Skip to content
Compliance

PCI DSS Certification Preparation

Non-compliance with PCI DSS means fines up to $100,000 per month plus losing ability to accept cards. We'll guide you through standard requirements - implementation, documentation, audit. Protect customer data and avoid sanctions.

Sales Representative
Przemysław Widomski

Przemysław Widomski

Sales Representative

What is PCI DSS Certification Preparation?

PCI DSS Certification Preparation is end-to-end support for organizations that accept card payments — from CDE scoping and gap analysis against all 12 PCI DSS 4.0 requirements, through technical control implementation and penetration testing, to obtaining the Attestation of Compliance (AOC) accepted by banks and acquirers. nFlo guides companies through the entire process to avoid fines of up to $100,000 per month and eliminate the risk of losing the ability to process card payments.

PCI DSS 4.0 Standard
Payment Card Industry
QSA Experience
Qualified Security Assessor
Visa, Mastercard, Amex
All card organizations

Without PCI DSS you lose the right to accept card payments

$100,000 monthly penalty for PCI DSS non-compliance from payment card organizations

Comprehensive PCI DSS certification preparation

Gap Analysis

Compliance assessment against all 12 PCI DSS requirements

Control Implementation

Missing technical security control implementation

SAQ & AOC

Documentation preparation and compliance audit

€55K Monthly Fine - Online Store Story

An online store with €2.5M annual revenue was fined €55K by acquirer for PCI DSS non-compliance. After 3 months without remediation - lost ability to accept card payments. Company went bankrupt within 6 months.

Without PCI DSS compliance:

  • Fines from $5,000 to $100,000 per month from card organizations
  • Increased transaction fees (up to 0.5% higher)
  • Risk of losing ability to accept card payments
  • Liability for card data breach - card replacement costs can reach millions

From CDE Scoping to Attestation of Compliance

We don’t leave you with a long list of requirements to meet. We guide you through the entire process - from defining cardholder data environment scope to obtaining AOC (Attestation of Compliance).

What you get:

  • CDE scoping - precise determination of which systems process card data
  • Compliance assessment against all 12 PCI DSS 4.0 requirements
  • Implementation plan for missing controls with priorities
  • Technical security implementation (segmentation, encryption, monitoring)
  • Security policy and procedure preparation
  • Self-Assessment Questionnaire (SAQ) appropriate for your business type
  • Penetration testing and ASV scanning coordination
  • Support during QSA audit (for Merchant Level 1 and 2)
  • Attestation of Compliance (AOC) for bank submission

Who Is It For?

This service is for you if:

  • You accept card payments (e-commerce, POS, call center)
  • You’re required by bank/acquirer to obtain PCI DSS
  • You process, store or transmit payment card data
  • You’re a payment service provider or payment processor
  • You want to lower transaction fees and avoid fines

PCI DSS Requirements

12 Payment Card Industry Data Security Standard Requirements

PCI DSS 4.0 defines 12 core requirements in 6 goals:

Build and Maintain Secure Network:

  1. Firewall configuration for card data protection
  2. Change default passwords and parameters

Protect Cardholder Data: 3. Protect stored card data 4. Encrypt transmission over public networks

Maintain Vulnerability Management: 5. Malware protection 6. Secure systems and applications

Implement Strong Access Control: 7. Restrict data access by need-to-know 8. Authenticate system access 9. Restrict physical access

Monitor and Test Networks: 10. Log and monitor data access 11. Regular security testing

Maintain Information Security Policy: 12. Information security policy

SAQ Types

Which SAQ is Right for You?

SAQ TypeWhoComplexity
SAQ AE-commerce with redirect to PSPSimplest
SAQ A-EPE-commerce with payment page elementsLow
SAQ BImprint machines, standalone terminalsLow
SAQ B-IPIP-connected terminalsMedium
SAQ CPayment applicationsMedium
SAQ C-VTVirtual terminal (manual entry)Low
SAQ P2PEP2PE-validated payment solutionsLow
SAQ D MerchantAll other merchantsFull scope
SAQ D SPService providersFull scope

Compliance Process

Step by Step to Certification

Phase 1: Scoping (1-2 weeks)

  • Identify all systems processing card data
  • Map data flows (where card data goes)
  • Define CDE boundaries
  • Identify connected systems

Phase 2: Gap Analysis (2-3 weeks)

  • Assessment against all 12 requirements
  • Technical configuration review
  • Policy and procedure review
  • Gap documentation and risk assessment

Phase 3: Remediation (4-12 weeks)

  • Technical control implementation
  • Network segmentation
  • Encryption implementation
  • Access control hardening
  • Logging and monitoring setup
  • Policy and procedure development

Phase 4: Validation (2-4 weeks)

  • Internal penetration testing
  • ASV external scanning
  • SAQ completion
  • Evidence collection

Phase 5: Audit/Certification (1-4 weeks)

  • QSA on-site audit (if required)
  • Finding remediation
  • AOC issuance
  • Submission to acquirer

Key Technical Requirements

What You Need to Implement

Network Security:

  • Firewall protecting CDE
  • DMZ for public-facing systems
  • Network segmentation
  • Wireless security (if applicable)

Data Protection:

  • No PAN storage (if possible)
  • Strong encryption for stored data (AES-256)
  • TLS 1.2+ for transmission
  • Key management procedures

Access Control:

  • Unique user IDs
  • Strong authentication (MFA)
  • Role-based access
  • Physical access controls

Monitoring:

  • Log all access to cardholder data
  • Centralized log management
  • Daily log review
  • Alerting on suspicious activity

Learn more about key concepts related to this service:

Contact your account manager

Discuss PCI DSS Certification Preparation with your dedicated account manager.

Sales Representative
Przemysław Widomski

Przemysław Widomski

Sales Representative

Response within 24 hours
Free consultation
Custom quote

Providing your phone number will speed up contact.

How we work

Our proven service delivery process.

01

Scoping

Define CDE (Cardholder Data Environment)

02

Gap Analysis

Compliance assessment against 12 PCI DSS 4.0 requirements

03

Remediation

Missing security control implementation

04

SAQ & Testing

Self-Assessment Questionnaire and penetration testing

05

QSA Audit

Audit by Qualified Security Assessor (if required)

Benefits for your business

What you gain by choosing this service.

Accept Payments

Maintain right to accept payment cards

Avoid Fines

Protection from fines up to $100,000 per month

Customer Trust

Customers know their data is secure

Lower Premiums

Cyber insurers value compliance

Frequently Asked Questions

Common questions about PCI DSS Certification Preparation.

How long does PCI DSS certification preparation take?

Implementation takes 3 to 9 months depending on the size of the CDE environment and current compliance level. Companies with ISO 27001 already in place can shorten this time by 30-40%.

Do I need a full QSA audit or is an SAQ sufficient?

It depends on your Merchant Level. Level 1 (over 6 million transactions per year) requires a QSA audit. Level 2-4 typically complete an SAQ (Self-Assessment Questionnaire). We help determine the appropriate type during the CDE scoping phase.

What does PCI DSS 4.0 cover and how does it differ from version 3.2.1?

PCI DSS 4.0 introduces a customized approach (flexibility in meeting requirements), requires continuous monitoring instead of point-in-time audits, and strengthens requirements for MFA, encryption and vulnerability management.

Do you also help with penetration testing and ASV scanning required by PCI DSS?

Yes, we coordinate both internal and external penetration testing (Requirement 11) as well as quarterly scanning by an Approved Scanning Vendor (ASV) required for all Merchant Levels.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist