Frequently Asked Questions
How long does PCI DSS compliance take?
Timeline depends on SAQ type and starting position: SAQ A (2-4 weeks), SAQ B/C (6-10 weeks), SAQ D-Merchant (16-24 weeks), ROC assessment (20-30 weeks). These estimates assume a dedicated team; actual timelines vary based on team size, current security posture, and scope complexity.
What should I do first for PCI compliance?
Start with: (1) Determine your SAQ type, (2) Define your CDE scope, (3) Conduct a gap analysis against applicable requirements, (4) Prioritise remediation by risk, (5) Implement controls in dependency order (network security first, then access controls, then monitoring).
Can I do PCI compliance without a QSA?
Level 2-4 merchants can self-assess using the appropriate SAQ without a QSA. Level 1 merchants (>6M annual transactions) require a QSA-validated Report on Compliance (ROC). However, engaging a QSA for guidance is recommended even for self-assessment to ensure accuracy.