Home / Governance / PCI DSS
PCI DSS v4.0.1

PCI compliance without the panic

If you take card payments, PCI DSS applies to you — and v4.0.1 raised the bar. We take merchants from "what's an SAQ?" to a signed attestation, and keep them there year after year.

What we do

  • Scoping — determine exactly which systems touch cardholder data, and shrink that footprint with segmentation so less of your network is in scope
  • SAQ selection — identify the right Self-Assessment Questionnaire for how you actually process cards (SAQ A, B, B-IP, C, and beyond)
  • Gap assessment — a requirement-by-requirement review against v4.0.1, with findings in plain English
  • Remediation — firewalls, segmentation, logging, encryption, policies, and training brought up to standard by one team
  • Ongoing compliance — quarterly scans, evidence collection, and annual attestation support so next year isn't a scramble

Multi-location? We do that.

Multi-site retail is our sweet spot: consistent network builds, centralized policy, and a single compliance program covering every register in every store. One assessment cycle, one point of contact, every location covered.

The real risk isn't the fine

It's the breach: forensic investigation costs, card-brand assessments, and the customer trust you don't get back. PCI DSS is the floor, not the ceiling — and a merchant who meets it honestly is dramatically harder to breach.

SAQ A–D Segmentation ASV Scans AOC Support
Start a PCI review

Processor asking for your SAQ?

Send us the letter. We'll tell you exactly what it means and what it'll take.

Talk to Northern Computers