PCI Audits can be intimidating
Using over 20 years of auditing experience, we’ve crafted a process that simplifies and streamlines your work. SecurityMetrics participates in the PCI Council’s GEAR meetings and holds credentials like: QSA, QPA, PFI, ASV, CISSP, HCISSP, CISA, HITRUST CSF Assessor.
PCI DSS Assessment Features
Your PCI DSS Assessment includes:
A PCI audit coordinator to help ensure you hit deadlines on time.
Proper PCI scoping to help you avoid potential roadblocks
Software to help you never miss another PCI audit task.
A focus to help you pass your PCI audit the first time.
A QSA that pays attention to you so you can get your needs addressed quickly.
Auditors that aren't overbooked so you can get the attention you deserve.
Pre-audit consulting to help you know what's needed to pass your audit.
A QSA that will help you understand how changes affect your PCI compliance now and moving forward.
![](https://cdn.prod.website-files.com/672118d386a0ee61ef1d8ee1/677ef65acddee7f61389e504_braintree-pci-audit-pass-on-schedule.png)
Get key insights from our team of PCI experts
Pass your PCI audit on schedule
Identify and solve your security needs
Benefit from a custom audit experience based on SecurityMetrics’s years of experience and comprehensive scoping process. With an in-depth understanding of the PCI 4.0 landscape and assessment methods, you can experience responsive guidance before, during, and after your PCI assessment.
Learn from an expert QSA perspective
Be confident in your PCI assessment, knowing that SecurityMetrics QSAs continuously study the latest security trends, so you don’t have to. SecurityMetrics QSAs have completed thousands of PCI DSS audits over the years, ensuring you won’t just get a surface-level assessment. With the full attention of the SecurityMetrics team, you will experience the peace of mind that your issues and vulnerabilities will be addressed and deadlines met.
Get the advice you need with PCI consulting
If you’re not ready for a PCI assessment but want to speak to an expert about your environment, SecurityMetrics now offers PCI Consulting. When you partner with SecurityMetrics for a PCI Consultation, you get:
- The latest PCI v.4.0 advice
- Scope Reduction Consulting
- PCI Gap Analysis (as part of our consulting)
- Reports with answers to your specific questions
SecurityMetrics QSAs are seasoned professionals with extensive experience in all aspects of PCI, so you can ask in-depth questions and get insightful advice.
Enjoy an on-time PCI 4.0 audit
You shouldn’t have to feel stressed about a looming PCI assessment deadline. SecurityMetrics provides you with a robust project management tool to keep everyone on task and help you:
- Stay organized by ordering messages and tasks by the requirement they are associated with.
- See which stage you’re at in your assessment using the project visualization tool.
- Download reports from your QSAs.
- Assign team members specific tasks as their administrator, leaving comments on tasks so everyone is informed.
- Guide your efforts to close your compliance gaps and prepare for your compliance validation assessment.
Stop shopping cart eskimming
Make PCI compliance a breeze with SecurityMetrics Shopping Cart Monitor. Monitor helps you comply with PCI requirements 6.4.3 and 11.6.1. Monitor uses SecurityMetrics Award-winning and patented Webpage Integrity Monitoring Technology. This means less worry and faster PCI compliance.
PCI Assessment Timeline Steps
01
Gap analysis
During this phase, knowledgeable SecurityMetrics QSAs complete an initial gap analysis of your organization's compliance status. After the gap analysis is completed, feedback and remediation checklist items will be shared with you in our online project management tool. Your SecurityMetrics QSAs are dedicated to helping you reach compliance and become fully secure, not to make you feel guilty for any gaps you might have.
02
PCI validation assessment
Your QSA will either work with you remotely to collect evidence or make an in-person visit to your location to assess your compliance to the PCI DSS standard. Your SecurityMetrics audit coordinator makes sure you meet deadlines by moving along your assessment in a timely manner.
03
Remediation and retesting
SecurityMetrics QSAs work with you to fix areas of non-compliance, expediting the retesting process to ensure a timely assessment.
04
Submitting Your AOC and ROC
After remediation and retesting, SecurityMetrics will submit your attestation of Compliance (AOC) and Report on Compliance (ROC) to any required parties, such as the card brand or merchant bank.
![](https://cdn.prod.website-files.com/672118d386a0ee61ef1d8ee1/677ef665e013ce8a6a523c43_braintree-pci-audit-timeline.png)
SecurityMetrics QSAs have performed 2000+ audits, mastering the audit process
Ready for PCI DSS solutions?
Request A QuotePCI DSS Compliance FAQs
How much time does a PCI assessment take?
If you involve a third-party QSA, this likely means you have a more complex environment or more transactions.
If it’s your first time receiving a PCI audit, you are likely looking at a three-month to a year-long process, depending on readiness. This is due to the discovery process and the significant change it presents to your environment.
There are also customers who have tight deadlines and who are willing to do the hard work of preparation and may be closer to the three-month mark.
How can I increase my likelihood of passing my PCI DSS assessment?
You need vulnerability scanning requirements in hand in order to pass your audit. To pass, you need four quarterly scans and for these to meet compliance requirements. Your audit is done to help you continuously get quarterly passing scans. Make sure you are using an approved scanning vendor for your scans and follow up quickly if you fail a scan.
What is an SAQ for PCI validation?
SAQ stands for self-assessment questionnaire. Depending on an organization’s card transaction volume and the types of transactions it performs, it may be able to use an SAQ to self-evaluate its compliance with the PCI Data Security Standard.
SAQs contain questions about card data security. SAQs range in size from 22 questions (SAQ A) to 329 questions (SAQ D).
How much does a PCI assessment cost?
A PCI assessment can range widely in cost. On the low end, a PCI audit can cost 16-18K. Audits can also cost tens to hundreds of thousands of dollars depending on how many locations you have, how many parties need to be audited, how complex your network is, and so forth.
Even a short call with a SecurityMetrics representative can give you a more accurate estimate of what a PCI audit would cost you.
Does my payment solution make me PCI compliant?
Sometimes people think that if they have the right solution, they will be PCI compliant. No matter what solution you choose, you will still be missing requirements, even if you use point-to-point encryption.
Depending on which SAQ you are, there are even more requirements. Your staff will also need systems in place to help them meet policies and procedures.
Resources
The following are related resources that we have prepared for you. Find more answers to your questions in our Learning Center.