ISO 27001 & PCI DSS
Certification and compliance support that produces the artefacts your auditor signs off, not a list of things to fix.
What you receive
- Gap assessment and remediation plan
- Statement of Applicability support
- Evidence pack assembly
- Auditor liaison
When you need this
Three situations that call for it. If none of them is yours, it probably is not the right spend.
A deal is blocked on a certificate you lack
Procurement increasingly treats ISO 27001 as a gate. Certification runs Stage 1 on documentation and Stage 2 on implementation, and clauses 9.2 and 9.3 mean an internal audit and a management review have to exist for the auditor to sample first.
Your PCI scope has quietly grown
Everything that stores, processes or transmits account data is in scope, along with anything connected to it or able to affect its security. Segmentation is the only thing that genuinely shrinks that, and Requirement 11.4.5 makes you test the segmentation.
Your acquirer has moved you to a full ROC
Validation level is set by the acquirer and the card brands, not by the Council. A Report on Compliance tests every applicable requirement against evidence, and the heaviest of that evidence sits in Requirement 10 logging and Requirement 3 key management.
How it runs
Where you actually are
A working session to establish what is already in place and what your regulator, your auditor or your board is going to ask for. Usually the gap is narrower than feared and differently shaped.
What the obligation really requires
We separate what the text mandates from what a consultancy has told you it mandates. Several of the controls sold against these regimes are not required by them.
A scoped programme
The specific modules and engagements that close the gap, sequenced by what your deadline is and what depends on what — not by what is easiest to sell you.
Evidence, not a gap report
The output is the artefact your assessor accepts: test results, control evidence and a record of what changed. A document describing your gaps is not evidence that you closed them.
No lock-in
Scoping costs nothing and carries no obligation. If the answer is that you do not need this, that is a legitimate outcome of the call.
Who turns up
The engineer on your scoping call is on the delivery team. We do not hand you to a different group after signature.
Scope
What this does not cover
Certification decisions rest with the accredited certification body, and the Report on Compliance is signed by the assessor of record.
Clause 9.3 puts the management review with your own top management, and that cannot be delegated to an adviser. An internal audit under clause 9.2 can be outsourced, but only to someone with no part in what is being audited — which rules us out wherever we built the control.
SOC 2, TISAX and sector schemes are not covered here — each has its own auditor, evidence model and reporting period.
- ISO/IEC 27001:2022
- Certifies an ISMS within a defined scope; clause 6.1.3 requires a Statement of Applicability justifying inclusions and exclusions.
- PCI DSS 4.0.1 Req. 11.4
- Requires internal and external penetration testing at least every 12 months, plus separate testing of segmentation controls.
If the scope is wrong
Tell us on the call. Re-scoping before we start costs nothing; discovering it at the readout costs you the engagement.
Questions
The ones we are actually asked.
Does certification mean we are secure?
No. ISO 27001 certifies that a management system meets the standard inside a stated scope, and the auditor samples rather than tests everything. It says something about process discipline, not about whether an attacker gets in.
Can we reuse ISO 27001 evidence for PCI DSS?
Some of it. Access control, logging and change management overlap, but PCI DSS prescribes parameters and frequencies where ISO 27001 asks you to justify your own. Most of the evidence needs re-cutting rather than re-labelling.
How small can we make the PCI scope?
Small enough that account data touches few systems, though connected-to and security-impacting systems come with it. Hosting the payment form elsewhere helps, and how far it helps depends on how you validate — the revised SAQ A turned the payment-page script requirements into an eligibility condition you confirm rather than a control you evidence. Either way the scripts on the page you serve are the exposure, whoever is asking about them.
See what an attacker sees
We map your external attack surface the way an adversary does — exposed assets, leaked credentials, impersonation domains. No agent, no access, no cost.
30 min
A scoping call, with an engineer rather than a sales rep.
What it costs
Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.
Under attack now?
Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.