap and preparation for the RoC/SAQ and AoC.
We are clear: signing a Report on Compliance (RoC) belongs to a QSA. We prepare you and take you there without surprises.