PCI DSS v4.x Gap Assessment and Scoping
Cardholder data environment scoping and a gap assessment against PCI DSS v4.0.1, including the requirements that became mandatory in 2025.
Start in the portal
Sign in, complete the intake form for this service, then pay the engagement fee before submitting. You can save a draft so your answers are not lost.
- Standard
- 5 business days
Regulatory and standards basis
This engagement is performed against the following instruments. Each is cited in the deliverable at the point it is relied on.
- PCI DSS v4.0.1
- PCI SSC scoping and segmentation guidance
Who this is for
- Payment processors
- Merchants and service providers handling card data
What you receive
- 01Cardholder data environment scope definition and data-flow diagrams
- 02Gap assessment against all applicable requirements
- 03Segmentation assessment and scope-reduction opportunities
- 04Remediation roadmap sequenced for assessment readiness
How the engagement runs
Phase 1
Intake
You complete a structured intake form and upload supporting documents. Autosaved, so it can be finished across several sittings.
Phase 2
Evidence review
We review what you have provided and raise a document request list for anything material that is missing. We do not guess at gaps.
Phase 3
Analysis and drafting
Your documents and answers are assessed against the applicable control universe. Findings are recorded with an evidence reference or explicitly flagged as an assumption.
Phase 4
Quality review
A named reviewer works through every finding and section, and a partner approves. Their name and credentials appear on the report.
Phase 5
Delivery
The deliverable is released in the portal within 5 business days of payment. Two revision rounds are included.
Accreditation disclosure
Qantid performs scoping, gap assessment and remediation. A Report on Compliance is issued only by a PCI SSC-registered Qualified Security Assessor.
Questions
Who approves the deliverable?
A named member of the engagement team reviews it and a partner approves it. Their name, title and credentials are printed on the report, and the approval is recorded against the engagement in the portal.
What happens if we disagree with a finding?
You raise a review from the deliverable page, selecting the specific finding or assumption you are challenging and attaching supporting evidence. Two revision rounds are included. Factual corrections and any error on our side never count against those rounds and are never billed.
How quickly can this be turned around?
Standard delivery is 5 business days from payment. Express delivery in 48 to 72 hours is available at a 75% uplift.
Where do our documents live?
In private storage, accessible only through short-lived signed links, with every view and download logged. Nothing is attached to email. Our security posture and data residency are published on the trust page.
How do we pay?
Sign in to the portal, choose this service, complete the intake form, then pay by card through Stripe. You can save a draft at any time before payment.
Related engagements in Cybersecurity and Assurance
Business Continuity and Disaster Recovery Plan
Continuity and recovery planning built from a business impact analysis, with recovery objectives that reflect what your infrastructure can actually deliver.
CBN Risk-Based Cybersecurity Framework Assessment
An assessment against the CBN Risk-Based Cybersecurity Framework, producing the evidence base for your annual return.
Incident Response Plan and Playbooks
An incident response plan with scenario playbooks, written so an on-call engineer at 3am can follow it.