What you need to know
- A named compliance consultant, not a portal link
- Correct SAQ scoped to how you actually take cards
- Quarterly ASV scanning with remediation included
- Segmentation that shrinks audit scope
- Non-compliance fees removed from your statement
- Breach protection program on every account
Step one: scope the cardholder data environment
Scope is everything. Every system that stores, processes or transmits cardholder data, plus anything connected to those systems, falls inside the assessment. An unsegmented flat network drags your back-office PC, your guest Wi-Fi and your camera recorder into scope with it.
We inventory the environment, map data flows from swipe to settlement, then segment aggressively so the assessed footprint is as small as it can honestly be.
Step two: the right SAQ, completed with a human
Picking the wrong questionnaire is the most common merchant mistake, usually attesting to SAQ A when an integrated POS actually requires SAQ C or B-IP. A false attestation is worse than none, because it voids safe-harbor arguments after an incident.
Our consultant walks the questionnaire with you line by line, documents compensating controls where needed, and files the attestation with your acquirer.
Step three: quarterly scanning and remediation
Approved Scanning Vendor scans run every quarter against your external IP addresses. Failures are not paperwork. They are open ports, expired TLS, default credentials and unpatched firmware. We remediate them as part of the managed IT engagement and re-scan until the report passes clean.
Step four: keep the evidence current all year
Compliance is annual on paper and continuous in practice. Firewall rule reviews, user access lists, patch records, training logs and scan reports are archived as they happen, so next year's attestation is a review rather than a scramble, and if you are ever asked to produce evidence after an incident, it already exists.