If you accept card payments instore or online, your business must comply with the latest PCI DSS (Payment Card Industry Data Security Standard) framework which protects your customers’ information when they provide their details to pay for your products or services.  

The penalties for non-compliance can be high and include immediate suspension of your payment facility and financial penalties for breaching your merchant agreement.  

But managing your payment security compliance doesn’t have to be complicated or overwhelming. Our QSAs (Qualified Security Assessors) are certified by the PCI Security Standards Council to independently assess merchants and service providers. This means we can provide peace of mind by doing all the heavy lifting to ensure your customers’ data is secure and protected, and your systems are PCI DSS compliant.  

How we can help 

We can evaluate your current level of compliance with services that range from assessing how applicable PCI DSS is to your business through to developing a prioritised roadmap to compliance. 

Our conclusive certification services will allow you to demonstrate your security credentials to regulators, business partners and your customers. 

Your organisation may not need to opt for a full onsite assessment. Grant Thornton can help you fill out or endorse the SAQ on your behalf (or for smaller environments, pass eligibility criteria). This is ideal if your organisation is having difficulty interpreting the SAQ requirement, or if you don’t have the bandwidth to complete this. 

An ASV scan is essential to achieve compliance. As qualified resellers of an ASV solution, we can help you perform quarterly ASV scans as part of the PCI DSS requirements. 

People are often the weakest link in any security programme. We can help your users understand the PCI DSS requirements and the important role they play in maintaining them. Our facilitator-led security and PCI DSS awareness training programmes will promote general awareness and compliance with PCI DSS requirements throughout your organisation. 

A significant piece of the assessment comprises governance and policies. We recognise the substantial time commitment needed to develop the relevant documentation – time you could be spending on other areas of your business. We can create policies that are aligned with your business model and compliant with the PCI DSS requirements. 

Hamish Bowen
Partner and National Director, Consulting
Hamish Bowen