In fact, the PCI Security Standards Council (SSC) strongly suggest and advocates the development of a plan for continued PCI compliance. The guidance document called “Best Practices for Maintaining PCI DSS Compliance” (January 2019) lists the key issues with maintaining compliance. One of the requirements even requires that businesses develop a PCI Charter and that they assign responsibility for “overall accountability for maintaining PCI DSS compliance.”
The activities and controls within PCI DSS need to be carried out daily, weekly, monthly, quarterly, biannual and annually. There are many reasons why actions can be missed, however, the most common reason is a lack of resourcing. Ideally, maintaining compliance activities should be the core responsibility of an employee or team of employees. However, as a QSA company, we see most companies failing in continuous compliance and see that they stop thinking about PCI as soon as the QSA has left the building. Not to mention the stress when the QSA arrives the next year.
To help companies validating for PCI compliance we developed our PCI Continuous Compliance program, implementing periodic sessions, checks and meetings. This will help to track the PCI DSS Compliance Program activities and to ensure that they are being carried out. By incorporating a QSA in this program you ensure your path towards PCI validation is smooth. Meet our PCI Continuous Compliance Service:
Our PCI DSS continuous compliance service is a subscription-based service. It offers an attractive and effective method of validating for PCI-DSS and having access to a QSA during the annual cycle. You are guided through the periodic tasks, to help you to keep track of them and that they are available during the compliance period to deal with any issues or questions that come up.
We have summed up the main benefits of our PCI Continuous Compliance service:
The monthly fee depends on the needs of the organization. Included are the 4-mandatory quarterly ASV scans and the annual PCI audit. We also offer annual penetration testing for an attractive price. If you are interested to learn more about how this service could work for your organization. Please contact us.
Return to blog