Attestation, assessment and label schemes
PCI DSS:v4.0.1
A prescriptive control standard for anyone storing, processing or transmitting cardholder data. Validation produces a Report on Compliance and a signed Attestation of Compliance, submitted to acquirers and brands.
What you receive
Report on Compliance and Attestation of Compliance
Assessed only by a Qualified Security Assessor company listed by the PCI Security Standards Council. No PCI DSS certificate exists — anyone selling one is misrepresenting the scheme.
This scheme does not produce a certificate. If a body has offered you one for PCI DSS, that alone tells you what their audit work is worth.
Who needs it
Merchants and service providers in the card flow. Validation level is set by transaction volume and by your acquirer, not by preference.
Prerequisites
A defined cardholder data environment. Scope reduction through segmentation is usually the largest single cost lever.
How this engagement is delivered
Audited by Securo Cert LLC. Certification decision rendered by the appointed partner body.
Securo Cert document not accreditedThe partner body is named in the proposal before any work begins, and printed on the resulting document alongside the delivery mode.
Frequent questions
Will we get a PCI DSS certificate?
No, because no such thing exists. Validation produces a Report on Compliance and a signed Attestation of Compliance. Any body offering a PCI DSS certificate is either confused or counting on you being confused.
Who decides our validation level?
Your acquirer and the card brands, based on annual transaction volume. It is not a choice you make.
What is the biggest cost lever?
Scope. Segmenting the cardholder data environment so fewer systems are in scope reduces assessment effort more than any other single decision, and the saving recurs annually.
Does tokenisation remove us from scope?
It reduces scope, it rarely eliminates it. The systems that transmit card data to the tokenisation provider remain in scope, as does the integration itself.