Skip to content

Solutions / By mandate

ISO 27001 & PCI DSS

Certification and compliance support that produces the artefacts your auditor signs off, not a list of things to fix.

What you receive

  • Gap assessment and remediation plan
  • Statement of Applicability support
  • Evidence pack assembly
  • Auditor liaison

When you need this

Three situations that call for it. If none of them is yours, it probably is not the right spend.

  • 01

    A deal is blocked on a certificate you lack

    Procurement increasingly treats ISO 27001 as a gate. Certification runs Stage 1 on documentation and Stage 2 on implementation, and clauses 9.2 and 9.3 mean an internal audit and a management review have to exist for the auditor to sample first.

  • 02

    Your PCI scope has quietly grown

    Everything that stores, processes or transmits account data is in scope, along with anything connected to it or able to affect its security. Segmentation is the only thing that genuinely shrinks that, and Requirement 11.4.5 makes you test the segmentation.

  • 03

    Your acquirer has moved you to a full ROC

    Validation level is set by the acquirer and the card brands, not by the Council. A Report on Compliance tests every applicable requirement against evidence, and the heaviest of that evidence sits in Requirement 10 logging and Requirement 3 key management.

How it runs

  1. 01

    Where you actually are

    A working session to establish what is already in place and what your regulator, your auditor or your board is going to ask for. Usually the gap is narrower than feared and differently shaped.

  2. 02

    What the obligation really requires

    We separate what the text mandates from what a consultancy has told you it mandates. Several of the controls sold against these regimes are not required by them.

  3. 03

    A scoped programme

    The specific modules and engagements that close the gap, sequenced by what your deadline is and what depends on what — not by what is easiest to sell you.

  4. 04

    Evidence, not a gap report

    The output is the artefact your assessor accepts: test results, control evidence and a record of what changed. A document describing your gaps is not evidence that you closed them.

No lock-in

Scoping costs nothing and carries no obligation. If the answer is that you do not need this, that is a legitimate outcome of the call.

Who turns up

The engineer on your scoping call is on the delivery team. We do not hand you to a different group after signature.

Scope

What this does not cover

  • Certification decisions rest with the accredited certification body, and the Report on Compliance is signed by the assessor of record.

  • Clause 9.3 puts the management review with your own top management, and that cannot be delegated to an adviser. An internal audit under clause 9.2 can be outsourced, but only to someone with no part in what is being audited — which rules us out wherever we built the control.

  • SOC 2, TISAX and sector schemes are not covered here — each has its own auditor, evidence model and reporting period.

Measured against

ISO/IEC 27001:2022
Certifies an ISMS within a defined scope; clause 6.1.3 requires a Statement of Applicability justifying inclusions and exclusions.
PCI DSS 4.0.1 Req. 11.4
Requires internal and external penetration testing at least every 12 months, plus separate testing of segmentation controls.

If the scope is wrong

Tell us on the call. Re-scoping before we start costs nothing; discovering it at the readout costs you the engagement.

Questions

The ones we are actually asked.

Does certification mean we are secure?

No. ISO 27001 certifies that a management system meets the standard inside a stated scope, and the auditor samples rather than tests everything. It says something about process discipline, not about whether an attacker gets in.

Can we reuse ISO 27001 evidence for PCI DSS?

Some of it. Access control, logging and change management overlap, but PCI DSS prescribes parameters and frequencies where ISO 27001 asks you to justify your own. Most of the evidence needs re-cutting rather than re-labelling.

How small can we make the PCI scope?

Small enough that account data touches few systems, though connected-to and security-impacting systems come with it. Hosting the payment form elsewhere helps, and how far it helps depends on how you validate — the revised SAQ A turned the payment-page script requirements into an eligibility condition you confirm rather than a control you evidence. Either way the scripts on the page you serve are the exposure, whoever is asking about them.

Next step

See what an attacker sees

We map your external attack surface the way an adversary does — exposed assets, leaked credentials, impersonation domains. No agent, no access, no cost.

30 min

A scoping call, with an engineer rather than a sales rep.

What it costs

Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.

Under attack now?

Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.