Every Requirement in PCI DSS v4.0.1 Is Now Mandatory
PCI DSS Assessment Services
The transition period for PCI DSS v4.0.1 is over, and every one of its requirements is now in scope for assessment. We help UK merchants and service providers close the gaps before their next SAQ or Report on Compliance is due.
- Certified Experts
- OSCP, CEH, CRTP & industry-certified testers.
- Real-World Approach
- Manual testing with real-world attack techniques.
- Actionable Reporting
- Detailed findings with clear risk ratings and remediation.
- Confidential & Secure
- Strict NDA, data protection & privacy practices.
// About PCI DSS Assessment
Getting Ahead of a Fully Mandatory Standard
PCI DSS v4.0.1 introduced dozens of new and updated requirements, including stricter controls around payment page scripts, multi-factor authentication and continuous monitoring. Many organisations that validated under earlier versions are now finding gaps they did not expect.
We run a practical gap assessment against the current standard, help you close the highest-risk items first, and prepare the evidence your Qualified Security Assessor or Self-Assessment Questionnaire process will need. We support UK merchants and service providers handling cardholder data.
- Full PCI DSS v4.0.1 Gap Analysis
- Payment Page and Script Controls Reviewed
- SAQ and QSA-Ready Evidence Prepared
- Priority-Based Remediation Roadmap
// Coverage
What We Cover
Cardholder Data Environment Scoping
Mapping of every system that stores, processes or transmits card data.
Network Security Review
Assessment of segmentation, firewalls and access controls around the cardholder environment.
Payment Page Integrity Controls
Review of script inventories and tamper detection required under v4.0.1.
Access Control and Authentication
Assessment of multi-factor authentication and least-privilege access.
Vulnerability Management
Review of your scanning, patching and remediation processes.
Documentation and Policy Review
Assessment of the written policies PCI DSS requires you to maintain.
// Methodology
Our Assessment Process
- 01
Scoping
We help define your cardholder data environment and identify all in-scope systems.
- 02
Gap Assessment
We review your current controls against all applicable PCI DSS v4.0.1 requirements.
- 03
Remediation Planning
We prioritise gaps by risk and effort, so the highest-impact fixes happen first.
- 04
Evidence Preparation
We help you build the documentation and evidence your SAQ or QSA process requires.
- 05
Assessment Support
We support coordination with your acquirer or Qualified Security Assessor through validation.
// Ready when you are
Put your pci dss assessment services to the test.
// Impact
Why PCI DSS Assessment Matters
The Transition Period Has Ended
Every requirement in v4.0.1, including the previously future-dated controls, is now mandatory for all assessments.
// How We Support Your PCI DSS Programme
- Cardholder data environment scoping
- Gap assessment against all twelve PCI DSS requirements
- Payment page script inventory and integrity control review
- Multi-factor authentication and access control review
- Vulnerability scanning and segmentation testing support
- Documentation and evidence preparation
- SAQ selection guidance or QSA coordination support
What you get
// Standards We Work Within
// Why Choose Pluto Cyber Security
Practical PCI DSS Support, Not Just a Checklist
PCI DSS compliance touches technical infrastructure, application development and business process all at once. We combine hands-on security testing experience with compliance expertise, so gaps are found and fixed, not just documented.
Current Standard Expertise
We work exclusively against the active PCI DSS v4.0.1 standard.
Technical and Compliance Combined
Our background in penetration testing strengthens every gap assessment.
Scope Reduction Focus
We help minimise unnecessary cardholder data exposure wherever possible.
QSA-Ready Documentation
We prepare evidence in the format your UK acquirer or assessor expects.
No. We provide readiness and gap assessment support to prepare you for validation. Formal ROC assessments must be performed by a QSA company certified by the PCI Security Standards Council.
// Related services
Explore Related Services.
Get started
Ready to Scope Your PCI DSS Assessment Services?
Tell us what you need tested. We reply with honest guidance and a fixed-scope quote, usually within one business day.

