PCI DSS, explained and handled in plain English.
Scoping, gap assessment, remediation and evidence collection for merchants and service providers who take card payments. We get you compliant and help you stay that way, without the jargon.
The problem
PCI DSS is simple in theory and confusing in practice.
The Payment Card Industry Data Security Standard exists to protect card data, and version 4 applies to any business that stores, handles or sends card numbers, from a single WooCommerce store to a full payment platform. Almost everyone who takes card payments falls under it somewhere.
Where it gets confusing is working out how much of it applies to you. The paperwork uses terms like SAQ type, scope reduction and sign-off as if they’re obvious, and most owners are left guessing which form to fill in and what it’s even asking.
We turn that into plain steps: what applies to your setup, what to fix first, and what proof you need to keep on file. If you run WooCommerce, we usually start by looking at exactly how payments flow through your store.
What’s involved
The 12 requirements, grouped simply.
Secure network and systems
Firewalls, secure setup, and no default vendor passwords anywhere near card data.
Protect card data
Encryption while data moves, and never storing more card data than you actually need.
Patch and scan
Anti-malware, and every system that touches card data kept patched and current.
Access control
Card data limited to people who need it, with a unique login for each person.
Watch and test
Logging, quarterly scans and a yearly penetration test on anything in scope.
Policy and rules
A written security policy your team actually follows, not a document nobody’s read.
Process
How we get you compliant.
Scoping
We map how card data flows through your systems and work out which SAQ type fits, or whether you need a full Report on Compliance.
Scope reduction
Where we can, we shrink scope first: a hosted payment page, tokens instead of real card numbers, and keeping card-data systems apart from the rest of your network.
Gap check
We check your current setup against the 12 rules and list exactly where you fall short, in plain language.
Fixes
We fix what we can directly, and hand your team or other suppliers clear steps for anything outside our reach.
Evidence and sign-off
We help you gather the proof your SAQ or QSA needs, and run the quarterly scans and yearly penetration test most categories require.
Who does what
What Maku does, and what needs a QSA.
We’re honest about where our role ends. Maku is not a Qualified Security Assessor, and we won’t claim to be one. What we do is get your systems ready: scoping, cutting scope where we can, fixing gaps, running the technical testing, and pulling evidence together.
Most merchants self-assess with an SAQ and never need a QSA. If your business falls into a category that needs a full Report on Compliance, an accredited QSA carries out that review, and we work alongside them, supplying the technical evidence and fixes they ask for rather than doing their job for them.
- Yearly penetration tests for PCI scope are covered by our penetration testing service.
- Ongoing advice between reviews, including scope checks when systems change, sits on our PCI consulting page.
- Pricing is quoted after scoping, since the work varies a lot between a single hosted checkout and a system that touches card data in several places. Tell us what you take payments through and we’ll scope it.
FAQ
Questions we get asked
Which SAQ am I?
It depends on how you take card payments. If you redirect fully to a hosted checkout like Stripe or PayPal and never touch card data yourself, you’re usually SAQ A, the simplest form. If you take card details directly, on your own server or through an embedded field, you’ll sit in a wider category with more rules. We work this out with you as the first step.
Do I need a QSA?
Most small and mid-size merchants self-assess with a Self-Assessment Questionnaire and don’t need a Qualified Security Assessor. Larger merchants, and some service providers, need a full Report on Compliance completed by an accredited QSA. Maku is not a QSA, but we help you scope, fix gaps and prepare evidence, and can work alongside your QSA when one’s required.
How long does this take?
A simple SAQ A merchant with a clean setup can often move through scoping and evidence in a couple of weeks. A larger business with card data touching several systems takes longer, especially if fixes are needed first. We’ll give you a real timeline once we’ve seen your setup.
What if we use Stripe or another hosted checkout?
Using a fully hosted payment page or a service like Stripe Checkout is the single biggest thing you can do to shrink your PCI scope, because card data never touches your servers. It doesn’t remove the requirement to comply, but it usually keeps you in the simplest SAQ category rather than a much heavier one.
What happens if we’re not compliant?
Your payment processor’s agreement sets the actual consequences, which can include fines or higher transaction fees, and they vary by processor and card scheme. We’re not going to invent a number here. Ask your processor what applies to your account, and treat compliance as an ongoing state rather than a one-off form.
How often do we need to do this?
Sign-off happens once a year for most merchants, alongside quarterly scans if you’re required to run them. Anything that changes your setup, like a new payment link or a platform move, is worth a scope review before your next sign-off rather than waiting for the yearly cycle.
What about WooCommerce specifically?
A WooCommerce store using a hosted or tokenised gateway usually stays in the simpler SAQ groups, but plugins, custom code and old links can quietly widen your scope if they ever touch raw card data. See our WooCommerce development page for how we build and check stores with this in mind.
Security
More Security services
-
Penetration testing
Web app, API, network and WordPress testing with a report you can act on.
-
PCI consulting
Ongoing advice for merchants and service providers: SAQs, scope reduction, evidence, audits.
-
Application licensing
Licensing, implementation and support for security platforms, quoted and managed through one team.
Engage
Building something ambitious?
Send us a few honest paragraphs about what you’re building, who it’s for and when you need it live. We’ll reply with a straight answer.