A payments startup had 90 days to achieve PCI DSS Level 1 certification or lose a $2.4M annual contract.
A Gold Coast payment facilitation startup was offered a $2.4M annual contract by a major national retailer — conditional on PCI DSS Level 1 compliance within 90 days. Their engineering team of six had no compliance experience. The CEO contacted us on a Friday afternoon. We had a fractional CTO on-site Monday morning.
The first week was a gap assessment against PCI DSS v4.0 requirements. We identified 47 remediation items across six domains: network segmentation, access control, encryption, logging and monitoring, vulnerability management, and physical security. Each item was scored by effort and criticality, and a 90-day sprint plan was designed with weekly milestones.
Critical architectural changes were prioritised first: network segmentation to isolate the cardholder data environment, WAF and IDS deployment, replacement of in-house key management with AWS KMS. We simultaneously engaged a QSA, managed all documentation production, and prepared the engineering team for assessment interviews.
The QSA assessment commenced at day 86. The Report on Compliance was issued at day 94. The enterprise contract was signed. No security incidents occurred during the engagement or in the 12 months following.
Compliance programmes succeed when led by someone who has done it before. The path through PCI DSS is well-mapped — you just need a guide who knows the map.
Book a free call with a CTO who has 27 years of hands-on experience — and a track record of measurable outcomes.