Because your QSA probably shouldn't be the person who discovers your PCI program.

PCI Readiness

PCI has a funny way of sounding manageable right up until you actually have to prove it.

You may already have security tools, policies, penetration tests, diagrams, access reviews, vendor agreements, and plenty of smart people doing the right things. The problem is that an assessment isn't based on whether everyone generally agrees security is important. You have to demonstrate that the right controls exist, that they operate consistently, that your documentation reflects reality, and that you can produce the evidence to prove it.

Preferably without turning the entire company into a month-long scavenger hunt.

That's what our PCI Readiness services are built to prevent.

Whether you're facing your first formal PCI assessment or you've already survived one and would rather not rebuild the whole thing again next year, we help turn PCI into a program your organization can actually operate.

PCI Shouldn't Become Everyone's Full-Time Job for Six Weeks

The compliance work itself is only part of the cost of PCI.

The real damage happens when everything gets pushed to the end.

Suddenly developers who should be shipping product are digging through tickets looking for evidence. Security teams are recreating documentation. Executives are getting pulled into meetings they didn't know existed. Customer commitments get pushed. Internal projects stall. Someone is trying to figure out who owns a quarterly review that should have happened four months ago.

Meanwhile, your QSA is waiting.

Your bank is asking why the assessment is overdue.

And if things get far enough off the rails, card-brand fines can become part of the conversation too. That tends to improve everyone's sense of urgency rather quickly.

This is exactly what we're trying to avoid.

PCI shouldn't periodically take over the company. When the program is managed correctly, the required work happens as part of the normal operating rhythm. Policies stay current. Evidence gets retained when activities happen. Scope gets reviewed as the environment changes. Owners know what they're responsible for. Issues get dealt with while they're still small.

Then assessment time comes around and everyone keeps doing their actual jobs.

That's the goal.

Before We Talk About Compliance, Let's Figure Out What's Actually in Scope

PCI scope has an unfortunate habit of being treated like a paperwork question.

It isn't.

Scope starts with understanding how payments actually move through your environment: where account data enters, where it travels, what systems touch it, what systems can impact its security, which vendors are involved, who has access, and which parts of the environment you believe are safely outside the boundary.

That last part can generate some especially entertaining conversations.

We work with your technical and business teams to understand payment flows, architecture, infrastructure, third-party dependencies, access paths, segmentation, applications, and the operational processes surrounding them. We help develop an accurate picture of the PCI environment and identify scope assumptions that need to be validated with your QSA.

For first-time assessments, that means helping establish the scope correctly before the assessment gets momentum.

For ongoing governance, it means making sure the scope you documented last year still bears some resemblance to the company you operate today.

Because applications change. Vendors change. Networks change. Payment flows change.

PCI scope does not freeze in amber simply because someone signed an Attestation of Compliance.

Policies That Describe the Company You Actually Run

PCI loves documentation.

Unfortunately, copying a 94-page information security policy from the internet does not magically make you secure or compliant. It mostly gives your assessor 94 pages of opportunities to ask why you aren't doing the things your own policy says you do.

For organizations going through PCI for the first time, we help develop and refine the policies, procedures, standards, responsibility assignments, and supporting documentation needed for the assessment. The objective is not to create an impressive stack of documents. It's to create policies that describe your actual technology, people, vendors, operational practices, and security program.

For organizations already operating under PCI, the challenge shifts from writing the policies to keeping them accurate. As systems change, responsibilities move, vendors come and go, and processes evolve, we help coordinate the recurring policy review process and identify where documentation needs to catch up with reality.

Policies should help explain how your organization works.

They shouldn't require everyone to pretend the organization works differently during assessment week.

And Then There's the QSA

This may be the most valuable part of what we do.

Your QSA has a job to do. They need to understand the environment, validate controls, review evidence, interview responsible personnel, and determine whether the applicable PCI requirements have been satisfied.

Your engineers, executives, product people, and operations teams also have jobs to do.

Those jobs generally do not include becoming fluent in PCI terminology just because an assessment started.

We operate in the middle.

Payments Therapist can serve as your day-to-day PCI advocate, coordinator, translator, and spokesperson throughout the assessment. We participate in QSA meetings, help interpret requests, prepare internal stakeholders, organize responses and evidence, track open questions, and make sure the right people are involved when direct technical or operational answers are required.

Just as importantly, we help prevent misunderstandings from becoming findings simply because the assessor and the person answering the question are speaking two slightly different dialects of security.

We are not there to hide problems, manufacture evidence, or argue with the QSA for sport.

We are there to make sure your organization is represented accurately, your controls are understood in context, your answers are complete and consistent, and legitimate questions or disagreements get worked through intelligently.

You still own your environment.

You just don't have to navigate the assessment alone.

Specialty Offerings

Your first PCI assessment should not feel like an ambush.

The first assessment is usually where companies discover the difference between doing security things and being able to demonstrate that those things are being done consistently, correctly, and across the organization.

First Time PCI is designed to close that gap before your QSA starts doing it for you. We begin by understanding the payment environment and helping determine the appropriate PCI scope. We look at payment flows, systems, applications, networks, service providers, personnel, access, infrastructure, and the other pieces that influence where PCI applies.

Then we look at readiness. What controls exist? What evidence exists? What documentation is missing? Which processes happen consistently, and which ones mostly happen because somebody remembers to do them? Where does the policy say one thing while the technology does another? What is likely to generate questions once the assessor begins digging?

From there, we help get the organization buttoned up. That can include developing or revising PCI-related policies and procedures, documenting responsibility and control ownership, organizing evidence, coordinating remediation, preparing team members for interviews, and establishing a clear process for handling assessor requests.

And when the formal assessment begins, we stay involved.

We participate in the assessment, coordinate with the QSA, help manage requests and responses, prepare your people for meetings, track open items and potential findings, and advocate for the organization through completion. The objective isn't simply to get the assessment finished.

It's to get it finished without PCI consuming the organization in the process. Your developers should still be developing. Your account teams should still be taking care of customers. Your product roadmap shouldn't grind to a halt because everyone suddenly needs to become part-time PCI project managers.

We're not the independent QSA, and the final assessment decisions belong to your assessor.

But we'll be standing next to you when those decisions are being discussed.

What's Included

  • ✓PCI readiness and gap review
  • ✓PCI scope review and validation support
  • ✓Review of payment flows, systems, applications, infrastructure, service providers, and other relevant components of the cardholder data environment
  • ✓Development and revision of PCI policies and procedures
  • ✓Identification of PCI responsibilities and control owners
  • ✓Evidence planning, collection, organization, and review
  • ✓Coordination and tracking of remediation activities
  • ✓Preparation of personnel for QSA interviews
  • ✓Organization of assessment materials
  • ✓Participation in assessment meetings
  • ✓Day-to-day coordination and liaison with the QSA
  • ✓Interpretation and management of assessor requests
  • ✓Tracking of findings, questions, responsibilities, and deadlines
  • ✓Support through final assessment completion
  • ✓Transition planning for ongoing PCI governance

Who First Time PCI Is Right For

This service is built for organizations approaching their first formal PCI assessment, companies whose growth or payment model has suddenly made PCI a much bigger conversation, or teams that have been "working on PCI" for months but still aren't entirely sure how all the pieces fit together.

You do not need to come into the engagement knowing PCI.

That would rather defeat the purpose.

You do need to be willing to let us look under the hood, ask uncomfortable questions, and fix things before the assessor finds them.

The goal is not merely to survive your first assessment.

It's to finish it with a PCI program you actually understand — without neglecting customers, shelving half the product roadmap, or making your bank wonder whether you've disappeared.

Two Different Problems. Two Different Programs.

First Time PCI helps you build the program, understand the scope, create the documentation, get ready for the assessment, and successfully navigate it with experienced advocates in the room.

PCI Governance as a Service takes over where that project ends. We help keep the program healthy from one assessment to the next, maintain policies and evidence, monitor scope as the company changes, and stand beside you again when the QSA returns.

And both are designed around the same larger goal:

One gets you ready. The other keeps you ready.

PCI should be part of running the business — not the thing that stops you from running the business.