Updated: 5 July 2026
What is a PCI DSS audit and when is it required? A PCI DSS audit is a formal compliance assessment conducted by an accredited Qualified Security Assessor (QSA) or through a Self-Assessment Questionnaire (SAQ). It is required for all organisations that store, process, or transmit payment card data. Level 1 Merchants must complete a full ROC (Report on Compliance) audit with a QSA annually. Inadequate preparation results in findings, a remediation project, and a delayed certificate – for fintechs and e-commerce organisations, this means real business risk.
Preparing for a PCI DSS audit – at a glance:
- Scope assessment is step zero – without it, you do not know what will be assessed or what it will cost
- Documentation (policies, procedures, network diagrams, DFDs) must be current and approved before the audit begins – the QSA starts with documents
- An internal pre-audit (gap analysis) 3 to 4 months before the formal assessment allows gaps to be closed without time pressure
- Suppliers (TPSPs) must provide current AOCs or Responsibility Matrices before the assessment – this is the most commonly overlooked step
- Penetration tests and ASV scans must be completed and accepted before Stage 2 of the audit begins
- Patronusec as an accredited QSA conducts both pre-audit gap analysis and the formal ROC assessment – the client works with one team from initial scope assessment to signed AOC
Table of Contents
What is scope assessment and why is it step zero?
Scope assessment is the analysis of what falls within PCI DSS certification scope – which systems, networks, and processes touch cardholder data or could affect it. It is step zero because without it, you cannot:
- Know how many PCI DSS controls apply to your organisation
- Plan a realistic timeline and budget
- Determine which SAQ variant or ROC is appropriate
- Identify optimisations (tokenisation, segmentation) before the project begins
The scope assessment produces a scope document containing: a CDE map with boundaries, a list of connected-to systems, a Data Flow Diagram (DFD), and a network diagram with the CDE marked.
Organisations that skip scope assessment frequently discover during the assessment that their CDE is 3 times wider than they assumed – resulting in a 6 to 12 month delay to certification and remediation costs that were not budgeted.
Patronusec Insight: We have conducted scope assessments for dozens of organisations and every single one revealed at least one system the client had not included in the CDE but should have. The most common example: Active Directory servers managing accounts with access to CHD servers are connected-to and fall within scope. The client was certain that AD “doesn’t touch card data” – and they were right, but that is not the relevant classification under PCI DSS. This is why we conduct scope assessment as a separate stage before pricing the assessment. See our PCI DSS gap analysis.
How do you determine your merchant level and choose the right certification format?
Before preparing for an assessment, you need to know which PCI DSS level applies and what document your acquirer requires.
How merchant levels are determined:
Merchant levels are based on the number of card transactions per year per card scheme:
- Level 1: more than 6 million Visa or Mastercard transactions per year (or following a security incident)
- Level 2: 1 to 6 million transactions
- Level 3: 20,000 to 1 million e-commerce transactions
- Level 4: fewer than 20,000 e-commerce transactions, or fewer than 1 million other transactions
Service Provider levels depend on the volume of cardholder data stored, processed, or transmitted (threshold: 300,000 transactions per year).
Critical point: Your acquirer may require a higher standard of documentation than the minimum implied by your level. Check your contract and contact your acquirer’s compliance team before the project begins.
How do you build the documentation a QSA requires during a PCI DSS audit?
Documentation is the first subject of QSA evaluation – Stage 1 of the audit is a documentation review. Gaps at Stage 1 halt the audit until they are remediated.
Mandatory documents before a PCI DSS audit:
| Document | PCI DSS requirement | Notes |
|---|---|---|
| Information security policy | 12.1 | Must be board-approved |
| Network diagram with CDE | 1.2.3 | Current, dated, and signed |
| Data Flow Diagram (DFD) | 1.2.4 | Shows PAN flow through systems |
| CDE system inventory | 12.5.1 | Complete list with classification |
| Access management policy | 7.1 | MFA, least privilege |
| Cryptographic key management policy | 3.6-3.7 | Required if organisation manages keys |
| Incident response plan | 12.10 | Must have been tested |
| ASV scan results | 11.3.2 | Not more than 90 days old |
| Penetration test report | 11.4 | Not more than 12 months old |
| TPSP policies | 12.8 | Including a list of current supplier AOCs |
Most common documentation mistakes:
- Network diagrams not updated for 2 or more years – do not reflect cloud migrations
- Missing DFD (many firms have a network diagram but do not map PAN flow)
- Policies approved by the IT manager rather than the board (Requirement 12.1 requires board approval)
- No cryptographic key management policy despite using encryption
PCI DSS assessment in 3 to 4 months and want to know whether your documentation is ready?
Patronusec conducts a pre-audit gap analysis – a review of your documentation and environment against PCI DSS v4.0.1 requirements. Output: a prioritised gap list with a remediation schedule before the formal assessment. Delivered within 10 working days.
How do you verify TPSP suppliers before a PCI DSS assessment?
Your suppliers processing cardholder data or with CDE access (Third-Party Service Providers, TPSPs) must demonstrate their own PCI DSS compliance – and you must document this before the assessment.
PCI DSS v4.0.1 Requirement 12.8 obligates you to:
- Maintain a list of all TPSPs with the scope of their access to CHD
- Have written agreements with TPSPs containing PCI DSS security requirements
- Monitor TPSP compliance status annually (via AOC or inclusion in your own assessment)
- Document the division of PCI DSS control responsibilities (Responsibility Matrix)
How to obtain TPSP compliance confirmation:
- An AOC (Attestation of Compliance) – document issued by the TPSP’s QSA following their audit
- Visa Global Registry of Service Providers (for Visa-registered providers)
- A Responsibility Matrix – a table specifying which PCI DSS controls belong to the TPSP and which to you
Typical TPSPs requiring verification:
Payment processor, payment gateway, cloud provider (AWS/Azure/GCP), hosting provider, SaaS managing cardholder data, payments integrator.
Patronusec Insight: TPSP management is one of the most commonly unsatisfied requirements in a first PCI DSS assessment. Clients assume “the processor is certified so we’re covered” – which is partially true, but ignores the obligation to document the division of control responsibilities. A QSA asks not only “is the supplier certified?” but also “how have you documented the division of controls between you and the supplier?” We help clients create Responsibility Matrices and AOC libraries for all in-scope TPSPs as a standard element of audit preparation.
How do you conduct an internal pre-audit before the formal QSA assessment?
A pre-audit (gap analysis) is the most cost-effective investment in PCI DSS certification. It allows gaps to be closed without time pressure and without the costs of remediation after a formal assessment.
What an effective pre-audit covers:
- Documentation review against v4.0.1 requirements (policies, procedures, diagrams)
- Technical assessment of key controls (MFA, encryption, key management, patch management)
- Firewall configuration and segmentation review
- Log and alert review
- Access and privilege review
- Vulnerability management process assessment
- Review of ASV scan results and penetration test reports
PCI DSS audit preparation timeline:
| Stage | Before formal audit | Activities |
|---|---|---|
| Scope assessment | 4 to 6 months | CDE map, system identification, scope optimisation |
| Gap analysis | 3 to 4 months | Identifying documentation and technical gaps |
| Remediation | 2 to 3 months | Policies updated, controls implemented, training delivered |
| Pre-audit check | 4 to 6 weeks | Readiness verification, ASV scans, penetration test |
| Stage 1 audit | Audit start | Documentation review by the QSA |
| Stage 2 audit | 2 to 4 weeks after Stage 1 | Technical testing, interviews, control verification |
| AOC | After findings closure | ROC and AOC issued |
How do you work effectively with the QSA during the assessment?
A PCI DSS assessment is a collaborative project, not an inspection. A QSA who operates as a partner is an asset. A QSA who operates as a box-ticker is a burden.
How to prepare the team for QSA collaboration:
- Appoint a single point of contact on the client side (project manager) – avoid the situation where the QSA receives 5 different answers from 5 different people
- Prepare an evidence pack before Stage 2 begins – screenshots, logs, configurations, and policies in a single repository (SharePoint, Confluence, or Google Drive)
- Brief the IT team on the scope of technical testing – for their peace of mind and for efficiency (nobody blocks QSA access)
- Agree the format for findings communication – will the QSA report findings in ongoing communication or only in the final report?
What to expect from a good QSA:
- Explanation of the intent behind a requirement, not only its literal wording
- Remediation suggestions alongside findings
- Availability for questions between formal audit sessions
- Transparency on project status
FAQ – Preparing for a PCI DSS audit
How long does PCI DSS audit preparation take from scratch?
For an organisation starting from scratch (no controls in place, no documentation): 9 to 12 months to AOC. For an organisation with partial controls and current documentation: 4 to 6 months. Scope assessment and gap analysis conducted at the outset precisely define how many months are needed for a specific organisation.
What documents must I have ready before the first QSA meeting?
The absolute minimum: a current network diagram with the CDE marked, a Data Flow Diagram, a list of in-scope systems, and an information security policy approved by the board. Absence of any of these halts Stage 1 and requires remediation before it can continue.
Can I conduct a PCI DSS gap analysis internally?
Yes, if you have a team member with PCI DSS experience or a certified Internal Security Assessor (ISA). However, a gap analysis conducted by an external QSA adds further value: an independent perspective and knowledge of how a QSA interprets specific requirements in practice during an assessment.
What happens if the assessment reveals critical gaps (findings)?
The QSA issues findings with categories: minor, major, or critical. Findings do not automatically mean certification is refused – the client has time to remediate and the specific areas are re-reviewed. An AOC is issued after all major and critical findings are closed.
How much does PCI DSS audit preparation with Patronusec cost?
A gap analysis as a standalone service is priced based on scope – typically less than 20% of the cost of the formal assessment. Patronusec provides a fixed-price quotation after a free initial call. Clients who commission gap analysis, formal assessment, and penetration testing together receive preferential package pricing.
How do I start PCI DSS audit preparation with Patronusec?
Best to begin with a free 30-minute initial call – you describe your business model, transaction volume, and current environment; we confirm your PCI DSS level, the appropriate certification document, and what the first steps should be. We can start a scope assessment or gap analysis within 1 to 2 weeks of the initial call.
PCI DSS audit preparation – free consultation
Patronusec as an accredited QSA conducts both gap analysis and the formal ROC/SAQ assessment – the client works with one team from initial scope assessment to signed AOC. We specialise in fintech, e-commerce, and payment service providers across the UK and EU.
In a free 30-minute consultation we will help you:
- Assess current readiness for a PCI DSS audit
- Identify priority gaps to address before the assessment begins
- Plan a realistic timeline and budget from today to AOC
- Choose the right engagement model (gap analysis plus assessment versus annual support)
Free consultation | PCI DSS certification | Gap analysis PCI DSS | Penetration testing | Vulnerability scans ASV