Skip to content
Griffin IT Group griffin markOakville IT ServicesPowered by Griffin IT Group

Capability

PCI DSS Readiness

PCI work rewards scope discipline more than anything else. Every system you can legitimately remove from the cardholder data environment is a permanent reduction in cost and effort.

At a glance

  • Cardholder data discovery and payment flow mapping
  • Segmentation to reduce scope
  • Control implementation and evidence
  • Readiness support — not a QSA

Scope and segmentation

We map where card data enters, moves and rests — terminals, e-commerce checkout, phone payments, email, and historic files or backups that nobody remembered. That determines what is genuinely in scope and what can be removed.

Segmentation then isolates payment systems onto controlled network segments, moving the rest of the environment out of scope. Where the payment provider supports point-to-point encryption, hosted pages or tokenisation, eliminating stored card data entirely is usually the cheapest outcome available.

  • Cardholder data discovery across systems and processes
  • Payment flow mapping including phone and email
  • Network segmentation design and validation
  • P2PE, hosted page and tokenisation options
  • SAQ type identification

Controls in the cardholder data environment

Inside scope, the requirements are specific: secure configuration with defaults removed, documented firewall and access rules, MFA on administrative and remote access, unique IDs with least privilege, prompt patching, endpoint protection, logging with retention and review, vulnerability scanning at the required cadence, and penetration testing including segmentation validation.

Vendors touching the payment path need documented assessment. Their compliance status forms part of your evidence and their failures become your problem.

  • Configuration baselines and default credential removal
  • Access control, MFA and privilege management
  • Vulnerability management and patch cadence
  • Logging, retention, monitoring and review records
  • Penetration testing and segmentation validation
  • Service provider assessment records

What we are not

Griffin IT Group is not a Qualified Security Assessor. We do not perform formal assessments, issue attestations, or guarantee compliance outcomes. We provide the technical readiness work and coordinate with your acquirer, payment provider or QSA where one is involved.

Questions

Frequently asked questions

We use a hosted checkout — are we out of scope?
Reduced, not eliminated. The systems delivering and securing your checkout, your redirect configuration and your provider due diligence remain relevant, and the applicable SAQ type depends on the integration method.
Can you fill out our SAQ?
The SAQ is your attestation. We help you understand each requirement, establish truthful answers, implement what is missing and assemble the evidence behind it.
How often is testing required?
PCI DSS requires periodic penetration testing and, where segmentation reduces scope, testing that validates the segmentation. We scope both under written authorisation.

Shrink the problem before solving it

A scope review frequently removes more cost from a PCI programme than any control implementation could.