A Level 1 PCI DSS assessment includes a detailed review by a Qualified Security Assessor (QSA). The assessor examines evidence, interviews staff, and documents the findings in a Report on Compliance (ROC).
Our PCI DSS work includes initial scoping, remediation, QSA coordination, and annual re-attestation. We prepare the client team and evidence throughout the assessment; the QSA performs the assessment and completes the ROC.
Defining the assessment scope
The cardholder data environment defines the audit's boundaries. Every system that stores, processes, or transmits card data falls in scope, along with everything connected to it. Early work includes reviewing network segmentation and whether each system needs access to card data. These early scope decisions determine how much evidence and remediation work the assessment requires.
Records the assessor reviews
The assessor reviews patch records, scan reports, and change tickets sampled across the audit period. We build evidence collection into routine operations so staff can retrieve those records during the assessment. Missing records may require staff to reconstruct work from older tickets and logs.
Allowing time for remediation
A gap assessment may identify firewall rules to justify, encryption to upgrade, logging to centralize, and access to revoke. Allow months for this phase and review dependencies between the fixes. A fix in one area often exposes a gap in another. A two-week remediation sprint may leave too little time to resolve those dependencies.
Working with the QSA
We join assessment interviews, answer questions, and raise known gaps with the QSA. Organized evidence helps the assessor verify the controls. When a control needs work, we explain the gap and the remediation plan.
Annual re-attestation
Annual re-attestation requires continued evidence that controls operate between assessments. We maintain those controls and records as part of daily operations.