PCI DSS
Readiness
PCI DSS is prescriptive in a way most frameworks are not - the requirements say what to do, and an assessor checks whether you did it. We run readiness so your cardholder data environment is scoped correctly and every requirement has evidence before a QSA starts asking.
Who this is for
Readiness earns its cost when something is waiting on the other side of it. These are the situations where it pays for itself.
Merchants and service providers who store, process, or transmit cardholder data
Companies whose acquirer or payment brand has asked for a Report on Compliance
Teams filling in a Self-Assessment Questionnaire who are not confident the answers are true
Anyone relying on segmentation to keep PCI scope small and wanting that validated before it is tested
What the engagement does
Your Lorikeet team runs the assessment, collects and vets the evidence, and keeps control status current. You are not handed a spreadsheet and wished well.
- Define the cardholder data environment and validate what is genuinely in and out of scope
- Confirm the right SAQ type, or the RoC path, before the work is scoped the wrong way
- Assess all twelve requirement areas and record where you stand against each
- Build the evidence each requirement needs, including the ones teams routinely miss - targeted risk analyses, defined roles, documented responsibilities
- Close the gap list with your team
- Prepare the package your QSA or acquirer will ask for
What you walk away with
A defensible scope, a control set mapped requirement by requirement, and evidence organised the way an assessor reads it. Where segmentation reduces your scope, that reduction is documented and supportable rather than assumed.
How it runs
Four phases. You always know which one you are in and what is outstanding.
Scoping call
We establish what is in scope, which assessment path applies, and what you already have. It costs nothing, and it ends with a straight answer about whether readiness is the right spend right now.
Assessment
We walk the control set and record where you actually stand, control by control. The gap list lands early so your team can start on the long items while the rest of the assessment continues.
Remediate and evidence
We work the gap list down with your team and collect what each control needs, filed against the control it belongs to with an owner and an expiry date rather than dumped in a folder.
Hand off to your assessor
You go in with a package that maps requirement to control to evidence, and we stay available through the assessment itself.
What the assessment covers
The control areas we walk for PCI DSS. Each breaks down into individual controls carrying status, owner and evidence in Talon.
A Report on Compliance is signed by a Qualified Security Assessor. Self-assessment questionnaires are signed by you. We prepare either, and coordinate with your QSA - we do not sign your RoC.
It runs in Talon, not in a spreadsheet
Every control, its status, its owner and its evidence sit in the portal your team already uses, so the readiness picture you see is the one your Lorikeet team is maintaining rather than a copy that went stale a fortnight ago.
- Control-by-control status, kept current by the people doing the work
- Evidence filed against the control it satisfies, with expiry dates tracked
- The auditor request list, so nothing is chased over email
- A readiness view that shows what an assessor would see
Tools like Vanta monitor controls continuously once they exist and work. Readiness is the part before that: deciding the boundary, designing the controls, and closing the gaps a monitoring tool would otherwise report as permanently red. We work alongside them, and we are a Vanta MSP partner.
Our partnersAsked on almost every PCI DSS call
It depends on your merchant or service provider level and how card data flows through your environment. Getting this wrong is expensive in both directions: over-scoping wastes months, under-scoping fails validation. Establishing it correctly is the first thing readiness does.
Yes. 4.0 added targeted risk analyses, expanded authentication requirements, and several requirements that became mandatory after the transition period. Controls that satisfied 3.2.1 do not automatically satisfy 4.0.
Substantially, if it is real. Segmentation that exists on a network diagram but not in the routing table is one of the more common ways a PCI scope turns out to be far larger than expected once an assessor looks.
A QSA for a Report on Compliance; your own officer for a SAQ. We prepare the environment and the evidence and work alongside whichever path applies.
Rarely run alone
Controls overlap heavily between frameworks, and evidence collected once counts everywhere it applies. A second framework costs a fraction of the first.
PCI DSS readiness, on your timeline
A scoping call costs nothing and ends with a straight answer: what the work involves, what it costs, and whether you need it yet.