Skip to main content
Compliance Readiness

PCI DSS
Readiness

PCI DSS is prescriptive in a way most frameworks are not - the requirements say what to do, and an assessor checks whether you did it. We run readiness so your cardholder data environment is scoped correctly and every requirement has evidence before a QSA starts asking.

Report on Compliance (RoC) Self-Assessment (SAQ) Readiness Assessment
readiness log PCI DSS assessing
09:14:02scopePCI DSS v4.0confirmed
09:14:17assessReq 1: Network Security Controlswalked
09:15:18assessReq 2: Secure Configurationswalked
09:16:19assessReq 3: Protect Stored Datawalked
09:18:40gapmarked complete, no evidence attachedblocker
09:19:05gapcontrol has no named owneropen
09:22:31evidencefiled against control · expiry trackedaccepted
09:24:12handoffrequirement → control → evidencemapped
your team assesses evidence vetted tracked in Talon
12
control areas walked
3
assessment paths
14
frameworks on one programme
0
methodology slides
Fit

Who this is for

Readiness earns its cost when something is waiting on the other side of it. These are the situations where it pays for itself.

Merchants and service providers who store, process, or transmit cardholder data

Companies whose acquirer or payment brand has asked for a Report on Compliance

Teams filling in a Self-Assessment Questionnaire who are not confident the answers are true

Anyone relying on segmentation to keep PCI scope small and wanting that validated before it is tested

Scope of work

What the engagement does

Your Lorikeet team runs the assessment, collects and vets the evidence, and keeps control status current. You are not handed a spreadsheet and wished well.

  • Define the cardholder data environment and validate what is genuinely in and out of scope
  • Confirm the right SAQ type, or the RoC path, before the work is scoped the wrong way
  • Assess all twelve requirement areas and record where you stand against each
  • Build the evidence each requirement needs, including the ones teams routinely miss - targeted risk analyses, defined roles, documented responsibilities
  • Close the gap list with your team
  • Prepare the package your QSA or acquirer will ask for

What you walk away with

A defensible scope, a control set mapped requirement by requirement, and evidence organised the way an assessor reads it. Where segmentation reduces your scope, that reduction is documented and supportable rather than assumed.

Sequence

How it runs

Four phases. You always know which one you are in and what is outstanding.

01

Scoping call

We establish what is in scope, which assessment path applies, and what you already have. It costs nothing, and it ends with a straight answer about whether readiness is the right spend right now.

no charge
02

Assessment

We walk the control set and record where you actually stand, control by control. The gap list lands early so your team can start on the long items while the rest of the assessment continues.

Lorikeet assessor
03

Remediate and evidence

We work the gap list down with your team and collect what each control needs, filed against the control it belongs to with an owner and an expiry date rather than dumped in a folder.

joint
04

Hand off to your assessor

You go in with a package that maps requirement to control to evidence, and we stay available through the assessment itself.

with your assessor
Coverage

What the assessment covers

The control areas we walk for PCI DSS. Each breaks down into individual controls carrying status, owner and evidence in Talon.

01 Req 1: Network Security Controls
02 Req 2: Secure Configurations
03 Req 3: Protect Stored Data
04 Req 4: Data in Transit
05 Req 5: Malware Protection
06 Req 6: Secure Development
07 Req 7: Access Restriction
08 Req 8: Authentication
09 Req 9: Physical Access
10 Req 10: Logging & Monitoring
11 Req 11: Security Testing
12 Req 12: Security Policies
Who performs the assessment

A Report on Compliance is signed by a Qualified Security Assessor. Self-assessment questionnaires are signed by you. We prepare either, and coordinate with your QSA - we do not sign your RoC.

Where it lives

It runs in Talon, not in a spreadsheet

Every control, its status, its owner and its evidence sit in the portal your team already uses, so the readiness picture you see is the one your Lorikeet team is maintaining rather than a copy that went stale a fortnight ago.

  • Control-by-control status, kept current by the people doing the work
  • Evidence filed against the control it satisfies, with expiry dates tracked
  • The auditor request list, so nothing is chased over email
  • A readiness view that shows what an assessor would see
Already running a compliance platform?

Tools like Vanta monitor controls continuously once they exist and work. Readiness is the part before that: deciding the boundary, designing the controls, and closing the gaps a monitoring tool would otherwise report as permanently red. We work alongside them, and we are a Vanta MSP partner.

Our partners
Questions

Asked on almost every PCI DSS call

It depends on your merchant or service provider level and how card data flows through your environment. Getting this wrong is expensive in both directions: over-scoping wastes months, under-scoping fails validation. Establishing it correctly is the first thing readiness does.

Yes. 4.0 added targeted risk analyses, expanded authentication requirements, and several requirements that became mandatory after the transition period. Controls that satisfied 3.2.1 do not automatically satisfy 4.0.

Substantially, if it is real. Segmentation that exists on a network diagram but not in the routing table is one of the more common ways a PCI scope turns out to be far larger than expected once an assessor looks.

A QSA for a Report on Compliance; your own officer for a SAQ. We prepare the environment and the evidence and work alongside whichever path applies.

Alongside

Rarely run alone

Controls overlap heavily between frameworks, and evidence collected once counts everywhere it applies. A second framework costs a fraction of the first.

Next

PCI DSS readiness, on your timeline

A scoping call costs nothing and ends with a straight answer: what the work involves, what it costs, and whether you need it yet.

Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!