Working toward PCI DSS compliance? Choose what best describes your business.
Typical for your business May apply
Outsourced your payment processing? You may still have PCI DSS responsibilities. We can help you sort out which ones.
Choose Service provider or Merchant to see how you validate and how Ascend helps.
How you validate
A Report on Compliance from a QSA company, or SAQ D for Service Providers where a payment brand allows it. Your customers will ask for your AOC and responsibility matrix.
How Ascend helps
One firm covers your ROC, penetration and segmentation testing, and quarterly ASV scans.
Most merchants complete the Self-Assessment Questionnaire that matches how they accept payments. The largest need a Report on Compliance from a QSA company.
How Ascend helps
We confirm which SAQ you are eligible for, or perform your ROC assessment, help you close the gaps, and run the ASV scans and penetration tests your validation calls for.
One relationship for assessment, testing and scanning
Each service stands on its own. Together, they come from one firm that already knows your environment.
PCI DSS compliance
Your first assessment, or your next one
New to PCI DSS? We help you define your cardholder data environment (CDE), find the gaps against the requirements that apply, and explain what each one expects as you close them.
Already validated, or considering a different QSA company? We pick up at your next SAQ or Report on Compliance cycle, with a smooth transition and a thorough, independent assessment.
Scoping and segmentation review, including your network and data-flow diagrams
Gap assessment, with clear guidance on what each requirement expects
Internal, external and segmentation testing where your PCI DSS validation requires it, at least once every 12 months and after significant change. Comprehensive testing, scoped and agreed with you, using industry-accepted methodologies, with risk-ranked findings and an executive summary.
Network and application layer testing of your CDE perimeter and critical systems, including web applications and APIs
Segmentation testing where you use segmentation, every six months for service providers
Testing for SOC 2 Type II, customers, partners and internal assurance
Testing for SOC 2 Type II and other compliance frameworks, cyber insurance and your own risk management. Comprehensive testing, scoped and agreed with you, using industry-accepted methodologies, with risk-ranked findings and an executive summary.
Network and application layer testing of your environment, including web applications and APIs
Reporting ready for your management, auditors, customers and partners
Quarterly external scans where your PCI DSS validation requires them, managed for you through the Ascend ASV Scanning Portal: scoping, scheduling, findings review, disputes and rescans until you pass.
External IPs and domains that apply
Rescans until you pass, at no extra charge
Managed false-positive disputes
ASV scan reports with the Attestation of Scan Compliance
Scans are performed and attested by a PCI SSC Approved Scanning Vendor.
We put consultation back into professional services.
Ascend was founded on the belief that delivering a service is not the same as building a relationship. Here is what that means when you work with us.
One firm instead of multiple vendors
Your PCI DSS assessment, penetration testing and ASV scanning from one firm. Each engagement builds on the last: one relationship, timelines that work together, and a partner who is familiar with your business and environment.
Coverage across your compliance needs
With Ascend: PCI DSS, penetration testing and ASV scanning.
With our affiliated firm, Ascend Audit & Advisory: SOC 1, SOC 2 Type II, ISO 27002 assessments, ISO 27001 readiness and HIPAA.
Expertise that spans compliance, audit and security
Assessments led by a QSA who is also CISA and CISM certified, fluent in compliance and security, and able to explain both to your leadership.
Big-firm rigor, personal service
The credentials and standards you'd expect from a large firm, with the senior attention and lean cost structure of a boutique.
How we work
Free consultation
One QSA-led firm
Year-round partnership
Defensible reporting
Process
Your PCI DSS compliance journey, end to end
New to PCI DSS? Start at Scope.
Scope
Identify or confirm your scope.
Readiness
Find any gaps before you're assessed.
Remediate
Your team closes gaps; we answer questions.
Already validated? Join at Assess.
Assess
Evidence, validation and interviews.
Attest
Your ROC or SAQ, then your AOC.
Maintain
Year-round partnership, scans and tests.
Repeats annually Assess, Attest and Maintain
The result: prove PCI DSS compliance when and where it's needed.
Need SOC, ISO or HIPAA work? Our affiliated firm, Ascend Audit & Advisory, provides attestation and audit services with the same consultative approach.
Tell us about your compliance objectives, whether PCI DSS, penetration testing or ASV scanning. We'll consult with you on the requirements that apply and how to meet your objectives.