The Payment Card Industry Data Security Standard (PCI DSS) is a global standard that protects cardholder data. It applies to any organization that stores, processes or transmits payment card information.
Compliance is mandated by the card brands through your acquirer. PCI DSS v4.0.1 is the only active version — v3.2.1 retired on 31 December 2024, and every requirement previously marked future-dated became mandatory on 31 March 2025.
Two roles are formally defined by the PCI Security Standards Council and cannot be performed by anyone else: a Qualified Security Assessor (QSA) signs the Report on Compliance and the Attestation of Compliance, and an Approved Scanning Vendor (ASV) performs the quarterly external scans under Requirement 11.3.2. Cetonix is neither a QSA nor an ASV. We do not sign Attestations of Compliance and we do not perform the quarterly ASV scans. What we do is get you ready for the assessment and deliver the Requirement 11.4 penetration testing, working alongside the QSA and ASV you appoint. If a vendor tells you they can certify your PCI DSS compliance without QSA registration, check their listing on the PCI SSC website before you sign anything.
Requirement 11.3 covers vulnerability scanning. Requirement 11.4 covers penetration testing. They are distinct requirements and an assessor will expect evidence of both. A scan report is not a penetration test, and any vendor that sells you one as the other is setting you up for a finding.
E-commerce merchants, payment service providers and gateways, SaaS platforms that touch cardholder data, and any service provider whose customers have placed them in PCI DSS scope.
Tell us the standard, the framework or the application. We come back with scope, timeline and a fixed quote.