Locking Trust Logo
PCI DSS v4.0

Secure Every
Transaction.

We help merchants and service providers secure cardholder data, navigate SAQs, and achieve full ROC compliance under the new v4.0 standards.

Who Needs PCI DSS?

If you accept, process, store, or transmit credit card data, you must be compliant. The strictness of the audit depends on your annual transaction volume.

Non-Compliance Risks

  • Monthly fines up to $100,000
  • Higher bank transaction fees
  • Revocation of card acceptance privileges
L1

Level 1 Merchants

6M+ txns/year

Requires an onsite audit by a QSA (Qualified Security Assessor) & a Report on Compliance (ROC).

L2

Level 2 - 3

20k - 6M txns/year

Generally requires a Self-Assessment Questionnaire (SAQ) signed by an officer.

L4

Level 4

< 20k txns/year

Small merchants using third-party processors. Requires SAQ.

The 12 Requirements

Goals of Compliance

PCI DSS covers 6 goals across 12 specific requirements. We help you implement all of them.

Secure Network

Firewalls, Router Configs, No Vendor Defaults.

Protect Data

Encryption at rest and in transit across open networks.

Vulnerability Mgmt

Anti-Virus updates, Secure Coding practices.

Access Control

Need-to-know restrictions, Unique IDs, Physical security.

Monitoring

Track all access to data, Regular testing (VAPT).

Policy

Information Security Policy maintenance and reviews.

The Journey

Path to Compliance

We streamline the journey from gap analysis to attestation.

1

Scope Definition

Isolate the Cardholder Data Environment (CDE) to reduce audit scope.

2

Gap Assessment

Identify areas where you fail the 12 requirements.

3

Remediation

Fix vulnerabilities, segment networks, and encrypt data.

4

ASV Scanning

Mandatory quarterly external scans by an Approved Scanning Vendor.

5

Validation (SAQ/ROC)

Complete the Self-Assessment or undergo onsite QSA audit.

6

Attestation (AOC)

Submit the Attestation of Compliance to your acquirer/bank.

Determine Your SAQ Type.

Not sure if you need SAQ-A, SAQ-D, or a full ROC? We help you scope your environment correctly to save time and money.