⚠️ PCI DSS 4.0 is now fully enforced

PCI DSS Compliance — Protect Cardholder Data, Avoid Fines

BrightWorks IT helps merchants and service providers achieve and maintain PCI DSS 4.0 compliance. We handle gap assessments, network segmentation, vulnerability scanning, and SAQ preparation — so you can process payments with confidence.

  • Full PCI DSS 4.0 gap assessment & remediation
  • Network segmentation & cardholder data environment scoping
  • Quarterly vulnerability scanning & penetration testing
  • SAQ completion & Attestation of Compliance support
Call: (844) 333-2948

Get Your Free PCI Compliance Assessment

Find out where your organization stands with PCI DSS 4.0.

No obligation. We'll review your situation and provide a clear roadmap within 48 hours.

$4.88M
Average Data Breach Cost (2024)
Active Now
PCI DSS 4.0 Enforcement
64
New Requirements in PCI 4.0
$500K+
Potential Non-Compliance Fines

Non-Compliance = Lost Revenue & Brand Damage

Payment card fraud costs the industry billions annually. PCI DSS 4.0 raises the bar — and acquirers are cracking down on non-compliant merchants.

PCI DSS 4.0 introduced 64 new requirements

The new standard demands targeted risk analysis, enhanced authentication, automated log reviews, and client-side script management. Organizations that were compliant under 3.2.1 may have significant gaps under 4.0.

SAQ complexity overwhelms internal teams

There are 9 different SAQ types, and choosing the wrong one — or filling it out incorrectly — can leave you exposed. Most businesses underestimate the complexity until their acquirer pushes back.

Network segmentation failures are the #1 finding

If your cardholder data environment (CDE) isn't properly segmented, your entire network is in scope. That means every device, every server, every workstation must meet PCI requirements.

Breach liability falls on you

After a breach, non-compliant merchants face fines from card brands ($5K–$100K/month), forensic investigation costs, card reissuance fees, and potential loss of the ability to process payments entirely.

Talk to a PCI Expert →

Does PCI DSS Apply to Your Business?

If you answer "yes" to any of these, you need PCI DSS compliance:

You accept credit or debit card payments — in-store, online, or over the phone
You store, process, or transmit cardholder data in any form
You are a service provider that handles cardholder data for other businesses
You operate an e-commerce website with payment processing
Your acquirer or payment processor requires PCI validation
You have point-of-sale systems or payment terminals on your network

PCI DSS applies to every organization that stores, processes, or transmits cardholder data — regardless of size or transaction volume.

End-to-End PCI DSS Compliance Services

We don't just assess — we implement, validate, and maintain your PCI compliance year-round.

PCI DSS 4.0 Gap Assessment

Comprehensive evaluation of your cardholder data environment against all PCI DSS 4.0 requirements, including the 64 new controls introduced in the latest version.

CDE scoping • Gap analysis • Prioritized remediation

Network Segmentation & CDE Scoping

Properly segment your network to minimize the cardholder data environment scope, reducing compliance burden and cost while strengthening security.

Micro-segmentation • Firewall rules • Scope reduction

Vulnerability Scanning & Penetration Testing

Quarterly ASV scans, internal vulnerability scanning, and annual penetration testing by qualified assessors — all required by PCI DSS.

ASV scans • Internal scans • Pen testing

SAQ & Attestation of Compliance

We determine the correct SAQ type for your business, complete it accurately, and prepare your Attestation of Compliance for your acquirer.

SAQ selection • Documentation • AoC preparation

Security Control Implementation

Deploy encryption, tokenization, MFA, log monitoring, WAF, and access controls. We implement the technical controls PCI DSS 4.0 requires.

Encryption • Tokenization • WAF • MFA

Ongoing Compliance Monitoring

Continuous log monitoring, quarterly scans, annual assessments, and policy reviews to keep you compliant 365 days a year — not just during validation.

Continuous monitoring • Quarterly scans • Annual reviews

PCI DSS Merchant Levels at a Glance

Your merchant level determines validation requirements. Most businesses are Level 3 or 4 — but all levels must comply with PCI DSS.

Level 1 Level 2 Level 3 ⭐ Level 4
Transaction Volume6M+ / year1M–6M / year20K–1M e-comm<20K e-comm / <1M other
ValidationOn-site QSA auditSAQ + ASV scanSAQ + ASV scanSAQ + ASV scan
Pen Test RequiredYes (annually)Yes (annually)RecommendedRecommended
Typical Timeline3–6 months2–4 months1–3 months1–2 months

What Changed in PCI DSS 4.0

PCI DSS 4.0 is now fully enforced. Here are the key changes every merchant needs to address.

New in 4.0
MFA Everywhere
MFA required for all access to CDE, not just remote
New in 4.0
Script Management
Payment page scripts must be inventoried & monitored
New in 4.0
Targeted Risk Analysis
Documented risk analysis for each flexible requirement
New in 4.0
Automated Log Reviews
Automated mechanisms to detect security anomalies

PCI DSS 4.0 is fully in effect. Organizations must be compliant now.

Get Your PCI Assessment →

Trusted by Merchants Nationwide

★★★★★
"We were struggling with PCI compliance after our acquirer flagged us for non-compliance. BrightWorks IT came in, properly scoped our CDE, segmented our network, and got us fully compliant with PCI DSS 4.0 in under 3 months. Our acquirer was impressed, and we avoided what could have been devastating fines."
Michael Torres
CFO, Regional Retail Chain (42 Locations)

Frequently Asked Questions

What is PCI DSS 4.0?
PCI DSS 4.0 is the latest version of the Payment Card Industry Data Security Standard, published by the PCI Security Standards Council. It replaces version 3.2.1 and introduces 64 new requirements including enhanced authentication, client-side script controls, targeted risk analysis, and automated log review mechanisms. All organizations must now comply with the full 4.0 standard.
What is the difference between an SAQ and a QSA audit?
A Self-Assessment Questionnaire (SAQ) is a self-validation tool for smaller merchants (Levels 2–4). A QSA (Qualified Security Assessor) audit is an on-site assessment by a PCI-certified assessor, required for Level 1 merchants and some service providers. BrightWorks IT helps with both — we prepare you for QSA audits and complete SAQs on your behalf.
What happens if we're not PCI compliant?
Non-compliance can result in fines of $5,000–$100,000 per month from card brands, increased transaction fees, liability for fraud losses after a breach, forensic investigation costs ($50K–$500K+), and in extreme cases, loss of the ability to process credit card payments entirely. The financial and reputational damage from a breach far exceeds the cost of compliance.
How long does PCI compliance take?
Timeline depends on your merchant level, current security posture, and the scope of your cardholder data environment. Level 4 merchants with a simple setup can achieve compliance in 4–6 weeks. Complex multi-location environments may take 3–6 months. A gap assessment is the best first step to understand your specific timeline.
Do we need PCI compliance if we use a third-party payment processor?
Yes — using a third-party processor reduces your scope but doesn't eliminate your PCI obligations. You still need to complete the appropriate SAQ, ensure your network is properly segmented, and validate that your processor is PCI compliant. We help you understand exactly what's still in scope and handle it properly.
What is network segmentation and why does it matter?
Network segmentation isolates your cardholder data environment (CDE) from the rest of your network. Without proper segmentation, every system on your network is considered in-scope for PCI, dramatically increasing your compliance burden and cost. Effective segmentation is the single most impactful step to reduce PCI scope and strengthen security.
How much does PCI compliance cost?
Costs vary based on merchant level, transaction volume, environment complexity, and current security posture. A gap assessment is the best way to scope the effort. BrightWorks IT offers free initial consultations. Consider: the average payment card breach costs $4.88M. Compliance is always cheaper than a breach.

Don't Risk Your Ability to Process Payments

Partner with BrightWorks IT and achieve PCI DSS 4.0 compliance with confidence. Free assessment — no obligation.

📞 Call Now: (844) 333-2948