Skip to contentSkip to content
SERVICE CATALOGUE

Compliance Services Catalogue

Explore 16 compliance services across assessment, testing, consulting, training, and managed services.

Not sure which service you need?

Tell us about your organisation and we'll recommend the right compliance services.

Get a Recommendation

Frequently Asked Questions

What PCI compliance services do I need?

Minimum services depend on your merchant level: all merchants need quarterly vulnerability scans (ASV), annual self-assessment or QSA audit, and penetration testing. Additional services like policy development, training, and managed compliance are recommended but not always required.

What is an ASV scan?

An Approved Scanning Vendor (ASV) scan is a quarterly external vulnerability scan required by PCI DSS. ASVs are certified by the PCI SSC to perform automated scans of internet-facing systems that handle card data. Results must show no high-risk vulnerabilities.

Do I need penetration testing for PCI compliance?

PCI DSS Requirement 11.4 mandates annual external and internal penetration testing, and testing after significant infrastructure changes. The test must cover the CDE perimeter and critical systems, and be performed by a qualified tester.