Skip to main content
FaizZab

Readiness assessment

PCI DSS v4.0.1 Readiness Assessment

Find scope, control and evidence gaps before formal PCI validation.

The business problem

Why organizations bring this to us

The most expensive discovery in a PCI validation is that the scope was wrong. Systems believed to be out of scope turn out to be connected, a segmentation control does not hold under testing, or account data is found in a location nobody assessed.

The second most expensive discovery is that the controls operate but cannot be evidenced across the required period. Both are found far more cheaply before validation than during it.

This assessment applies validation-style scrutiny to scope, controls and evidence, and returns a sequenced remediation plan aimed at the gaps that would actually cause a finding.

Who this is for

  • Organizations approaching a PCI validation cycle that want no surprises.
  • Businesses uncertain whether their declared scope reflects the real environment.
  • Companies that have changed payment channels, integrations or architecture since the last validation.
  • Organizations that struggled to produce evidence during a previous cycle.

Service scope

Assessment areas

The assessment is deliberately sceptical about declared scope and declared control operation, and tests both against evidence.

Validation Route Review

Confirm which validation route applies given merchant or service provider category, channels and volumes, so preparation is aimed at the correct requirements.

Scope Accuracy

Test the declared scope against discovered reality, including connected and security-impacting systems that are commonly omitted from scope statements.

CDE Boundary Challenge

Challenge the cardholder data environment boundary directly, looking for paths into the CDE that segmentation was assumed to close.

Payment Flow Validation

Validate documented payment flows against actual system behaviour, including refund, chargeback, support and exception paths that formal documentation typically omits.

Evidence Sufficiency

Sample the evidence set for recurring controls and assess whether it covers the required period, is retrievable, and demonstrates the control operated rather than merely existed.

Technical Control Weaknesses

Review configuration, patching, vulnerability management and monitoring control implementation for weaknesses likely to be identified during validation.

Access & Authentication Testing Readiness

Assess whether identity, authentication, multi-factor and privileged access controls are implemented consistently across in-scope components and can be demonstrated on request.

Monitoring Evidence

Test whether logging is complete across in-scope components, whether retention meets expectations, and whether review activity itself is evidenced.

Third-Party Dependencies

Identify service providers affecting account data security, review the responsibility split and confirm the required assurance has actually been obtained and is current.

Remediation Sequencing

Sequence remediation by validation impact and dependency, distinguishing what must be resolved before validation from what can follow.

Methodology

How the assessment runs

  1. Scope discovery

    Independently establish where account data lives and moves, rather than accepting the documented scope.

  2. Boundary and flow testing

    Challenge segmentation and validate payment flows against real system behaviour and configuration.

  3. Control review

    Review implementation of technical and process controls across a sample of in-scope components.

  4. Evidence sampling

    Request the evidence a validation would require and assess coverage, retrievability and sufficiency.

  5. Findings and sequencing

    Classify findings by validation impact and deliver a sequenced remediation plan with owners.

What you receive

Key deliverables

  • Validation route confirmation and applicable requirement set
  • Independent scope determination compared against declared scope
  • CDE boundary challenge findings
  • Validated payment flow maps including exception paths
  • Evidence sufficiency results by control area
  • Technical control weakness findings
  • Access and authentication readiness findings
  • Logging and monitoring coverage assessment
  • Third-party dependency and responsibility findings
  • Sequenced remediation plan with pre-validation priorities

Outcome

Enter PCI validation knowing where the real exposure sits.

Commercial value

Why this service matters

Scope surprises are the biggest risk

A scope correction discovered during validation can add months and significant cost. Finding it early is materially cheaper.

Evidence coverage takes time to fix

Evidence gaps covering a past period often cannot be remediated retroactively, so early discovery is the only remedy.

Predictable validation

Entering validation with a known position protects budget, timelines and the relationship with payment partners.

Questions

Common questions

Does this produce an Attestation of Compliance?

No. A readiness assessment is a preparation exercise. Formal validation and any resulting attestation must follow the applicable PCI SSC programme requirements and, where required, be performed by an appropriately qualified assessor.

Do you perform the penetration testing?

The assessment reviews the testing programme, its coverage and remediation tracking. Penetration testing itself is a separate specialist engagement and is scoped independently.

How current does the evidence need to be?

Evidence sampling targets the period a validation would examine. Where coverage gaps exist in a past period, the remediation plan addresses both the immediate position and the process change needed to prevent recurrence.

Related

Related services

View all services
ImplementationAVAILABLE NOW

PCI DSS Implementation

Implementation support for PCI DSS v4.0.1 - scope definition, cardholder data environment design, payment data flow mapping, segmentation, secure configuration, access control, vulnerability management, logging and the compliance evidence programme.

Explore this service
Audit supportAVAILABLE NOW

IT Audit

Independent IT audit covering IT general controls, access controls, change management and IT operations, with structured evidence testing, findings and tracked remediation.

Explore this service
Readiness assessmentAVAILABLE NOW

ISO 27001 Readiness Assessment

An evidence-based benchmark of your existing ISMS against ISO/IEC 27001:2022 certification expectations - clause and Annex A readiness, documentation sufficiency, evidence sampling, and a prioritized 30/60/90-day remediation roadmap.

Explore this service
AdvisoryAVAILABLE NOW

Cybersecurity Governance

Design and implementation of security governance - governance structure and accountability, policy architecture, risk oversight, security metrics and management visibility.

Explore this service

Important

Formal validation must follow applicable PCI SSC programme and qualified-assessor requirements where relevant. FaizZab does not claim QSA status unless formally obtained. This readiness assessment is not a formal PCI DSS assessment and does not produce an Attestation of Compliance.

Find out where you actually stand

Tell us your obligation, your timeline and where you are today. We will confirm whether this is the right engagement for you.