We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Large Indian Payment Gateway case study hero background

Large Indian Payment Gateway: PCI DSS v4.0 with 35% CDE Scope Reduction and Zero Major Findings

PCI SSC Qualified Security Assessor — CYBERSIGMA CONSULTING SERVICES LLP

QSA Authorised
CEMEA · Asia Pacific · USA

Executive Summary

One of India's largest payment gateways — processing card transactions for thousands of merchants across web, app, and API channels — needed to transition from PCI DSS v3.2.1 to v4.0 while its infrastructure footprint kept growing. This engagement shows how disciplined scoping, tokenization, and segmentation turned an expanding assessment into a smaller, cleaner one, validated with zero major findings.

Client Overview

The client is one of India's largest payment gateways, operating multi-datacentre and cloud infrastructure across India and serving merchants nationwide. The regulatory driver was the mandatory PCI DSS v4.0 transition combined with acquirer and network (card scheme) obligations; the engagement covered the full cardholder data environment across two datacentres and a public-cloud footprint.

  • Industry: Payments / Payment Gateway (large enterprise)
  • Region: India (multi-datacentre + cloud)
  • Regulatory driver: PCI DSS v4.0 transition; acquirer and card-scheme mandates
  • Timeline: ~7 months from scoping to validated RoC
  • CyberSigma team: Lead QSA, two PCI consultants, network security architect, VAPT team

Challenge

Years of product growth had let cardholder data touch far more systems than necessary: merchant dashboards, reconciliation jobs, support tooling, and analytics pipelines were all in scope. A v4.0 assessment across the full estate would have been slow, costly, and high-risk.

  • Cardholder data flows spread across payment, reconciliation, support, and analytics systems
  • Flat network zones pulling non-payment systems into PCI scope
  • New v4.0 requirements (targeted risk analyses, authenticated scanning, expanded MFA) not yet operationalised
  • Assessment window fixed by acquirer and card-scheme deadlines
  • Prior assessments had grown longer each year as scope expanded

Objectives

  • Reduce the assessed CDE materially before the v4.0 assessment began
  • Design and validate network segmentation between CDE and corporate zones
  • Replace stored PANs with tokens wherever business processes allowed
  • Complete the full PCI DSS v4.0 QSA assessment on the acquirer timeline
  • Target zero major findings at validation

Our Approach

1. Data Discovery & Scope Definition

Automated PAN discovery plus data-flow workshops across payment, reconciliation, support, and analytics teams produced a verified inventory of every system that stored, processed, or transmitted cardholder data — and, critically, the list of systems that did not need to.

2. Tokenization & Descoping

Reconciliation, support, and analytics workflows were migrated to tokenized references so full PANs were confined to the core payment switch and vault. Legacy PAN stores were purged under documented retention decisions.

3. Network Segmentation & Validation

The CDE was isolated behind dedicated firewall zones with tightly defined rule sets; segmentation penetration testing confirmed non-CDE zones could not reach cardholder data, formally removing them from assessment scope.

4. v4.0 Control Uplift

New v4.0 obligations — targeted risk analyses, expanded MFA coverage, authenticated internal scanning, and payment-page script controls — were implemented with named control owners and evidence templates.

5. QSA Assessment & Validation

The QSA assessment ran against the reduced environment with pre-staged evidence packs per requirement family, interviews scheduled by control owner, and remediation of minor observations tracked to closure before sign-off.

Solution

  • Verified cardholder data inventory and data-flow maps across all business functions
  • Tokenization rollout that confined full PANs to the core payment switch and vault
  • Segmentation architecture with penetration-test validation formally descoping non-payment zones
  • PCI DSS v4.0 control uplift with named owners, targeted risk analyses, and evidence packs
  • Full QSA assessment through Report on Compliance and Attestation of Compliance

Results

  • Assessed CDE scope reduced by approximately 35% before the assessment began
  • Zero major findings at PCI DSS v4.0 validation
  • RoC and AoC delivered within the acquirer deadline (~7-month programme)
  • Assessment effort and evidence volume reduced against the prior cycle despite the v4.0 transition
  • Repeatable scoping and evidence model in place for annual revalidation

Timelines and outcomes reflect the documented engagement record for this client; results vary with scope and readiness.

What We Delivered

  • Scope definition and network/data-flow diagrams for the cardholder data environment
  • Gap assessment against PCI DSS v4.0.1 with risk-ranked remediation plan
  • Evidence pack per requirement (configurations, records, sampled artefacts)
  • Formal validation deliverable — Report on Compliance or Self-Assessment Questionnaire with Attestation of Compliance
  • Quarterly ASV scan coordination and remediation verification

The standard artefact set for this engagement type; per-client environment and architecture details are shared under NDA during procurement, not published.

Lessons Learned

  • Scope decided the budget: every environment that touched cardholder data unnecessarily was cost — segmentation work done early paid for itself before the assessment started.
  • v4.0.1’s future-dated controls (MFA for all CDE access, payment-page script controls) were the schedule risk; treating them as day-one requirements removed the crunch.
  • Evidence produced continuously beat evidence assembled before the audit — the requests that stall assessments are always for artefacts nobody collected at the time.
Facing a similar challenge?

Talk to the team that ran this engagement

This was a real PCI DSS v4.0 QSA Assessment & Scope Reduction engagement. If you are preparing for the same, speak to a specialist who has delivered it — not a sales rep. We will give you a clear read on your scope, gaps and the fastest path, and reply within four business hours.

Abhay Singh, Director — Compliance & Penetration Testing
Led by our PCI DSS specialists — Abhay Singh · PCI SSC-qualified QSA professional

Explore PCI DSS QSA assessment · more case studies

Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne see all locations & addresses →