PCI DSS Consulting & Compliance

Australia’s trusted PCI experts.Compliance made practical.

Independent QSA guidance, assessment and validation from one of Australia’s most experienced PCI DSS consulting companies.

Vectra has supported payment-card security programmes since 2004. We help merchants and service providers understand scope, remediate gaps, validate compliance and maintain confidence under PCI DSS v4.0.1.

Independent PCI DSS guidance for merchants and service providers QSA AssessmentsGap AssessmentsSAQ AssistanceASV ScanningPenetration Testing
A clearer path to compliance

Know what applies, what is missing and what to do next.

PCI DSS can become complex when payment channels, third parties, cloud platforms, e-commerce scripts and business processes overlap. Vectra turns the standard into a structured, achievable programme.

01 / SCOPE

Define the cardholder data environment

Understand payment flows, connected systems, service providers, segmentation and the correct validation pathway.

02 / ASSESS

Identify compliance gaps

Review technical controls, policies, evidence and operational processes against PCI DSS v4.0.1.

03 / REMEDIATE

Close gaps pragmatically

Prioritise findings, clarify ownership and implement controls without unnecessary cost or disruption.

04 / VALIDATE

Complete the right assessment

Prepare and complete ROC, SAQ, AoC and supporting testing with clear evidence and QSA guidance.

PCI DSS services

End-to-end support from readiness to annual validation.

QSA Assessment

Report on Compliance

Independent QSA assessment and validation for Level 1 merchants, service providers and organisations requiring a formal ROC.

Readiness

PCI DSS gap assessment

Identify non-compliance, evidence gaps and remediation priorities before the formal annual assessment begins.

Self-Assessment

SAQ assistance and review

Determine the appropriate SAQ, interpret requirements and prepare accurate, supportable responses and evidence.

Advisory

Scoping and design review

Review payment architecture, segmentation, cloud, outsourcing, tokenisation and scope-reduction opportunities.

Scanning

ASV vulnerability scanning

Quarterly external scanning, remediation support and reporting through an Approved Scanning Vendor service.

Explore ASV scanning →
Testing

PCI penetration testing

Validate cardholder-data environment controls, segmentation and exploit resistance against real attack techniques.

Explore penetration testing →
E-commerce

Payment-page script security

Address PCI DSS requirements 6.4.3 and 11.6.1 through script inventory, authorisation, integrity and change detection.

Remediation

Control implementation advice

Translate findings into practical technical, procedural and governance actions with clear priorities and ownership.

Ongoing Compliance

Continuous PCI advisory

Maintain evidence, manage change, prepare for annual validation and reduce last-minute compliance pressure.

PCI DSS v4.0.1

Current requirements, explained clearly.

PCI DSS v4.0.1 is the current active version of the standard. The future-dated requirements became effective on 31 March 2025, making stronger authentication, targeted risk analysis, payment-page security and evidence-based control operation part of today’s compliance programme.

01
Role-based and risk-based controlsTargeted risk analyses must support defined frequencies and control decisions where the standard allows flexibility.
02
Stronger identity and authenticationMulti-factor authentication, account governance and access-management requirements apply more broadly.
03
Payment-page script securityOrganisations must authorise, inventory and justify payment-page scripts and detect unauthorised changes.
04
Continuous evidence and operationCompliance must be supported by repeatable processes, accountable owners and evidence that controls operate throughout the year.
Who we support

PCI expertise across complex payment environments.

Vectra supports organisations of every size, from SAQ-eligible merchants to national enterprises and service providers with complex cardholder-data environments.

Merchants

Retail, e-commerce and customer payments

Support for in-store, online, contact-centre and recurring payment channels.

  • SAQ and ROC pathways
  • Payment-page security
  • Scope reduction
  • Multi-channel payments
Service Providers

Platforms, hosting and payment services

Assessment and advisory for organisations that store, process, transmit or affect the security of account data.

  • Service-provider ROC
  • Responsibility matrices
  • Customer assurance
  • Shared-control environments
Complex Enterprise

Large and regulated organisations

Practical QSA support across business units, cloud platforms, outsourced services and extensive technology estates.

  • Multiple payment channels
  • Cloud and hybrid environments
  • Segmentation validation
  • Enterprise remediation programmes
Why Vectra

Experienced assessors who understand operations.

A strong QSA does more than identify non-compliance. Vectra combines assessment experience with cybersecurity, infrastructure, testing and managed-services capability to provide advice that can actually be implemented.

ExperiencedPayment security since 2004

Long-standing experience across card schemes, standards and changing payment technology.

IndependentClear, defensible assessment

Objective guidance focused on evidence, risk and the requirements that genuinely apply.

PracticalAdvice your teams can use

Concise findings, clear priorities and remediation guidance aligned to business operations.

End-to-EndAssessment plus technical capability

Access to penetration testing, scanning, architecture, governance and cybersecurity specialists.

NationalAustralian delivery capability

Support across Australia with experience in enterprise and distributed environments.

TrustedThousands of engagements

Extensive experience supporting organisations across retail, finance, transport, utilities and service providers.

Our assessment approach

Structured, transparent and focused on a successful outcome.

01

Scope

Map payment flows, systems, people, providers and validation obligations.

02

Assess

Review controls, evidence, documentation and technical implementation.

03

Remediate

Prioritise findings and work with owners to close gaps efficiently.

04

Validate

Complete testing, interviews, evidence review and the required reporting.

05

Maintain

Support ongoing evidence, change management and next-year readiness.

Start with a PCI conversation

Make compliance clearer, faster and easier to maintain.

Talk to one of Australia’s most experienced PCI DSS teams about scoping, gap assessment, SAQ assistance, QSA validation, testing or ongoing compliance.

Speak with a Vectra QSA

Tell us how your organisation accepts payments and what stage you have reached in the compliance journey.

Contact the PCI Team →

What are the 12 requirements of the PCI DSS

Before diving into the Payment Card Industry Data Security Standard requirements, you will also want to find out which Self Assessment Questionnaire (SAQ) applies to your business. While most requirements will stay the same, there are some differences in the work you’ll need to do based on your SAQ.

The current PCI DSS standard has twelve core requirements that are divided into six distinct control objectives. It’s imperative for businesses, regardless of size, to thoroughly understand and adhere to these requirements to maintain a level of data security that aligns with best practice methodology. Organisations looking to obtain and maintain PCI DSS compliance must meet or exceed these requirements on an ongoing basis.

Objectives
PCI DSS Requirements
Build and Maintain a Secure Network and Systems
1. Install and maintain a firewall configuration to protect cardholder data
2. Do not use vendor-supplied defaults for system passwords and other security parameters
Protect Cardholder Data
3. Protect stored cardholder data
4. Encrypt transmission of cardholder data across open, public network
Maintain a Vulnerability Management Program
5. Protect all systems against malware and regularly update anti-virus software or programs
6. Develop and maintain secure systems and applications
Implement Strong Access Control Measures
7. Restrict access to cardholder data by business need to know
8. Identify and authenticate access to system components
9. Restrict physical access to cardholder data
Regularly Monitor and Test Networks
10. Track and monitor all access to network resources and cardholder data
11. Regularly test security systems and processes
Maintain an Information Security Policy
12. Maintain a policy that addresses information security for all personnel

Stay up to date

Visit our blog for fresh advice and insights on PCI DSS.

FAQs

Every organisation, anywhere in the world, that stores, processes or handles payment card data is required to be Payment Card Industry Data Security Standard (PCI DSS) compliant . This standard was designed to increase cardholder data protection to dramatically reduce credit card fraud. It doesn’t matter how few transactions your business or organisation has. It doesn’t matter if all your payments are handled by third-party payment processors. It doesn’t matter if the credit card is never stored on your servers, you still need to be PCI DSS compliant by meeting the requirements that are set out in the standard.

Payment Card Industry Data Security Standard (PCI DSS) compliance is, at its core, a contractual agreement between your organisation or business and the financial institution that handles the payments.

The PCI DSS has 12 requirements that have a clear focus on using secure systems. Implementation of the standard will depend on the size and nature of your business or organisation, the way in which you are configured to accept and process card payments, and the services providers you work with and their roles in the payment process.

Compliance reporting for small merchants can be as simple as completing a Self-Assessment Questionnaire (SAQ) while for larger merchants and third party service providers, annual assessments must be conducted by a Qualified Security Assessor (QSA) Company such as Vectra Corporation or a PCI SSC certified Internal Security Assessor (ISA). If you have internet facing IP addresses you may be required to conduct network vulnerability scanning utilising an Approved Scanning Vendor (ASV) certified by the PCI Security Standards Council. The compliance requirements and how often compliance needs to be validated depends on the number of annual transactions processed by your business or organisation. 

Merchant levels are assigned by the Acquirer based on transaction volume.  We can support categorisation based on what the bank’s expectations are and the relevant card scheme requirements. Your merchant level will determine the PCI DSS compliance requirements that your organisation will need to meet.