Define the cardholder data environment
Understand payment flows, connected systems, service providers, segmentation and the correct validation pathway.
Independent QSA guidance, assessment and validation from one of Australia’s most experienced PCI DSS consulting companies.
Vectra has supported payment-card security programmes since 2004. We help merchants and service providers understand scope, remediate gaps, validate compliance and maintain confidence under PCI DSS v4.0.1.
PCI DSS can become complex when payment channels, third parties, cloud platforms, e-commerce scripts and business processes overlap. Vectra turns the standard into a structured, achievable programme.
Understand payment flows, connected systems, service providers, segmentation and the correct validation pathway.
Review technical controls, policies, evidence and operational processes against PCI DSS v4.0.1.
Prioritise findings, clarify ownership and implement controls without unnecessary cost or disruption.
Prepare and complete ROC, SAQ, AoC and supporting testing with clear evidence and QSA guidance.
Independent QSA assessment and validation for Level 1 merchants, service providers and organisations requiring a formal ROC.
Identify non-compliance, evidence gaps and remediation priorities before the formal annual assessment begins.
Determine the appropriate SAQ, interpret requirements and prepare accurate, supportable responses and evidence.
Review payment architecture, segmentation, cloud, outsourcing, tokenisation and scope-reduction opportunities.
Quarterly external scanning, remediation support and reporting through an Approved Scanning Vendor service.
Explore ASV scanning →Validate cardholder-data environment controls, segmentation and exploit resistance against real attack techniques.
Explore penetration testing →Address PCI DSS requirements 6.4.3 and 11.6.1 through script inventory, authorisation, integrity and change detection.
Translate findings into practical technical, procedural and governance actions with clear priorities and ownership.
Maintain evidence, manage change, prepare for annual validation and reduce last-minute compliance pressure.
PCI DSS v4.0.1 is the current active version of the standard. The future-dated requirements became effective on 31 March 2025, making stronger authentication, targeted risk analysis, payment-page security and evidence-based control operation part of today’s compliance programme.
Vectra supports organisations of every size, from SAQ-eligible merchants to national enterprises and service providers with complex cardholder-data environments.
Support for in-store, online, contact-centre and recurring payment channels.
Assessment and advisory for organisations that store, process, transmit or affect the security of account data.
Practical QSA support across business units, cloud platforms, outsourced services and extensive technology estates.
A strong QSA does more than identify non-compliance. Vectra combines assessment experience with cybersecurity, infrastructure, testing and managed-services capability to provide advice that can actually be implemented.
Long-standing experience across card schemes, standards and changing payment technology.
Objective guidance focused on evidence, risk and the requirements that genuinely apply.
Concise findings, clear priorities and remediation guidance aligned to business operations.
Access to penetration testing, scanning, architecture, governance and cybersecurity specialists.
Support across Australia with experience in enterprise and distributed environments.
Extensive experience supporting organisations across retail, finance, transport, utilities and service providers.
Map payment flows, systems, people, providers and validation obligations.
Review controls, evidence, documentation and technical implementation.
Prioritise findings and work with owners to close gaps efficiently.
Complete testing, interviews, evidence review and the required reporting.
Support ongoing evidence, change management and next-year readiness.
Talk to one of Australia’s most experienced PCI DSS teams about scoping, gap assessment, SAQ assistance, QSA validation, testing or ongoing compliance.
Tell us how your organisation accepts payments and what stage you have reached in the compliance journey.
Contact the PCI Team →Before diving into the Payment Card Industry Data Security Standard requirements, you will also want to find out which Self Assessment Questionnaire (SAQ) applies to your business. While most requirements will stay the same, there are some differences in the work you’ll need to do based on your SAQ.
The current PCI DSS standard has twelve core requirements that are divided into six distinct control objectives. It’s imperative for businesses, regardless of size, to thoroughly understand and adhere to these requirements to maintain a level of data security that aligns with best practice methodology. Organisations looking to obtain and maintain PCI DSS compliance must meet or exceed these requirements on an ongoing basis.
Objectives | PCI DSS Requirements |
|---|---|
Build and Maintain a Secure Network and Systems | 1. Install and maintain a firewall configuration to protect cardholder data 2. Do not use vendor-supplied defaults for system passwords and other security parameters |
Protect Cardholder Data | 3. Protect stored cardholder data 4. Encrypt transmission of cardholder data across open, public network |
Maintain a Vulnerability Management Program | 5. Protect all systems against malware and regularly update anti-virus software or programs 6. Develop and maintain secure systems and applications |
Implement Strong Access Control Measures | 7. Restrict access to cardholder data by business need to know 8. Identify and authenticate access to system components 9. Restrict physical access to cardholder data |
Regularly Monitor and Test Networks | 10. Track and monitor all access to network resources and cardholder data 11. Regularly test security systems and processes |
Maintain an Information Security Policy | 12. Maintain a policy that addresses information security for all personnel |
What is PCI DSS?
Every organisation, anywhere in the world, that stores, processes or handles payment card data is required to be Payment Card Industry Data Security Standard (PCI DSS) compliant . This standard was designed to increase cardholder data protection to dramatically reduce credit card fraud. It doesn’t matter how few transactions your business or organisation has. It doesn’t matter if all your payments are handled by third-party payment processors. It doesn’t matter if the credit card is never stored on your servers, you still need to be PCI DSS compliant by meeting the requirements that are set out in the standard.
Payment Card Industry Data Security Standard (PCI DSS) compliance is, at its core, a contractual agreement between your organisation or business and the financial institution that handles the payments.
The PCI DSS has 12 requirements that have a clear focus on using secure systems. Implementation of the standard will depend on the size and nature of your business or organisation, the way in which you are configured to accept and process card payments, and the services providers you work with and their roles in the payment process.
How do you comply with the PCI DSS?
Compliance reporting for small merchants can be as simple as completing a Self-Assessment Questionnaire (SAQ) while for larger merchants and third party service providers, annual assessments must be conducted by a Qualified Security Assessor (QSA) Company such as Vectra Corporation or a PCI SSC certified Internal Security Assessor (ISA). If you have internet facing IP addresses you may be required to conduct network vulnerability scanning utilising an Approved Scanning Vendor (ASV) certified by the PCI Security Standards Council. The compliance requirements and how often compliance needs to be validated depends on the number of annual transactions processed by your business or organisation.
What are the Merchant Levels and PCI DSS Compliance Requirements?
Merchant levels are assigned by the Acquirer based on transaction volume. We can support categorisation based on what the bank’s expectations are and the relevant card scheme requirements. Your merchant level will determine the PCI DSS compliance requirements that your organisation will need to meet.
| Cookie | Duration | Description |
|---|---|---|
| cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
| cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
| cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
| cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
| cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
| viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |