PCI

Blog space

Preparing for a PCI DSS Audit – 10 Steps to Avoid Costly Mistakes

In this article you will learn

  • How PCI DSS audit preparation should start before the QSA review
  • Which documents, scans, pentests and TPSP evidence should be ready in advance
  • Which mistakes most often delay a PCI DSS audit and how to avoid them
Jak skutecznie przygotować firmę do audytu PCI DSS?

Updated: 5 July 2026

What is a PCI DSS audit and when is it required? A PCI DSS audit is a formal compliance assessment conducted by an accredited Qualified Security Assessor (QSA) or through a Self-Assessment Questionnaire (SAQ). It is required for all organisations that store, process, or transmit payment card data. Level 1 Merchants must complete a full ROC (Report on Compliance) audit with a QSA annually. Inadequate preparation results in findings, a remediation project, and a delayed certificate – for fintechs and e-commerce organisations, this means real business risk.

Preparing for a PCI DSS audit – at a glance:

  1. Scope assessment is step zero – without it, you do not know what will be assessed or what it will cost
  2. Documentation (policies, procedures, network diagrams, DFDs) must be current and approved before the audit begins – the QSA starts with documents
  3. An internal pre-audit (gap analysis) 3 to 4 months before the formal assessment allows gaps to be closed without time pressure
  4. Suppliers (TPSPs) must provide current AOCs or Responsibility Matrices before the assessment – this is the most commonly overlooked step
  5. Penetration tests and ASV scans must be completed and accepted before Stage 2 of the audit begins
  6. Patronusec as an accredited QSA conducts both pre-audit gap analysis and the formal ROC assessment – the client works with one team from initial scope assessment to signed AOC


What is scope assessment and why is it step zero?

Scope assessment is the analysis of what falls within PCI DSS certification scope – which systems, networks, and processes touch cardholder data or could affect it. It is step zero because without it, you cannot:

  • Know how many PCI DSS controls apply to your organisation
  • Plan a realistic timeline and budget
  • Determine which SAQ variant or ROC is appropriate
  • Identify optimisations (tokenisation, segmentation) before the project begins

The scope assessment produces a scope document containing: a CDE map with boundaries, a list of connected-to systems, a Data Flow Diagram (DFD), and a network diagram with the CDE marked.

Organisations that skip scope assessment frequently discover during the assessment that their CDE is 3 times wider than they assumed – resulting in a 6 to 12 month delay to certification and remediation costs that were not budgeted.

Patronusec Insight: We have conducted scope assessments for dozens of organisations and every single one revealed at least one system the client had not included in the CDE but should have. The most common example: Active Directory servers managing accounts with access to CHD servers are connected-to and fall within scope. The client was certain that AD “doesn’t touch card data” – and they were right, but that is not the relevant classification under PCI DSS. This is why we conduct scope assessment as a separate stage before pricing the assessment. See our PCI DSS gap analysis.

How do you determine your merchant level and choose the right certification format?

Before preparing for an assessment, you need to know which PCI DSS level applies and what document your acquirer requires.

How merchant levels are determined:

Merchant levels are based on the number of card transactions per year per card scheme:

  • Level 1: more than 6 million Visa or Mastercard transactions per year (or following a security incident)
  • Level 2: 1 to 6 million transactions
  • Level 3: 20,000 to 1 million e-commerce transactions
  • Level 4: fewer than 20,000 e-commerce transactions, or fewer than 1 million other transactions

Service Provider levels depend on the volume of cardholder data stored, processed, or transmitted (threshold: 300,000 transactions per year).

Critical point: Your acquirer may require a higher standard of documentation than the minimum implied by your level. Check your contract and contact your acquirer’s compliance team before the project begins.

How do you build the documentation a QSA requires during a PCI DSS audit?

Documentation is the first subject of QSA evaluation – Stage 1 of the audit is a documentation review. Gaps at Stage 1 halt the audit until they are remediated.

Mandatory documents before a PCI DSS audit:

DocumentPCI DSS requirementNotes
Information security policy12.1Must be board-approved
Network diagram with CDE1.2.3Current, dated, and signed
Data Flow Diagram (DFD)1.2.4Shows PAN flow through systems
CDE system inventory12.5.1Complete list with classification
Access management policy7.1MFA, least privilege
Cryptographic key management policy3.6-3.7Required if organisation manages keys
Incident response plan12.10Must have been tested
ASV scan results11.3.2Not more than 90 days old
Penetration test report11.4Not more than 12 months old
TPSP policies12.8Including a list of current supplier AOCs

Most common documentation mistakes:

  • Network diagrams not updated for 2 or more years – do not reflect cloud migrations
  • Missing DFD (many firms have a network diagram but do not map PAN flow)
  • Policies approved by the IT manager rather than the board (Requirement 12.1 requires board approval)
  • No cryptographic key management policy despite using encryption


PCI DSS assessment in 3 to 4 months and want to know whether your documentation is ready?

Patronusec conducts a pre-audit gap analysis – a review of your documentation and environment against PCI DSS v4.0.1 requirements. Output: a prioritised gap list with a remediation schedule before the formal assessment. Delivered within 10 working days.

Book a PCI DSS gap analysis


How do you verify TPSP suppliers before a PCI DSS assessment?

Your suppliers processing cardholder data or with CDE access (Third-Party Service Providers, TPSPs) must demonstrate their own PCI DSS compliance – and you must document this before the assessment.

PCI DSS v4.0.1 Requirement 12.8 obligates you to:

  • Maintain a list of all TPSPs with the scope of their access to CHD
  • Have written agreements with TPSPs containing PCI DSS security requirements
  • Monitor TPSP compliance status annually (via AOC or inclusion in your own assessment)
  • Document the division of PCI DSS control responsibilities (Responsibility Matrix)

How to obtain TPSP compliance confirmation:

  • An AOC (Attestation of Compliance) – document issued by the TPSP’s QSA following their audit
  • Visa Global Registry of Service Providers (for Visa-registered providers)
  • A Responsibility Matrix – a table specifying which PCI DSS controls belong to the TPSP and which to you

Typical TPSPs requiring verification:

Payment processor, payment gateway, cloud provider (AWS/Azure/GCP), hosting provider, SaaS managing cardholder data, payments integrator.

Patronusec Insight: TPSP management is one of the most commonly unsatisfied requirements in a first PCI DSS assessment. Clients assume “the processor is certified so we’re covered” – which is partially true, but ignores the obligation to document the division of control responsibilities. A QSA asks not only “is the supplier certified?” but also “how have you documented the division of controls between you and the supplier?” We help clients create Responsibility Matrices and AOC libraries for all in-scope TPSPs as a standard element of audit preparation.

How do you conduct an internal pre-audit before the formal QSA assessment?

A pre-audit (gap analysis) is the most cost-effective investment in PCI DSS certification. It allows gaps to be closed without time pressure and without the costs of remediation after a formal assessment.

What an effective pre-audit covers:

  • Documentation review against v4.0.1 requirements (policies, procedures, diagrams)
  • Technical assessment of key controls (MFA, encryption, key management, patch management)
  • Firewall configuration and segmentation review
  • Log and alert review
  • Access and privilege review
  • Vulnerability management process assessment
  • Review of ASV scan results and penetration test reports

PCI DSS audit preparation timeline:

StageBefore formal auditActivities
Scope assessment4 to 6 monthsCDE map, system identification, scope optimisation
Gap analysis3 to 4 monthsIdentifying documentation and technical gaps
Remediation2 to 3 monthsPolicies updated, controls implemented, training delivered
Pre-audit check4 to 6 weeksReadiness verification, ASV scans, penetration test
Stage 1 auditAudit startDocumentation review by the QSA
Stage 2 audit2 to 4 weeks after Stage 1Technical testing, interviews, control verification
AOCAfter findings closureROC and AOC issued

How do you work effectively with the QSA during the assessment?

A PCI DSS assessment is a collaborative project, not an inspection. A QSA who operates as a partner is an asset. A QSA who operates as a box-ticker is a burden.

How to prepare the team for QSA collaboration:

  • Appoint a single point of contact on the client side (project manager) – avoid the situation where the QSA receives 5 different answers from 5 different people
  • Prepare an evidence pack before Stage 2 begins – screenshots, logs, configurations, and policies in a single repository (SharePoint, Confluence, or Google Drive)
  • Brief the IT team on the scope of technical testing – for their peace of mind and for efficiency (nobody blocks QSA access)
  • Agree the format for findings communication – will the QSA report findings in ongoing communication or only in the final report?

What to expect from a good QSA:

  • Explanation of the intent behind a requirement, not only its literal wording
  • Remediation suggestions alongside findings
  • Availability for questions between formal audit sessions
  • Transparency on project status

FAQ – Preparing for a PCI DSS audit

How long does PCI DSS audit preparation take from scratch?

For an organisation starting from scratch (no controls in place, no documentation): 9 to 12 months to AOC. For an organisation with partial controls and current documentation: 4 to 6 months. Scope assessment and gap analysis conducted at the outset precisely define how many months are needed for a specific organisation.

What documents must I have ready before the first QSA meeting?

The absolute minimum: a current network diagram with the CDE marked, a Data Flow Diagram, a list of in-scope systems, and an information security policy approved by the board. Absence of any of these halts Stage 1 and requires remediation before it can continue.

Can I conduct a PCI DSS gap analysis internally?

Yes, if you have a team member with PCI DSS experience or a certified Internal Security Assessor (ISA). However, a gap analysis conducted by an external QSA adds further value: an independent perspective and knowledge of how a QSA interprets specific requirements in practice during an assessment.

What happens if the assessment reveals critical gaps (findings)?

The QSA issues findings with categories: minor, major, or critical. Findings do not automatically mean certification is refused – the client has time to remediate and the specific areas are re-reviewed. An AOC is issued after all major and critical findings are closed.

How much does PCI DSS audit preparation with Patronusec cost?

A gap analysis as a standalone service is priced based on scope – typically less than 20% of the cost of the formal assessment. Patronusec provides a fixed-price quotation after a free initial call. Clients who commission gap analysis, formal assessment, and penetration testing together receive preferential package pricing.

How do I start PCI DSS audit preparation with Patronusec?

Best to begin with a free 30-minute initial call – you describe your business model, transaction volume, and current environment; we confirm your PCI DSS level, the appropriate certification document, and what the first steps should be. We can start a scope assessment or gap analysis within 1 to 2 weeks of the initial call.


PCI DSS audit preparation – free consultation

Patronusec as an accredited QSA conducts both gap analysis and the formal ROC/SAQ assessment – the client works with one team from initial scope assessment to signed AOC. We specialise in fintech, e-commerce, and payment service providers across the UK and EU.

In a free 30-minute consultation we will help you:

  • Assess current readiness for a PCI DSS audit
  • Identify priority gaps to address before the assessment begins
  • Plan a realistic timeline and budget from today to AOC
  • Choose the right engagement model (gap analysis plus assessment versus annual support)

Free consultation | PCI DSS certification | Gap analysis PCI DSS | Penetration testing | Vulnerability scans ASV

Don't buy a pig in a poke -
request a free consultation and check how we can assist you.

Free consultation
Contact form

Use the contact form or contact us directly.

Patronusec Sp z o. o.

Head Office:
ul. Święty Marcin 29/8
61-806 Poznań, Polska

KRS: 0001039087
REGON: 525433988
NIP: 7831881739
D-U-N-S: 989454390
LEI: 259400NAR8ZOX1O66C64

To top