Contact

What are you looking for?

Payment Card Industry Data Security Standard (PCI DSS) Compliance Services

Protect customer cardholder information with PCI DSS advisory, readiness and certification services from SGS.

When you take card payments, you rely on customer trust in your ability to protect their financial data. With the Payment Card Industry Data Security Standard, established by major card brands, your business can demonstrate adherence to stringent security measures. The protocols of the standard are designed to safeguard transactional data, deter identity fraud and prevent costly security breaches, enhancing your reputation as a trustworthy business.

Our accredited PCI DSS v4.0.1 certification service, provided by Panacea Infosec (part of SGS), confirms your compliance with the 12 key PCI DSS requirements and positions you to manage ongoing security challenges effectively.

Elevate your data protection standards with PCI DSS certification from SGS

  • Manage risk, increase awareness
    Significantly reduce the risk of security incidents.
  • Build trust and relationships
    Foster trust among customers, partners and vendors.
  • Save time, money and effort
    Enhance operational efficiency and avoid non-compliance fines.
  • Improve your position in the marketplace
    Boost brand recognition, gain a competitive edge and access international markets.
  • Achieve continuous improvement
    Pursue continual improvement for long-term business sustainability.
Woman Using a Laptop in a Server Room

Unrivaled PCI DSS expertise and support

As the world leader in testing, inspection and certification, we offer in-depth data security expertise for your business operations. Our comprehensive PCI DSS services are tailored to the needs of your organization, regardless of its size or sector. We guide you through every step – from initial gap analysis to continuous compliance maintenance. Our global presence and experience ensure that your data security measures meet international standards, helping you navigate and adapt to the evolving landscape of cyber threats.

FAQ

The PCI DSS is a set of requirements explaining how to protect you and your customers when taking card payments. These are industry-spanning requirements, so all suppliers taking payments should take the PCI DSS seriously.

PCI DSS version 4 has many changes, including a customized approach, new requirements and clarification on the use of targeted risk analysis.

Customized approach

To better align with contemporary cybersecurity frameworks, the PCI Security Standards Council (PCI SSC) has added the option for companies to develop their own responses to requirements through secure equivalent implementation. This gives organizations more autonomy to design and implement their control responses to meet the requirements. This requires targeted risk analysis (TRA) for each control where the customized approach is used.

Visa, MasterCard, Discover Financial Services, JCB International and American Express created the PCI DSS in 2004.

There are 6 broad areas containing 12 requirements for handling cardholder data and continuously protecting a network:

  1. Secure network
  1. A firewall must be installed and maintained
  2. Apply secure configurations to all system components
  1. Secure cardholder data
  1. Stored cardholder data must be protected
  2. Protect cardholder data with strong cryptography during transmission over open, public networks
  1. Vulnerability management
  1. Protect all systems and networks from malicious software
  2. Secure systems and applications must be developed and maintained
  1. Access control
  1. Restrict access to system components and cardholder data by business need-to-know
  2. Enforce unique IDs and control all system-level access
  3. Restrict physical access to cardholder data
  1. Network monitoring and testing
  1. Access to cardholder data and network resources must be tracked and monitored
  2. Security systems and processes must be regularly tested
  1. Information security
  1. An information security policy must be maintained

Your compliance level is based on the annual number of credit/debit card transactions your business processes. The level determines what you must do to maintain compliance.

Level 1: 6 million transactions per year
Level 2: 1-6 million transactions per year
Level 3: 20,000-1 million transactions per year
Level 4: <20,000 transactions per year

Different entities may request that your organization obtain PCI DSS compliance, including:

  • Your acquiring bank (the bank you deal with the most)
  • Your business partners
  • Clients
  • Other contractual or legal entities

An organization that starts taking card payments has 90 days to meet the PCI DSS requirements. After this, you must maintain compliance and show it at least once a year.

Foundation

  • Understand the 12 PCI DSS requirements
  • Identify your compliance level and applicable requirements
  • Map your payment card data flows and access points

Assessment

  • Complete the appropriate Self-Assessment Questionnaire (SAQ) or Report on Compliance (ROC)
  • Review and confirm security controls and protocols
  • Conduct quarterly Approved Scanning Vendor (ASV) scans

Validation

  • Perform a risk assessment of the payment environment
  • Conduct a gap analysis against the PCI DSS requirements
  • Complete an internal audit

Certification

  • Establish continuous monitoring
  • Engage a Qualified Security Assessor (QSA) and complete the formal assessment

Every organization is different, from its size and type to its information security and cybersecurity measures. Therefore, an organization is judged individually. What you must do to comply depends on your potential security risks.

If you cannot prove you are protecting customer cardholder data, the consequences could be severe for both sides, including:

  • Lawsuits
  • Financial penalties
  • Reputational damage
  • Customer disillusionment and distrust
  • Theft of customers’ money and identities

News & Insights

  • SGS – PCI DSS certification

30 Boon Lay Way, #03-01,

609957,

Singapore, Singapore