PCI DSS Compliance Southern California | WCC Technologies
PCI DSS Compliance · Cybersecurity · Southern California

PCI DSS Compliance
scope reduction first, controls second.

PCI DSS compliance services for SoCal merchants and service providers handling cardholder data — PCI DSS 4.0 scope analysis, SAQ classification, network segmentation for scope reduction, control implementation across all 12 requirements, ASV scanning coordination, and QSA partnership for Report on Compliance engagements. Since 2003.

What PCI DSS is

PCI DSS — the card brand security mandate for cardholder data

PCI DSS (Payment Card Industry Data Security Standard) is the security framework required by the card brands — Visa, MasterCard, American Express, Discover, JCB — for any business that stores, processes, or transmits cardholder data. The mandate flows through your acquiring bank's merchant agreement; non-compliance penalties range from monthly fines starting around $5,000 per month through complete loss of card-acceptance privileges. The current version is PCI DSS 4.0, fully enforced since March 31, 2025.

For SoCal merchants and service providers, the practical question isn't whether PCI DSS applies but how much of your environment falls into scope. An e-commerce site that redirects payment to a tokenized processor has minimal scope and can complete SAQ A in weeks. A multi-location retailer with integrated POS, back-office systems, and an in-house e-commerce platform has substantial scope and may need a Level 1 Report on Compliance with quarterly Approved Scanning Vendor scans, formal QSA assessment, and annual penetration testing. The single most valuable engineering decision is usually scope reduction — using network segmentation, tokenization, and point-to-point encryption to shrink the in-scope environment and the corresponding compliance cost.

This page covers WCC's PCI DSS practice. For the broader operational security stack, see cybersecurity services. For executive ownership of the compliance program, see vCISO services. Start with a free IT consultation.

Assessment path comparison

Three PCI DSS assessment paths

How you demonstrate compliance depends on your merchant level, processing volume, and acceptance model. Most SoCal mid-market businesses fall into SAQ classification; Level 1 merchants and Level 1 service providers go through the Report on Compliance path.

Lowest Scope

SAQ A / A-EP

Fully outsourced or redirect e-commerce
  • Smallest in-scope environment
  • Cardholder data never touches merchant systems
  • Payment fully outsourced to PCI DSS-compliant processor
  • SAQ A: about 22 controls to validate
  • SAQ A-EP: about 191 controls (redirect with site scope)
  • Typical readiness 4-8 weeks
QSA-Audited

ROC (Report on Compliance)

Level 1 merchants & service providers
  • Required for >6M annual transactions (merchants)
  • Required for >300K transactions (service providers)
  • Performed by QSA firm (Coalfire, Schellman, A-LIGN)
  • 100+ page detailed assessment report
  • On-site audit period typically 4-8 weeks
  • Typical readiness 6-12 months from start
The integrator advantage

How WCC delivers PCI DSS programs end-to-end

Four layers underneath every WCC PCI DSS engagement. Most readiness firms stop at documentation and the SAQ. WCC owns the scope reduction engineering AND the network segmentation deployment AND the control implementation AND the ongoing operations — one accountable team.

1
1 — Your organization
SoCal Merchant or Service Provider
Retailers, e-commerce platforms, restaurants, hospitality, SaaS billing, healthcare payment, service providers — any business storing, processing, or transmitting cardholder data through their systems.
RetailE-CommerceRestaurants & HospitalitySaaS BillingService ProvidersHealthcare Payment
2
2 — What WCC manages
WCC PCI DSS Program
The strategic compliance ownership — scope analysis, SAQ classification, gap assessment, policy authorship, ASV coordination, QSA partnership, and ongoing program maintenance.
Scope AnalysisSAQ ClassificationGap AssessmentPolicy SuiteASV CoordQSA PartnershipAnnual Refresh
3
3 — The control framework
12 Requirements · 6 Control Objectives
The actual PCI DSS 4.0 framework — 12 requirements organized into 6 control objectives covering network security, access control, encryption, monitoring, testing, and policy management.
Network SecurityCardholder Data ProtectionVulnerability MgmtAccess ControlMonitoringPolicy
4
4 — What WCC operates
PCI DSS-Aligned Operations
The operational stack that produces evidence for the SAQ or ROC — network segmentation, tokenization, encryption, MFA, SIEM, EDR, quarterly ASV scanning, and 24/7 SOC operations.
SegmentationTokenization / P2PEFIPS EncryptionMFA24/7 SOCASV Scanning
Why it matters: PCI DSS readiness firms produce policies and a control matrix. The QSA shows up months later and asks where the network segmentation is, whether the firewalls are actually configured correctly, whether quarterly ASV scans have actually been running, whether MFA is enforced on every path into the cardholder data environment. WCC owns the documentation AND the segmentation engineering AND the 24/7 SOC AND the ASV scanning relationship. The program manager writes the SAQ, drives the framework, and walks downstairs to the team that operates the network, runs the MFA platform, and produces the evidence the QSA accepts on first review.
Why WCC for PCI DSS

Why choose WCC for PCI DSS compliance in Southern California

PCI DSS programs are annual cycles with high-stakes enforcement. The right partner has SoCal mid-market context, deep network and security operations capability, and the QSA relationships that keep audits moving.

2003

Founded in SoCal

22+ years operating across LA, Orange, Inland Empire, San Diego, and Ventura counties. Real institutional context on SoCal mid-market payment environments.

Scope-First

Engineering for scope reduction

Most engagements start by shrinking the in-scope environment through segmentation, tokenization, and P2PE. Smaller scope means lower cost forever. The single highest-ROI work in PCI DSS.

Multi-Framework

PCI DSS + SOC 2 + HIPAA

Most customers maintain multiple frameworks. WCC structures one control set to satisfy several audits — less duplication, less work, lower cost.

QSA Network

QSA & ASV partnerships

WCC partners with Coalfire, Schellman, A-LIGN for QSA engagements, and qualified ASV firms for quarterly scanning. Customer chooses the auditor; WCC ensures the assessment runs efficiently.

What WCC PCI DSS services include

End-to-end program management

Every engagement is scoped to current maturity, merchant level, acceptance model, and target assessment path. These are the six core capability areas every PCI DSS engagement covers.

Scope

Scope Analysis & Reduction

Cardholder data flow mapping. Network architecture analysis. Identification of in-scope systems. Recommendations for scope reduction through network segmentation, tokenization, point-to-point encryption, and redirect payment integration. Usually the highest-ROI work in the engagement.

CHD Mapping · Segmentation Design · P2PE
Classify

SAQ Classification & Path Selection

Determining the appropriate SAQ type (A, A-EP, B, B-IP, C, C-VT, D-Merchant, D-Service Provider, P2PE) based on acceptance model. ROC eligibility analysis. Merchant level confirmation. Service provider level confirmation.

SAQ Classification · ROC Path · Level Confirm
Document

Policy & Procedure Suite

Full PCI DSS policy suite — Information Security Policy, Network Security, Access Control, Change Management, Vulnerability Management, Incident Response, Vendor Management, and the supporting procedures required by Requirement 12.

Policies · Procedures · Standards
Implement

Control Implementation

Hands-on implementation across all 12 requirements — network segmentation, firewall rules, MFA, FIPS-validated encryption, audit logging, anti-malware deployment, and the change management workflow that satisfies Requirements 5, 6, 8, and 10.

Segmentation · MFA · Logging · Anti-Malware
Scan

ASV & Penetration Testing

Quarterly Approved Scanning Vendor (ASV) external vulnerability scanning. Internal vulnerability scanning. Annual penetration testing for Requirement 11. Segmentation testing where network segmentation is the basis for scope reduction.

ASV Scans · Internal Scans · Pen Test · Seg Test
Audit

QSA Audit & Ongoing Maintenance

For Level 1 ROC engagements: QSA partnership and on-site assessment coordination. For all engagements: ongoing program maintenance, annual SAQ refresh, quarterly attestations, and continuous evidence collection. Often combined with vCISO services.

QSA Coord · Annual SAQ · Evidence
The 12 PCI DSS requirements

What the standard actually requires

PCI DSS 4.0 organizes 12 requirements into 6 control objectives. The control language is prescriptive — specific controls, specific evidence, specific intervals. WCC's practice covers every requirement, with most engagements emphasizing scope reduction (the foundation) and Requirements 1, 2, 3, 7, 8, 10, and 11 (the technical core).

Req 1

Network Security Controls

Install and maintain network security controls (formerly firewalls). Network segmentation evidence.

Req 2

Secure Configurations

Apply secure configurations to all system components. No vendor-supplied defaults.

Req 3

Protect Stored Data

Protect stored account data through encryption, masking, truncation, or hashing.

Req 4

Encrypt in Transit

Protect cardholder data with strong cryptography during transmission over open public networks.

Req 5

Anti-Malware

Protect all systems and networks from malicious software. Deploy and maintain anti-malware.

Req 6

Secure Development

Develop and maintain secure systems and software. Vulnerability management. Change control.

Req 7

Need-to-Know Access

Restrict access to system components and cardholder data by business need-to-know.

Req 8

Identify & Authenticate

Identify users and authenticate access. MFA for all CDE access (expanded in 4.0).

Req 9

Restrict Physical Access

Restrict physical access to cardholder data. Visitor logs, media handling, device inventory.

Req 10

Log & Monitor

Log and monitor all access to system components and cardholder data. SIEM, log review, retention.

Req 11

Test Security Regularly

Test the security of systems and networks regularly. Quarterly ASV scans, annual pen testing.

Req 12

Information Security Policy

Support information security with organizational policies and programs. Documentation foundation.

Who needs PCI DSS

PCI DSS across SoCal verticals

Any SoCal business that accepts, stores, processes, or transmits cardholder data has PCI DSS obligations. These are the six verticals where WCC has deepest experience.

Multi-Site Retail & Hospitality

Retailers, restaurants, hotels, and entertainment venues operating across multiple SoCal locations. Integrated POS, back-office systems, and e-commerce typically push scope toward SAQ D. Scope reduction through P2PE terminals and tokenization is high-ROI.

E-Commerce

E-commerce platforms ranging from SAQ A (fully redirected payment) through SAQ D (integrated payment forms). Magecart-style attacks have made the new PCI DSS 4.0 payment page scripting requirements (Requirements 6.4.3 and 11.6.1) particularly important.

SaaS Billing & Subscription Platforms

Recurring billing platforms, subscription services, and SaaS businesses with payment processing. Often pair PCI DSS with SOC 2 for the enterprise procurement angle.

Healthcare Payment

Medical practices, healthcare technology, and revenue cycle management businesses processing patient payments. PCI DSS and HIPAA run in parallel — one well-designed control program can satisfy both.

Service Providers

Payment processors, gateways, hosting providers, and other service providers handling cardholder data. Level 1 service providers (over 300,000 transactions/year) require annual ROC. Level 2 service providers use SAQ D-Service Provider.

Property Management & Real Estate

Property management firms, HOA management, and real estate businesses processing rent and HOA payments. Often start as SAQ A through redirect processors but expand scope as payment systems integrate with accounting platforms.

2003
Founded in SoCal — 22+ years operating
12 Req
All PCI DSS 4.0 requirements covered across the practice
Scope-First
Network segmentation engineering for scope reduction
#819788
CSLB Licensed — C-7 · C-10 · C-28
FAQs

PCI DSS frequently asked questions

PCI DSS (Payment Card Industry Data Security Standard) is the security framework required by the card brands (Visa, MasterCard, American Express, Discover, JCB) for any organization that stores, processes, or transmits cardholder data. Required parties include merchants (retailers, restaurants, e-commerce, SaaS billing), service providers (payment processors, gateways, hosting providers handling card data), and any business that touches cardholder data through their systems. Compliance is mandated by the card brand acquiring agreements — not by government regulation. Non-compliance penalties run from monthly fines ($5,000 to $100,000+ per month) up to loss of card-acceptance privileges entirely.

Merchant level is based on annual transaction volume. Level 1: over 6 million transactions per year (any card brand) — requires annual Report on Compliance (ROC) by a Qualified Security Assessor (QSA) and quarterly Approved Scanning Vendor (ASV) scans. Level 2: 1 to 6 million transactions per year — requires annual Self-Assessment Questionnaire (SAQ) and quarterly ASV scans, with some acquirers requiring ROC. Level 3: 20,000 to 1 million e-commerce transactions per year — annual SAQ plus quarterly ASV scans. Level 4: under 20,000 e-commerce or under 1 million total transactions — annual SAQ plus quarterly ASV scans. Service providers have their own level scheme.

SAQ (Self-Assessment Questionnaire) is a self-reported compliance document. There are 9 SAQ types matched to different acceptance scenarios — SAQ A for card-not-present fully outsourced, SAQ A-EP for e-commerce with payment redirect, SAQ B for imprint or standalone dial-out terminals, SAQ B-IP for IP-based terminals, SAQ C for payment applications connected to internet, SAQ C-VT for virtual terminals, SAQ D-Merchant for all others, SAQ D-Service Provider for service providers, and SAQ P2PE for point-to-point encrypted solutions. ROC (Report on Compliance) is an independent assessment performed by a QSA producing a 100+ page detailed report. Level 1 merchants and Level 1 service providers must produce a ROC; other levels typically use SAQs.

PCI DSS 4.0 replaced version 3.2.1 with full enforcement starting March 31, 2025. The 12 core requirements remained but with substantial updates. Key changes include: customized approach (allowing businesses to meet objectives through alternative controls validated by a QSA), expanded MFA requirements (now required for all access into the cardholder data environment, not just remote and administrative), more rigorous authentication requirements (phishing-resistant where feasible), expanded encryption requirements, more detailed third-party service provider monitoring, expanded vulnerability scanning, expanded penetration testing requirements, and new requirements around payment page scripting (combating Magecart attacks). The transition window closed March 31, 2025 — all assessments now reference 4.0.

For SAQs, WCC supports completion but the document is self-attested by the merchant. For Report on Compliance engagements, the assessment must be performed by a Qualified Security Assessor (QSA) firm registered with the PCI Security Standards Council. WCC partners with qualified QSA firms (Coalfire, Schellman, A-LIGN, and others) for ROC engagements. WCC handles the readiness work — scope analysis, SAQ classification, gap assessment, control implementation, policy authorship, ASV scanning coordination, and QSA pre-assessment preparation — then partners on the formal ROC assessment when required.

PCI DSS scope is every system that stores, processes, or transmits cardholder data, plus every system connected to those systems. Without deliberate scope reduction, the in-scope environment can grow to include most of the corporate network — multiplying the cost of compliance dramatically. Scope reduction techniques include network segmentation isolating cardholder data systems, tokenization (replacing card data with non-sensitive tokens), point-to-point encryption (P2PE) that takes systems out of scope entirely, and redirect/iframe payment integration that keeps card data off the merchant's systems. A well-scoped PCI DSS environment can cost 10-20% of an unscoped environment to maintain.

Depends on scope, current maturity, and target level. SAQ A (fully outsourced) can be completed in 4-8 weeks if controls are already in place. SAQ D for a merchant with retail operations and integrated payment systems typically runs 4-6 months including remediation. Level 1 ROC preparation runs 6-12 months from kickoff to ROC issuance, including the QSA on-site assessment period. Service provider ROC engagements are typically the longest given broader scope. The single largest variable is whether scope reduction work is required upfront — when network segmentation or tokenization is part of the project, add 2-4 months to most timelines.

PCI DSS is industry-mandated by the card brands for anyone touching cardholder data — non-negotiable if you accept payment cards. SOC 2 is market-driven by enterprise procurement — required by your enterprise customers, not by regulation. HIPAA is US federal regulation for protected health information. Many WCC customers maintain multiple frameworks simultaneously — for example a healthcare SaaS holding cardholder data needs HIPAA + SOC 2 + PCI DSS together. The control work overlaps substantially (MFA, encryption, logging, vulnerability management, incident response are all common), so one well-designed control program can satisfy multiple frameworks with minimal additional effort.

SoCal Coverage

PCI DSS services across Southern California

WCC delivers PCI DSS work across all six SoCal counties. Headquartered in Chino.

Ready to talk PCI DSS?

Most engagements start with a scope question.

Tell us your merchant level, your acceptance model, and what your current PCI DSS posture actually is — the gap between what the SAQ says and what the systems do is usually larger than people expect. WCC will scope the assessment path, identify scope reduction opportunities first, then build the readiness plan around what your actual environment requires.

Scroll to Top