If your company stores, processes, or transmits credit card data, PCI DSS applies to you. The standard covers 12 requirement areas, including network security, access controls, encryption, and monitoring.
A PCI compliance audit is how you prove it. Depending on your transaction volume and environment, that means completing a Self-Assessment Questionnaire (SAQ) or going through a formal review with a Qualified Security Assessor (QSA).
All assessments now follow PCI DSS 4.0, which became the only active version in March 2024 when version 3.2.1 was retired.
Any organization that stores, processes, or transmits payment card data has PCI DSS obligations. Companies that typically need to get this sorted:
Our Reviews
Co-Founder Brick Towers AG
Expectation for an expected timeline was given and also adhered to which helped us a lot to manage expectations with our prospects. Decrypt accommodated our additional input to the draft audit report which helped us to stand out.
CEO, Tillion.ai
CEO, Leen Inc
CEO · jumbomail.me
Mid-Market
Small Business
Small Business · France
Our Latest Articles
PCI DSS 4.0 is the current version and applies to all assessments. The main changes that affect most companies include stronger multi-factor authentication requirements across more system access points, expanded requirements around web-facing application security, and a shift toward targeted risk analysis for certain controls rather than fixed implementation timelines.
Yes. Using Stripe or Square reduces your scope but doesn't eliminate your obligations. You still need to attest to the requirements that cover your environment, usually through a simpler SAQ. Decrypt maps your scope first so you're not working through requirements that don't apply.
An SAQ is completed by merchants and service providers with lower transaction volumes or limited CDE exposure. A QSA engagement involves a third-party assessor validating controls directly. Which applies depends on your setup and what your card brand or acquirer requires.
For companies with a well-scoped CDE and existing controls, an SAQ-based assessment can move in weeks. More complex environments take longer. Decrypt sets timeline expectations at the start.
Most clients start here. Decrypt maps your environment, identifies the right SAQ type, and walks through the requirements with you. No prior PCI knowledge needed.
Yes. If you have prior gap work or documentation already in progress, Decrypt picks up from where things stand.
Yes. Decrypt also conducts SOC 2 Type I and II audits, ISO 27001 certification, and ISO 42001 assessments. If you need more than one framework, evidence collection overlaps instead of doubling up.
Get Started
Tell us about your company and we’ll get back to you with a clear path to certification – including timeline and pricing.