Executive Summary
This is a named client story, published with ShadvalPay’s consent. ShadvalPay, an Indian banking-payments company, needed three assurance outcomes at once — PCI DSS, ISO 27001 and security testing — without running three separate projects. The engagement ran February to July as ONE programme: shared gap assessment, one hardening effort mapped to both standards, and VAPT feeding evidence into both. The build-once-comply-many-times model, applied for real.
Client Overview
ShadvalPay operates in Indian banking payments. The engagement combined PCI DSS, ISO 27001 and VAPT into a single delivery programme.
- Client: ShadvalPay (named with consent)
- Industry: Banking payments / Fintech
- Region: India
- Scope: PCI DSS + ISO 27001 + VAPT
- Timeline: February – July
Challenge
ShadvalPay came in with implementation and hardening gaps — controls that existed on paper but were not fully implemented or hardened to the level PCI DSS and ISO 27001 actually require.
- Implementation gaps: controls documented but not fully operational
- Hardening gaps across systems in scope for both standards
- Two frameworks plus security testing needed without tripling the effort
- One team on the client side serving all three workstreams
Objectives
- Close implementation and hardening gaps once, mapped to both standards
- Run VAPT with findings remediated and evidence reusable across frameworks
- Deliver an audit-ready programme across PCI DSS and ISO 27001
- Keep the effort proportionate: one programme, not three projects
Our Approach
1. Combined Gap Assessment
One assessment scored against PCI DSS and ISO 27001 simultaneously, so every gap carried both mappings from day one.
2. Hardening & Implementation
Closed the implementation gaps and hardened in-scope systems once — each fix evidenced for both frameworks.
3. VAPT & Remediation
Vulnerability assessment and penetration testing with remediation and retest, feeding evidence into both control sets.
4. Audit-Ready Delivery
Took the programme to audit readiness across both standards with a shared, traceable evidence base.
Solution
- Single gap assessment double-mapped to PCI DSS and ISO 27001
- One hardening and implementation effort, evidenced for both standards
- VAPT with remediation and retest, reused across both evidence sets
- Shared evidence base delivered audit-ready
Results
- Implementation and hardening gaps closed across all in-scope systems
- PCI DSS audit passed — Attestation of Compliance (AOC) issued
- ISO 27001 certification achieved
- VAPT findings remediated and retest-verified
- Three assurance outcomes from one programme, February to July
Timelines and outcomes reflect the documented engagement record for this client; results vary with scope and readiness.
What We Delivered
- Unified control framework mapped across all in-scope frameworks
- Single evidence repository serving every audit from one collection effort
- Per-framework gap assessments and remediation orchestration
- Coordinated audit calendar across assessors and jurisdictions
- Consolidated compliance reporting for leadership
The standard artefact set for this engagement type; per-client environment and architecture details are shared under NDA during procurement, not published.
Lessons Learned
- One control, many mappings: building the control once and expressing it per framework cut the evidence burden roughly in proportion to the number of frameworks.
- The audit calendar was the constraint to optimise — sequencing assessments so evidence windows overlapped avoided repeating collection.
- Jurisdictional differences concentrated in data-residency and reporting duties; the control layer stayed common, the paperwork localised.
Talk to the team that ran this engagement
This was a real PCI DSS + ISO 27001 + VAPT engagement. If you are preparing for the same, speak to a specialist who has delivered it — not a sales rep. We will give you a clear read on your scope, gaps and the fastest path, and reply within four business hours.
Explore PCI DSS QSA assessment · more case studies
Liked the case study? Share on:


