PCI DSS Audit

A PCI audit helps Level 1 and some Level 2 merchants and service providers identify and understand the necessary controls to protect cardholder data and related systems against potential threats.

Ready to learn more about PCI audits and what they involve? See below for details on who needs to conduct an audit and how to prepare effectively.

Understand the audit process

What is a PCI DSS audit?

A PCI DSS audit, conducted by a Qualified Security Assessor (QSA), evaluates how your business manages customer payment information in alignment with PCI DSS requirements.

The audit has three main objectives:

1. Assess existing PCI controls and identify any compliance gaps
2. Document these gaps and provide a list of remediation actions
3. Confirm that all issues have been resolved

During the audit, the QSA reviews your current controls to determine if they satisfy the 12 PCI requirements, either directly or through compensating measures. The QSA then prepares a Report on Compliance (RoC) or verifies your Self-Assessment Questionnaire (SAQ) to confirm your organizationโ€™s compliance.

Differences between levels

Who needs a PCI audit?

Not all businesses are required to undergo a PCI audit. Only Level 1 merchants and service providers must complete a QSA-led audit and submit a Report on Compliance (RoC), unless a specific request is made for another level.

Level 1 merchants and service providers process the highest volume of card transactions within the four PCI levels:

โ€ข PCI DSS Merchant Level 1: Businesses accepting card payments for goods and services, processing over 6 million transactions annually.
โ€ข PCI DSS Service Provider Level 1: Organizations handling cardholder data on behalf of others, processing over 300,000 transactions annually.

Level 2 merchants and service providers may also need to complete an annual audit along with an attested Self-Assessment Questionnaire (SAQ).

Additionally, any merchant or service provider that has experienced a data breach involving cardholder data (CHD) may be required to undergo an annual audit.

Understand the audit process

What does the QSA do?

Your QSA will examine all of your controls, policies, and procedures against the PCI DSS requirements.

QSAs will also:

Review evidence provided by your company
Approve (or direct you to make changes to) your PCI scope
Evaluate your compensating controls, which are alternative controls to satisfy a requirement that the company is unable to implement at that point
Verify whether PCI DSS standards are being met
Produce and submit a comprehensive final report (PCI AoC and RoC)

Questions?

Meet with Matt and book a free 15-min call below to
better understand how to implement PCI DSS compliance in your company

6 steps of a PCI audit:

Steps

Process Description

Step 1

Define your scopeย 

When defining the scope of your PCI assessment, identify all people, processes, and technologies that could influence the security of cardholder data.

To determine your businessโ€™s PCI scope, consider all locations and flows of cardholder data (CHD) and any connected systems, including third parties and service providers, that could impact the security of this data if compromised.

Itโ€™s essential to re-evaluate your PCI scope each year to maintain accuracy. Keeping thorough documentation of how your PCI scope was defined will assist your auditor in verifying the correctness of your scoping process.

Step 2

Find a Qualified Security Assessor (QSA)

Qualified Security Assessors (QSAs) are the only licensed professionals authorized to conduct PCI audits. You can locate a QSA by searching the official list on the PCI website.

While many organizations choose to outsource audits to a QSA, if your company has its own internal auditorโ€”such as benchmarkedโ€”you may consider having them certified as an Internal Security Assessor (ISA) through PCI Security Standards Council training. ISAs are also qualified to perform annual PCI audits, providing an in-house option for maintaining compliance.

Step 3

Conduct a gap analysis

If youโ€™re undergoing first-time compliance with PCI DSS, it can be helpful to do an initial gap analysis to make the compliance journey a little bit easier.

A gap analysis helps merchants and service providers understand their current compliance status before undertaking the more extensive PCI audit.

Similar to an official audit, a QSA, ISA, or experienced person leads the gap analysis to generate a report which states findings allowing you as an organization to proactively address gaps in your security controls to potentially make the audit process faster and more efficient.

Step 4

Complete a QSA-led assessment

After a gap analysis, the next step will be for your QSA to conduct a thorough assessment.

The assessment will involve:

Reviewing documentation provided by the business
Validating that required security controls are in place
Interviewing relevant team members
Inspecting physical security controls

Step 5

Address security issuesย 

Once your QSA has completed their assessment, they will provide a documented list of findings and allow you to potentially resolve any vulnerabilities or missing controls in order for you to receive a Report on Compliance (RoC).

Once those non-conformities are addressed and reviewed by your QSA, they will send over a final RoC for you to review. Once approved, your RoC will signify to your stakeholders and clients that you are PCI compliant.

Step 6

Continue to monitor PCI security standards

An approved RoC is not the final step of your PCI compliance journey. Businesses that are required to complete QSA-led audits will need to do so annually.

Between audits, youโ€™re responsible for continually monitoring security controls to ensure all PCI standards are being met. If your business changes and your PCI scope evolves, youโ€™ll need to update that, as well.

Ongoing PCI compliance can be overwhelming. However, there are tools and tips to help make the process easier, such as:

  • Perform ASV scanning
  • Use automatic evidence collection
  • Continually monitor your systems and internal controls
  • Fill out and store vendor risk assessments

FAQs:

A PCI audit isnโ€™t a simple pass/fail test like a math exam. Instead, itโ€™s an opportunity to evaluate the effectiveness of your current security controls and strengthen them where needed.

If your QSA identifies vulnerabilities in your cardholder data security practices, you may not pass that section of the audit. However, the QSA will provide a โ€œstudy guideโ€ to help you make the required adjustments to achieve PCI compliance.

While finding no issues in the audit would be ideal, identifying and addressing vulnerabilities at this stage can help prevent more significant non-compliance issues in the future, avoiding potentially costly financial and reputational impacts.

A Level 1 merchant or service provider will need to undergo a QSA- or ISA-led audit annually.

If youโ€™re a Level 2, 3, or 4 merchant or service provider that has experienced a data breach that compromised your customerโ€™s card data, you will also need to complete a PCI audit.

The duration of a PCI audit varies based on several factors. For organizations going through PCI compliance for the first timeโ€”which includes establishing security controlsโ€”the entire process may take around six months.

The fieldwork portion of the audit, where a QSA conducts team interviews and performs necessary testing, generally spans six to eight weeks. However, partnering with a compliance automation company like Benchmarked can help streamline and potentially shorten this process.