Compliance/04 - PCI DSS

PCI DSS, scoped down before it is worked through.

The cheapest PCI programme is the one with the smallest cardholder data environment. We shrink the scope first, then evidence what is genuinely left - and run the annual test the standard names outright.

  • Scope reduction first - segmentation, tokenization, and getting systems out of the CDE
  • The right SAQ for how you actually take payments, or a Report on Compliance if you need one
  • Requirement 11.4 penetration testing already inside your flat plan
Trusted by teams shipping in regulated markets
EchoWin
Maru AI
Naked Denver
Weird Gloop
Destination Dutchess
EchoWin
Maru AI
Naked Denver
Weird Gloop
Destination Dutchess
EchoWin
Maru AI
Naked Denver
Weird Gloop
Destination Dutchess

Every system you remove from scope is a system you never evidence again.

PCI cost scales with the size of the cardholder data environment. Most programmes start by working through 12 requirements against an environment that should have been half the size.

Scope reduction before control work

Segmentation, tokenization, and moving card capture to a compliant processor take systems out of the CDE entirely. Cheaper than evidencing them forever.

- smallest defensible CDE

The right validation path

The SAQ you qualify for depends on how you actually take payments. Filling in the wrong one is worse than useless - we determine it against your real flows.

- SAQ type - or full RoC

Requirement 11.4 is our day job

PCI names penetration testing explicitly - annually and after significant change, internal and external, plus segmentation testing. That is the work we already do for you.

- 11.4 - included in plan

Quarterly, not annual

ASV scans quarterly, log review continuously, and the customized-approach documentation v4 asks for. PCI has more recurring obligations than any other framework we run.

- quarterly ASV - continuous logs

The twelve requirements, in six goals.

Everything in PCI hangs off one prior question: what is in your cardholder data environment? Answer that well and the twelve requirements shrink with it.

Build and maintain a secure network

req 1-2

Network security controls and secure configuration for all system components - no vendor defaults left in place.

Protect account data

req 3-4

Storage protections for stored account data and strong cryptography for cardholder data in transit across open networks.

Maintain a vulnerability management programme

req 5-6

Malware protection, and secure development and maintenance of bespoke and custom software.

Implement strong access control

req 7-9

Need-to-know restriction, identification and authentication including MFA, and physical access restrictions.

Monitor and test networks

req 10-11

Logging and monitoring of all access, plus the regular testing programme - ASV scans, internal and external penetration testing, and segmentation validation.

Maintain an information security policy

req 12

Organizational policies and programmes, including the targeted risk analyses v4 introduced for customized approaches.

We scope to PCI DSS v4.0.1, including the future-dated v4 requirements that are now in force. Your merchant level and validation path - SAQ versus Report on Compliance - depend on transaction volume and your acquirer, and we confirm both before any control work starts.

From scoping call to attestation.

Two phases are gated - CDE scoping and attestation. Scope is gated because every mistake there multiplies across twelve requirements and then recurs every year.

Phase 01 - gated

Define and shrink the CDE

We trace every card data flow, identify connected systems, and take everything we can out of scope through segmentation, tokenization, or redirecting capture to the processor.

CDE defined - scope reduced
Phase 02

Fix the validation path

Merchant level, acquirer expectations, and the right SAQ - or a Report on Compliance with a QSA. We confirm this before control work so nothing gets evidenced twice.

Level confirmed - path set
Phase 03

Work the twelve requirements

Controls implemented and evidenced against the reduced scope, with quarterly ASV scans, log review, and the annual penetration and segmentation testing running on schedule.

Requirements evidenced - scans passing
Phase 04 - gated

Attest and stay attested

We assemble the evidence, complete the SAQ or support the QSA through the RoC, and produce the Attestation of Compliance - then keep the recurring obligations running.

AOC signed - obligations scheduled
Pricing

PCI DSS is $3,000 a year.
The security department is the rest.

Every other vendor in this category makes you book a demo to learn what PCI DSS costs. Here it is. Your whole security department is one flat price, and compliance is the only thing we bill per framework.

Startup plan + PCI DSS
$20,000 / year

For companies under $5M revenue or 50 staff. The whole department, included.

  • Penetration testing
  • Vulnerability management
  • Monitoring & detection 24/7
  • Incident response
  • Compliance & GRC support
  • A named human on call
  • The Sythe Labs platform, run by us
+ $3,000 / yr for PCI DSS - scoping, evidence, gap closure, and the path to a signed Attestation of Compliance. Add other frameworks at the same rate, only when you need them.
Book a call
Enterprise
Custom

Over $5M revenue or 50 staff. Negotiated to your scale and obligations.

  • Everything in Startup
  • Dedicated security lead
  • Custom SLAs & response times
  • Audit & board reporting
  • Scaled to your headcount
  • Procurement & MSA support
Talk to us
IncludedRequirement 11.4 mandates annual internal and external penetration testing plus segmentation testing. That is in the flat plan, not a separate engagement you get billed for.
Compliance billed per framework - no per-seat fees, ever. Auditor and certification-body fees are billed by them, not by us.

The people who already handed it over.

"Jarred, Andrew, and their team are trusted partners - extensive penetration testing, code analysis, and security reviews that protect our users. We share a vision of prioritizing customer security above all else."
EchoWin
"Sythe Labs was great to work with. Extremely knowledgeable, responsive, and trustworthy. I'd recommend them to anyone looking for security or penetration testing."
Maru AI
"The strategic security recommendations from Sythe Labs have been invaluable. Their expertise helped us put real protection in place while keeping us moving fast."
Naked Denver

PCI DSS, honestly answered.

The questions that come up on every PCI DSS scoping call, answered before you have to ask them.

Do we need a QSA?
It depends on merchant level and what your acquirer demands. Many companies validate with a Self-Assessment Questionnaire; larger volumes or a service provider role can require a QSA-led Report on Compliance. We confirm which applies before doing any control work.
Which SAQ do we fill in?
That is determined by how you take payments - whether card data touches your systems at all, whether you redirect to a processor, whether it is card-present. Using the wrong SAQ is a common and expensive mistake, so we determine it from your real payment flows.
Can we get out of scope entirely?
Rarely entirely, but often dramatically. Moving card capture to a hosted payment page or tokenizing early removes whole systems from the CDE. That work usually pays for itself in the first year.
Is the penetration test extra?
No. Requirement 11.4 mandates annual internal and external penetration testing plus segmentation testing, and your flat plan already includes penetration testing. That is a meaningful part of why our PCI programme costs what it does.
How often do the obligations recur?
PCI is the most recurring framework we run: quarterly ASV scans, annual penetration and segmentation testing, continuous log review, and annual revalidation. We schedule and run them rather than reminding you to.

Shrink the scope before you work the requirements.

A 30-minute call. We will trace where card data actually flows, tell you what can come out of scope, and price the real path to an AOC - whether or not you hire us.