NetSPI Services
Services
Risk
Management
Compliance
Management
Assessment
Services
PCI/PA-DSS
Services
Advisory
Services
HITRUST
Services
CorrelatedVM™
Engine
 

PCI/PA-DSS Compliance Services

NetSPI is a full-spectrum PCI consulting firm, advising clients on their PCI posture and providing prescriptive guidance to address vulnerabilities and concerns for their PCI audit.

As a QSA, ASV, and PA-QSA, we work with clients from beginning to end, providing advisory services, pre-audit preparation, the on-site QSA audit, and the required ASV scanning services. NetSPI is among the few consulting firms that can provide a turnkey approach for merchants, service providers, and software vendors subject to PCI requirements.

NetSPI is also a business-focused team. We understand that our clients can't address PCI in a vacuum. We work with client staff creatively to address vulnerabilities and findings in a way that considers more than just adherence to the standard. We also look at operational concerns, financial restrictions, and technological capabilities in the context of PCI.

NetSPI is a true consulting firm - we do not sell product. Our goal is not only to help ensure compliance with PCI requirements, but also to incorporate best security practices in the organization. We work with clients to understand where additional technology investment in security makes sense, where compensating controls can be effective, and how existing investments can be best used.

Click any service below to read more about it:

PCI Compliance Assessment

NetSPI’s PCI Compliance Assessment allows organizations to evaluate their state-in-time compliance against the PCI Data Security Standard. Our detailed assessments provide the following components:

  • Gap Analysis – evaluate current environment and controls against the most current PCI Data Security Standard
  • Risk Prioritization – risk-based prioritization of non-compliant areas allows customers to address areas of highest risk
  • Remediation Strategy – detailed recommendations to remediate areas of non-compliance using a vendor-agnostic approach (NetSPI does not sell product)
  • SAQ – completed Self-Assessment Questionnaire
PCI Pre-Audit Assessment

NetSPI’s PCI pre-audit assessment allows first-time Level 1 merchants and service providers to identify gaps in compliance against the PCI Data Security Standard. Many organizations indicate they are compliant with the standards. However, organizations not having endured a Report on Compliance audit do not fully comprehend the level of detail required for successful validation. Our process assists organizations in preparing for the Report on Compliance.

PCI Report on Compliance

NetSPI’s PCI validation services provide merchants and service providers with annual onsite validation of the PCI Data Security Standard. As a QSA firm, NetSPI is certified to provide this independent validation. Our QSAs are experienced security professionals who understand your industry. Through this experience, our QSAs can recommend solutions, including compensating controls. Unlike other QSA organizations, NetSPI does not sell product, and our customers can rest assured that we are product-agnostic.

PCI Program Consulting

NetSPI’s program management services work with organizations to develop PCI programs. Often, organizations scramble near the time of audit to ensure that all controls are in place. But a requirement of PCI is to be compliant at all times, not at just the time of audit. NetSPI works with organizations to operationalize PCI, that is, to integrate PCI in the daily workflow of technology and security. By integrating PCI into their daily processes, organizations are better prepared for the audit and do not have to scramble to get technology or process implemented. Ultimately, this integration results in lower costs, more efficiency, and greater security.

PCI Quarterly ASV Scanning

As an Approved Scanning Vendor (ASV) qualified by the Payment Card Industry Security Standards Council (PCI SSC), NetSPI offers clients the Quarterly PCI/ASV Assessment to demonstrate compliance with the Payment Card Industry’s Data Security Standard (PCI DSS) and also to gain insight into their overall security posture. The Quarterly PCI/ASV Assessment will help clients identify and address the security issues that exist in their Internet-accessible environment, reduce risk to cardholder data and other sensitive information, and demonstrate compliance with PCI DSS requirement 11.2.

Penetration Testing

NetSPI's internal and external penetration tests provide clients with an understanding of the exposures related to their systems, applications, and sensitive information. Specifically, NetSPI leverages automated and manual processes to determine susceptibility to code, configuration, and patch-related vulnerabilities. During penetration tests NetSPI will attempt to gain unauthorized access to target systems and applications, escalate privileges in the target environment, and gain access to sensitive information such as cardholder data.

PA-DSS Report on Validation

NetSPI’s Payment Application validation services provide software vendors that develop applications that store, process, or transmit cardholder data as a part of authorization or settlement services with validation against the Payment Application Data Security Standard. Our PA-QSAs have an application development background as well as significant security experience.


Levels of merchants and service providers, and the required validations for each:

Merchant Levels
LevelMerchant CriteriaValidation ActionValidated By
1
  • Merchants processing over 6 million Visa or MasterCard transactions annually (all channels) or Global merchants identified as Level 1 by any Visa region
  • Any merchant that has suffered a breach that resulted in an account data compromise
  • Any merchant identified as a Level 1 through card brand reciprocity
  • Annual Report on Compliance (“ROC”)
  • Quarterly network scan
  • Attestation of Compliance Form
  • Qualified Security Assessor
  • Approved Scanning Vendor
2
  • Merchants processing 1 million to 6 million Visa or MasterCard transactions annually (all channels)
  • Annual Self-Assessment Questionnaire (“SAQ”)
  • Quarterly network scan
  • Attestation of Compliance Form
  • Annual Report on Compliance (“ROC”)
  • Merchant
  • Approved Scanning Vendor
  • Qualified Security Assessor (starting 12/31/2010)
3
  • Merchants processing 20,000 to 1 million Visa or MasterCard e-commerce transactions annually
  • Annual SAQ
  • Quarterly network scan
  • Attestation of Compliance Form
  • Merchant
  • Approved Scanning Vendor
4
  • Merchants processing less than 20,000 Visa e-commerce transactions annually and all other merchants processing up to 1 million Visa or MasterCard transactions annually
  • Annual SAQ recommended
  • Quarterly network scan
  • Compliance validation requirements set by acquirer
  • Merchant
  • Approved Scanning Vendor
Service Provider Levels
LevelService Provider CriteriaValidation ActionValidated By
1
  • VisaNet processors or any service provider that stores, processes and/or transmits over 300,000 transactions per year
  • Annual On-Site PCI Data Security Assessment
  • Quarterly Network Scan
  • Qualified Security Assessor
  • Approved Scanning Vendor
2
  • Any service provider that stores, processes and/or transmits less than 300,000 transactions per year
  • Annual PCI Self-Assessment Questionnaire
  • Quarterly Network Scan
  • Service Provider
  • Approved Scanning Vendor