PCI DSS Service Desk Australia

Make merchant PCI compliance easier to complete—and easier to support.

Vectra operates an Australian PCI DSS Service Desk for acquiring banks, payment providers and their merchants. We guide merchants through scoping, Self-Assessment Questionnaires, ASV scanning, remediation questions and annual renewal—backed by one of Australia’s most experienced PCI DSS teams.

A supported merchant compliance journey
01
OnboardMerchant registration, users, notifications and portal access.
02
ScopeUnderstand the payment environment and the appropriate validation pathway.
03
AssessPractical guidance through the applicable PCI DSS Self-Assessment Questionnaire.
04
ScanASV scanning support where external vulnerability scanning is required.
05
ResolveHelp merchants understand failures, evidence requirements and next actions.
06
RenewNotifications and guidance to help keep annual compliance activity on track.
20+ years in payment securityVectra has supported PCI programmes since 2004
QSA capability since 2006Australia’s first PCI SSC-certified QSA Company
Australian Service DeskLocal merchant support by PCI DSS and QSA-trained staff
End-to-end PCI capabilityService Desk, QSA, ASV, penetration testing and advisory
For Acquiring Banks & Payment Providers

Operate a stronger merchant compliance programme without building the support function yourself.

Merchant PCI programmes generate a very specific support workload: portal access, SAQ selection, scoping questions, scan failures, annual reminders and merchants who simply need someone to explain what the requirement means in practical terms.

Vectra becomes the specialist PCI support layer between your programme and your merchant population.

Merchant supportGive merchants direct access to an Australian team that understands PCI DSS, payment channels and common validation pathways.
Programme consistencyProvide a repeatable support experience rather than relying on general banking or payments teams to interpret PCI requirements.
Lower support burdenMove specialist PCI questions, SAQ guidance and ASV assistance away from internal service teams.
Compliance momentumSupport onboarding, renewal activity and remediation so merchants are less likely to stall when the process becomes technical.
Specialist escalationWhere an issue moves beyond Service Desk guidance, Vectra can escalate into QSA, ASV, penetration testing or broader cybersecurity capability.
One Service. Two Stakeholders.

Designed for the programme owner and the merchant completing the work.

Acquirers & Payment Providers

A managed merchant PCI support capability

Vectra can operate the merchant-facing support layer on behalf of an acquiring bank or payment provider, helping make compliance programmes easier for merchants to navigate and simpler for internal teams to sustain.

  • Merchant onboarding and support
  • PCI DSS scoping and SAQ guidance
  • ASV scan assistance
  • Renewal and compliance-cycle support
  • Escalation to specialist PCI services
Merchants

Talk to people who can explain PCI DSS clearly.

If your acquiring bank or payment provider uses Vectra’s PCI DSS Service Desk, our team can help you understand your validation process, use the compliance portal, complete your SAQ and work through applicable ASV scanning.

  • Portal access and user assistance
  • SAQ selection and questionnaire guidance
  • Scoping and re-scoping support
  • ASV scan guidance and false-positive disputes
  • Annual renewal guidance
PCI DSS Merchant Support

The practical work that keeps a merchant programme moving.

Service Desk support focuses on helping merchants understand and complete the activities relevant to their PCI compliance pathway. Requirements vary by merchant environment, payment channel, acquirer and validation type.

01

Portal & account support

User provisioning, login guidance, password resets, contact updates and assistance navigating the merchant compliance portal.

02

Scoping & re-scoping

Help merchants describe how they accept payments and understand how changes to payment channels or technology can affect their PCI scope.

03

SAQ guidance

Assist merchants in identifying the appropriate Self-Assessment Questionnaire and understanding the questions and evidence relevant to their environment.

04

ASV scanning support

Guide merchants through external vulnerability scanning where required, including scan setup, results, remediation and false-positive dispute processes.

05

Compliance-cycle support

Provide renewal notifications and assistance as merchants return to the portal to complete their next annual validation cycle.

06

Specialist escalation

Connect more complex requirements with Vectra QSA, security testing, penetration testing, ASV and cybersecurity specialists when additional expertise is needed.

PCI Compliance Portal

Give merchants a structured path from registration to validation.

Vectra’s merchant programmes can combine the Service Desk with a secure PCI DSS compliance portal. The workflow gives merchants a clear place to manage their assessment activity while the Service Desk provides human support when questions arise.

The result is a simpler merchant experience: self-service where it makes sense, backed by specialist assistance when the process becomes unclear or technical.

01
Register & accessMerchant users access the programme portal using their registered contact details.
02
Confirm detailsReview company and merchant information relevant to the compliance process.
03
Determine pathwayWork through the relevant scoping and SAQ-selection process.
04
Complete assessmentAnswer the applicable SAQ and complete required supporting activities such as ASV scanning.
05
Validate & reportComplete applicable attestation and access available compliance outputs for the programme.
PCI DSS v4.0.1

Merchant support needs to reflect today’s PCI requirements.

PCI DSS v4.0.1 is the current version of the standard. The future-dated v4.x requirements became effective on 31 March 2025, increasing the importance of areas such as stronger authentication, e-commerce security, targeted risk analysis and evidence that controls operate throughout the year.

Not every requirement applies to every merchant or every SAQ. The Service Desk helps merchants understand the pathway relevant to their payment environment and when specialist advice is required.

E-commerce securityPayment-page scripts, integrity and change-detection obligations now require closer attention for applicable e-commerce merchants.
AuthenticationPCI DSS v4.x expanded multi-factor authentication and access-control expectations in applicable environments.
EvidenceCompliance increasingly depends on showing that security processes are operating—not simply confirming that a policy exists.
Risk-based frequenciesTargeted risk analysis supports specified activities where PCI DSS allows an organisation to determine frequency.
Changing SAQ eligibilityChanges to websites, payment providers, terminals or payment flows can affect the correct validation pathway and should trigger re-scoping.
Approved Scanning Vendor Support

External scanning without leaving merchants to decipher the result.

PCI DSS Requirement 11.3.2 requires passing external vulnerability scans by a PCI SSC Approved Scanning Vendor for applicable environments. For merchants that need ASV scanning, Vectra supports the process from setup through remediation and the next quarterly cycle.

That support is particularly valuable when a merchant receives a failing result and needs to understand what must change before the scan can pass.

Initial setupHelp establish the required external IP addresses or domains and configure the initial scanning workflow.
Quarterly scanningSupport merchants with the recurring scan cycle required for applicable PCI DSS environments.
Failure guidanceExplain identified vulnerabilities and the practical remediation required to move toward a passing result.
False-positive disputesGuide merchants through the supporting information required where an identified result may not apply.
Beyond the Service Desk

When a merchant needs more than questionnaire support, the expertise is already here.

A Service Desk should not try to turn every merchant question into a help-desk answer. Complex environments, Level 1 validation, segmentation, e-commerce architecture and technical failures sometimes need specialist assessment or engineering.

Vectra can keep those escalations inside one PCI and cybersecurity practice.

QSA assessmentFormal PCI DSS assessment, gap analysis, ROC and complex compliance advice. PCI Consulting →
ASV scanningPCI SSC-approved external vulnerability scanning and remediation support. ASV Scanning →
Penetration testingCREST-accredited testing for PCI DSS and broader security assurance requirements. Penetration Testing →
E-commerce securityGuidance around payment-page controls, scripts, change detection and applicable PCI DSS v4.0.1 requirements.
Cybersecurity remediationAccess to Vectra security specialists where merchants need technical support to address identified control weaknesses.
Why Vectra

A merchant Service Desk backed by real PCI depth.

Long-standing PCI experience

Vectra has supported payment-card security programmes since 2004 and became Australia’s first PCI SSC-certified QSA Company in 2006.

Australian-based support

Merchants can speak with local PCI DSS and QSA-trained staff rather than relying entirely on self-service content.

Merchant-friendly guidance

Translate PCI terminology into the practical actions a retailer, e-commerce business or other merchant needs to complete.

Technical escalation

Move seamlessly into QSA, ASV, penetration testing and cybersecurity expertise when a merchant issue needs deeper analysis.

Programme flexibility

Support merchant populations with different payment channels, SAQ pathways, technical maturity and compliance needs.

One accountable partner

Keep merchant support, compliance expertise and technical assurance connected rather than fragmented across multiple providers.

Existing merchant support
1800 558 522
PCI Service Desk email
support@vectrapci.com.au
PCI DSS Service Desk FAQs

Merchant PCI compliance support, explained.

What is a PCI DSS Service Desk?

A PCI DSS Service Desk is a specialist merchant-support function that helps merchants understand and complete their PCI compliance activities. Vectra’s service can include portal support, PCI scoping and re-scoping guidance, SAQ assistance, ASV scanning guidance, renewal notifications and escalation to specialist PCI services.

Can an acquiring bank outsource merchant PCI support to Vectra?

Yes. Vectra operates merchant-facing PCI DSS support on behalf of acquiring banks and payment providers, giving their merchants access to specialist PCI guidance while reducing the need for general internal support teams to interpret the standard.

Does Vectra help merchants choose and complete the correct SAQ?

Yes. The Service Desk can guide merchants through scoping and SAQ selection and help them understand the questions relevant to their payment environment. The final validation pathway is determined by the applicable payment programme, acquirer requirements and the merchant’s actual environment.

Does Vectra provide PCI DSS ASV scanning?

Yes. Vectra provides Approved Scanning Vendor services for applicable PCI environments, including scanning support, remediation guidance and assistance with false-positive dispute processes.

What is the difference between the PCI Service Desk and a QSA assessment?

The Service Desk helps merchants navigate their compliance process and self-assessment activities. A Qualified Security Assessor performs formal PCI DSS assessment and validation work where required. Vectra provides both capabilities, allowing complex questions to be escalated appropriately.

Is the Service Desk based in Australia?

Yes. Vectra’s PCI DSS Service Desk is Australian based and is operated by staff trained in PCI DSS and supported by Vectra’s wider QSA and cybersecurity teams.

What version of PCI DSS applies now?

PCI DSS v4.0.1 is the current active version of the standard. The future-dated v4.x requirements became effective on 31 March 2025. Which individual requirements apply to a merchant depends on its payment environment and validation pathway.

How do existing merchants contact the Vectra PCI Service Desk?

Existing merchants can contact the Vectra PCI DSS Service Desk on 1800 558 522 or support@vectrapci.com.au.

Merchant PCI Compliance at Scale

Give your merchants specialist PCI support without adding another internal support layer.

Talk to Vectra about operating a PCI DSS Service Desk and merchant compliance programme for your acquiring bank, payment business or merchant portfolio.

PCI DSS validation requirements, SAQ eligibility and merchant obligations depend on the applicable payment brand or acquiring-bank programme and the merchant’s payment environment. Vectra provides guidance based on the agreed service scope.