The challenge

What the organization was facing.

The organization accepted payment cards across retail locations, an e-commerce platform and a call centre, and each channel had grown independently. Nobody could produce a definitive map of where cardholder data was stored, processed or transmitted, which meant PCI scope was assumed rather than evidenced. With the v4.0 future-dated requirements becoming mandatory, leadership needed to know what was genuinely in scope before committing to a remediation budget.

What ISC did

The approach.

  1. 01

    Traced cardholder data flows across every payment channel, including third-party processors, call recording systems and support tooling that had never been formally assessed.

  2. 02

    Confirmed merchant level, applicable SAQ and the boundary of the cardholder data environment, then identified systems that were in scope only because of flat network connectivity.

  3. 03

    Ran a gap assessment against PCI DSS v4.0, giving specific attention to the newer requirements: targeted risk analyses, authenticated internal scanning, and client-side script management on payment pages.

  4. 04

    Modelled segmentation and scope-reduction options, quantifying which changes removed the most systems from assessment scope for the least operational disruption.

  5. 05

    Built a remediation roadmap sequenced against the compliance deadline, with owners, dependencies and evidence requirements attached to each item.

Outcomes

What changed.

  1. 01

    A documented, evidence-backed PCI scope replacing the previous assumed boundary.

  2. 02

    A reduced cardholder data environment through targeted segmentation, lowering ongoing assessment effort.

  3. 03

    A remediation plan mapped to the v4.0 deadline, with clear ownership and evidence expectations per control.

Services used

Capabilities behind this engagement.