PCI DSS Compliance
scope reduction first, controls second.
PCI DSS compliance services for SoCal merchants and service providers handling cardholder data — PCI DSS 4.0 scope analysis, SAQ classification, network segmentation for scope reduction, control implementation across all 12 requirements, ASV scanning coordination, and QSA partnership for Report on Compliance engagements. Since 2003.
PCI DSS — the card brand security mandate for cardholder data
PCI DSS (Payment Card Industry Data Security Standard) is the security framework required by the card brands — Visa, MasterCard, American Express, Discover, JCB — for any business that stores, processes, or transmits cardholder data. The mandate flows through your acquiring bank's merchant agreement; non-compliance penalties range from monthly fines starting around $5,000 per month through complete loss of card-acceptance privileges. The current version is PCI DSS 4.0, fully enforced since March 31, 2025.
For SoCal merchants and service providers, the practical question isn't whether PCI DSS applies but how much of your environment falls into scope. An e-commerce site that redirects payment to a tokenized processor has minimal scope and can complete SAQ A in weeks. A multi-location retailer with integrated POS, back-office systems, and an in-house e-commerce platform has substantial scope and may need a Level 1 Report on Compliance with quarterly Approved Scanning Vendor scans, formal QSA assessment, and annual penetration testing. The single most valuable engineering decision is usually scope reduction — using network segmentation, tokenization, and point-to-point encryption to shrink the in-scope environment and the corresponding compliance cost.
This page covers WCC's PCI DSS practice. For the broader operational security stack, see cybersecurity services. For executive ownership of the compliance program, see vCISO services. Start with a free IT consultation.
Three PCI DSS assessment paths
How you demonstrate compliance depends on your merchant level, processing volume, and acceptance model. Most SoCal mid-market businesses fall into SAQ classification; Level 1 merchants and Level 1 service providers go through the Report on Compliance path.
SAQ A / A-EP
- Smallest in-scope environment
- Cardholder data never touches merchant systems
- Payment fully outsourced to PCI DSS-compliant processor
- SAQ A: about 22 controls to validate
- SAQ A-EP: about 191 controls (redirect with site scope)
- Typical readiness 4-8 weeks
SAQ D
- Default for merchants not fitting other SAQ categories
- Covers all 12 requirements (about 320 controls)
- Self-attested but evidence trail required
- Quarterly ASV scanning mandatory
- Annual penetration testing for segmentation validation
- Typical readiness 4-6 months
ROC (Report on Compliance)
- Required for >6M annual transactions (merchants)
- Required for >300K transactions (service providers)
- Performed by QSA firm (Coalfire, Schellman, A-LIGN)
- 100+ page detailed assessment report
- On-site audit period typically 4-8 weeks
- Typical readiness 6-12 months from start
How WCC delivers PCI DSS programs end-to-end
Four layers underneath every WCC PCI DSS engagement. Most readiness firms stop at documentation and the SAQ. WCC owns the scope reduction engineering AND the network segmentation deployment AND the control implementation AND the ongoing operations — one accountable team.
Why choose WCC for PCI DSS compliance in Southern California
PCI DSS programs are annual cycles with high-stakes enforcement. The right partner has SoCal mid-market context, deep network and security operations capability, and the QSA relationships that keep audits moving.
Founded in SoCal
22+ years operating across LA, Orange, Inland Empire, San Diego, and Ventura counties. Real institutional context on SoCal mid-market payment environments.
Engineering for scope reduction
Most engagements start by shrinking the in-scope environment through segmentation, tokenization, and P2PE. Smaller scope means lower cost forever. The single highest-ROI work in PCI DSS.
PCI DSS + SOC 2 + HIPAA
Most customers maintain multiple frameworks. WCC structures one control set to satisfy several audits — less duplication, less work, lower cost.
QSA & ASV partnerships
WCC partners with Coalfire, Schellman, A-LIGN for QSA engagements, and qualified ASV firms for quarterly scanning. Customer chooses the auditor; WCC ensures the assessment runs efficiently.
End-to-end program management
Every engagement is scoped to current maturity, merchant level, acceptance model, and target assessment path. These are the six core capability areas every PCI DSS engagement covers.
Scope Analysis & Reduction
Cardholder data flow mapping. Network architecture analysis. Identification of in-scope systems. Recommendations for scope reduction through network segmentation, tokenization, point-to-point encryption, and redirect payment integration. Usually the highest-ROI work in the engagement.
SAQ Classification & Path Selection
Determining the appropriate SAQ type (A, A-EP, B, B-IP, C, C-VT, D-Merchant, D-Service Provider, P2PE) based on acceptance model. ROC eligibility analysis. Merchant level confirmation. Service provider level confirmation.
Policy & Procedure Suite
Full PCI DSS policy suite — Information Security Policy, Network Security, Access Control, Change Management, Vulnerability Management, Incident Response, Vendor Management, and the supporting procedures required by Requirement 12.
Control Implementation
Hands-on implementation across all 12 requirements — network segmentation, firewall rules, MFA, FIPS-validated encryption, audit logging, anti-malware deployment, and the change management workflow that satisfies Requirements 5, 6, 8, and 10.
ASV & Penetration Testing
Quarterly Approved Scanning Vendor (ASV) external vulnerability scanning. Internal vulnerability scanning. Annual penetration testing for Requirement 11. Segmentation testing where network segmentation is the basis for scope reduction.
QSA Audit & Ongoing Maintenance
For Level 1 ROC engagements: QSA partnership and on-site assessment coordination. For all engagements: ongoing program maintenance, annual SAQ refresh, quarterly attestations, and continuous evidence collection. Often combined with vCISO services.
What the standard actually requires
PCI DSS 4.0 organizes 12 requirements into 6 control objectives. The control language is prescriptive — specific controls, specific evidence, specific intervals. WCC's practice covers every requirement, with most engagements emphasizing scope reduction (the foundation) and Requirements 1, 2, 3, 7, 8, 10, and 11 (the technical core).
Network Security Controls
Install and maintain network security controls (formerly firewalls). Network segmentation evidence.
Secure Configurations
Apply secure configurations to all system components. No vendor-supplied defaults.
Protect Stored Data
Protect stored account data through encryption, masking, truncation, or hashing.
Encrypt in Transit
Protect cardholder data with strong cryptography during transmission over open public networks.
Anti-Malware
Protect all systems and networks from malicious software. Deploy and maintain anti-malware.
Secure Development
Develop and maintain secure systems and software. Vulnerability management. Change control.
Need-to-Know Access
Restrict access to system components and cardholder data by business need-to-know.
Identify & Authenticate
Identify users and authenticate access. MFA for all CDE access (expanded in 4.0).
Restrict Physical Access
Restrict physical access to cardholder data. Visitor logs, media handling, device inventory.
Log & Monitor
Log and monitor all access to system components and cardholder data. SIEM, log review, retention.
Test Security Regularly
Test the security of systems and networks regularly. Quarterly ASV scans, annual pen testing.
Information Security Policy
Support information security with organizational policies and programs. Documentation foundation.
PCI DSS across SoCal verticals
Any SoCal business that accepts, stores, processes, or transmits cardholder data has PCI DSS obligations. These are the six verticals where WCC has deepest experience.
Multi-Site Retail & Hospitality
Retailers, restaurants, hotels, and entertainment venues operating across multiple SoCal locations. Integrated POS, back-office systems, and e-commerce typically push scope toward SAQ D. Scope reduction through P2PE terminals and tokenization is high-ROI.
E-Commerce
E-commerce platforms ranging from SAQ A (fully redirected payment) through SAQ D (integrated payment forms). Magecart-style attacks have made the new PCI DSS 4.0 payment page scripting requirements (Requirements 6.4.3 and 11.6.1) particularly important.
SaaS Billing & Subscription Platforms
Recurring billing platforms, subscription services, and SaaS businesses with payment processing. Often pair PCI DSS with SOC 2 for the enterprise procurement angle.
Healthcare Payment
Medical practices, healthcare technology, and revenue cycle management businesses processing patient payments. PCI DSS and HIPAA run in parallel — one well-designed control program can satisfy both.
Service Providers
Payment processors, gateways, hosting providers, and other service providers handling cardholder data. Level 1 service providers (over 300,000 transactions/year) require annual ROC. Level 2 service providers use SAQ D-Service Provider.
Property Management & Real Estate
Property management firms, HOA management, and real estate businesses processing rent and HOA payments. Often start as SAQ A through redirect processors but expand scope as payment systems integrate with accounting platforms.
PCI DSS frequently asked questions
PCI DSS (Payment Card Industry Data Security Standard) is the security framework required by the card brands (Visa, MasterCard, American Express, Discover, JCB) for any organization that stores, processes, or transmits cardholder data. Required parties include merchants (retailers, restaurants, e-commerce, SaaS billing), service providers (payment processors, gateways, hosting providers handling card data), and any business that touches cardholder data through their systems. Compliance is mandated by the card brand acquiring agreements — not by government regulation. Non-compliance penalties run from monthly fines ($5,000 to $100,000+ per month) up to loss of card-acceptance privileges entirely.
Merchant level is based on annual transaction volume. Level 1: over 6 million transactions per year (any card brand) — requires annual Report on Compliance (ROC) by a Qualified Security Assessor (QSA) and quarterly Approved Scanning Vendor (ASV) scans. Level 2: 1 to 6 million transactions per year — requires annual Self-Assessment Questionnaire (SAQ) and quarterly ASV scans, with some acquirers requiring ROC. Level 3: 20,000 to 1 million e-commerce transactions per year — annual SAQ plus quarterly ASV scans. Level 4: under 20,000 e-commerce or under 1 million total transactions — annual SAQ plus quarterly ASV scans. Service providers have their own level scheme.
SAQ (Self-Assessment Questionnaire) is a self-reported compliance document. There are 9 SAQ types matched to different acceptance scenarios — SAQ A for card-not-present fully outsourced, SAQ A-EP for e-commerce with payment redirect, SAQ B for imprint or standalone dial-out terminals, SAQ B-IP for IP-based terminals, SAQ C for payment applications connected to internet, SAQ C-VT for virtual terminals, SAQ D-Merchant for all others, SAQ D-Service Provider for service providers, and SAQ P2PE for point-to-point encrypted solutions. ROC (Report on Compliance) is an independent assessment performed by a QSA producing a 100+ page detailed report. Level 1 merchants and Level 1 service providers must produce a ROC; other levels typically use SAQs.
PCI DSS 4.0 replaced version 3.2.1 with full enforcement starting March 31, 2025. The 12 core requirements remained but with substantial updates. Key changes include: customized approach (allowing businesses to meet objectives through alternative controls validated by a QSA), expanded MFA requirements (now required for all access into the cardholder data environment, not just remote and administrative), more rigorous authentication requirements (phishing-resistant where feasible), expanded encryption requirements, more detailed third-party service provider monitoring, expanded vulnerability scanning, expanded penetration testing requirements, and new requirements around payment page scripting (combating Magecart attacks). The transition window closed March 31, 2025 — all assessments now reference 4.0.
For SAQs, WCC supports completion but the document is self-attested by the merchant. For Report on Compliance engagements, the assessment must be performed by a Qualified Security Assessor (QSA) firm registered with the PCI Security Standards Council. WCC partners with qualified QSA firms (Coalfire, Schellman, A-LIGN, and others) for ROC engagements. WCC handles the readiness work — scope analysis, SAQ classification, gap assessment, control implementation, policy authorship, ASV scanning coordination, and QSA pre-assessment preparation — then partners on the formal ROC assessment when required.
PCI DSS scope is every system that stores, processes, or transmits cardholder data, plus every system connected to those systems. Without deliberate scope reduction, the in-scope environment can grow to include most of the corporate network — multiplying the cost of compliance dramatically. Scope reduction techniques include network segmentation isolating cardholder data systems, tokenization (replacing card data with non-sensitive tokens), point-to-point encryption (P2PE) that takes systems out of scope entirely, and redirect/iframe payment integration that keeps card data off the merchant's systems. A well-scoped PCI DSS environment can cost 10-20% of an unscoped environment to maintain.
Depends on scope, current maturity, and target level. SAQ A (fully outsourced) can be completed in 4-8 weeks if controls are already in place. SAQ D for a merchant with retail operations and integrated payment systems typically runs 4-6 months including remediation. Level 1 ROC preparation runs 6-12 months from kickoff to ROC issuance, including the QSA on-site assessment period. Service provider ROC engagements are typically the longest given broader scope. The single largest variable is whether scope reduction work is required upfront — when network segmentation or tokenization is part of the project, add 2-4 months to most timelines.
PCI DSS is industry-mandated by the card brands for anyone touching cardholder data — non-negotiable if you accept payment cards. SOC 2 is market-driven by enterprise procurement — required by your enterprise customers, not by regulation. HIPAA is US federal regulation for protected health information. Many WCC customers maintain multiple frameworks simultaneously — for example a healthcare SaaS holding cardholder data needs HIPAA + SOC 2 + PCI DSS together. The control work overlaps substantially (MFA, encryption, logging, vulnerability management, incident response are all common), so one well-designed control program can satisfy multiple frameworks with minimal additional effort.
PCI DSS work pairs with these WCC capabilities
PCI DSS readiness touches network engineering, identity, security operations, and ongoing program management. The services below commonly bundle with PCI DSS engagements.
SOC 2 Compliance
Often paired with PCI DSS for SaaS billing and B2B service providers serving enterprise customers.
HIPAA Compliant IT
For healthcare businesses processing patient payments — HIPAA and PCI DSS run in parallel.
vCISO Services
Executive ownership of the PCI DSS program, QSA coordination, and board-level reporting.
MFA Management
Required by PCI DSS 4.0 Requirement 8 for all access into the cardholder data environment.
Managed SOC
24/7 SOC monitoring — required for PCI DSS Requirement 10. SIEM, alerts, investigation, audit trail.
Penetration Testing
Annual penetration testing — required for PCI DSS Requirement 11 and segmentation validation.
Vulnerability Assessment
Internal vulnerability scanning to complement quarterly ASV external scans — Requirement 11.3.
Free IT Consultation
The fastest way to scope a PCI DSS engagement — a 60-90 minute conversation with a senior WCC engineer.
PCI DSS services across Southern California
WCC delivers PCI DSS work across all six SoCal counties. Headquartered in Chino.
Most engagements start with a scope question.
Tell us your merchant level, your acceptance model, and what your current PCI DSS posture actually is — the gap between what the SAQ says and what the systems do is usually larger than people expect. WCC will scope the assessment path, identify scope reduction opportunities first, then build the readiness plan around what your actual environment requires.
