We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

ShadvalPay case study hero background

ShadvalPay: One Hardening Programme, Three Frameworks: PCI DSS, ISO 27001 and VAPT

PCI SSC Qualified Security Assessor — CYBERSIGMA CONSULTING SERVICES LLP

QSA Authorised
CEMEA · Asia Pacific · USA

Executive Summary

This is a named client story, published with ShadvalPay’s consent. ShadvalPay, an Indian banking-payments company, needed three assurance outcomes at once — PCI DSS, ISO 27001 and security testing — without running three separate projects. The engagement ran February to July as ONE programme: shared gap assessment, one hardening effort mapped to both standards, and VAPT feeding evidence into both. The build-once-comply-many-times model, applied for real.

Client Overview

ShadvalPay operates in Indian banking payments. The engagement combined PCI DSS, ISO 27001 and VAPT into a single delivery programme.

  • Client: ShadvalPay (named with consent)
  • Industry: Banking payments / Fintech
  • Region: India
  • Scope: PCI DSS + ISO 27001 + VAPT
  • Timeline: February – July

Challenge

ShadvalPay came in with implementation and hardening gaps — controls that existed on paper but were not fully implemented or hardened to the level PCI DSS and ISO 27001 actually require.

  • Implementation gaps: controls documented but not fully operational
  • Hardening gaps across systems in scope for both standards
  • Two frameworks plus security testing needed without tripling the effort
  • One team on the client side serving all three workstreams

Objectives

  • Close implementation and hardening gaps once, mapped to both standards
  • Run VAPT with findings remediated and evidence reusable across frameworks
  • Deliver an audit-ready programme across PCI DSS and ISO 27001
  • Keep the effort proportionate: one programme, not three projects

Our Approach

1. Combined Gap Assessment

One assessment scored against PCI DSS and ISO 27001 simultaneously, so every gap carried both mappings from day one.

2. Hardening & Implementation

Closed the implementation gaps and hardened in-scope systems once — each fix evidenced for both frameworks.

3. VAPT & Remediation

Vulnerability assessment and penetration testing with remediation and retest, feeding evidence into both control sets.

4. Audit-Ready Delivery

Took the programme to audit readiness across both standards with a shared, traceable evidence base.

Solution

  • Single gap assessment double-mapped to PCI DSS and ISO 27001
  • One hardening and implementation effort, evidenced for both standards
  • VAPT with remediation and retest, reused across both evidence sets
  • Shared evidence base delivered audit-ready

Results

  • Implementation and hardening gaps closed across all in-scope systems
  • PCI DSS audit passed — Attestation of Compliance (AOC) issued
  • ISO 27001 certification achieved
  • VAPT findings remediated and retest-verified
  • Three assurance outcomes from one programme, February to July

Timelines and outcomes reflect the documented engagement record for this client; results vary with scope and readiness.

What We Delivered

  • Unified control framework mapped across all in-scope frameworks
  • Single evidence repository serving every audit from one collection effort
  • Per-framework gap assessments and remediation orchestration
  • Coordinated audit calendar across assessors and jurisdictions
  • Consolidated compliance reporting for leadership

The standard artefact set for this engagement type; per-client environment and architecture details are shared under NDA during procurement, not published.

Lessons Learned

  • One control, many mappings: building the control once and expressing it per framework cut the evidence burden roughly in proportion to the number of frameworks.
  • The audit calendar was the constraint to optimise — sequencing assessments so evidence windows overlapped avoided repeating collection.
  • Jurisdictional differences concentrated in data-residency and reporting duties; the control layer stayed common, the paperwork localised.
Facing a similar challenge?

Talk to the team that ran this engagement

This was a real PCI DSS + ISO 27001 + VAPT engagement. If you are preparing for the same, speak to a specialist who has delivered it — not a sales rep. We will give you a clear read on your scope, gaps and the fastest path, and reply within four business hours.

Abhay Singh, Director — Compliance & Penetration Testing
Led by our PCI DSS specialists — Abhay Singh · PCI SSC-qualified QSA professional

Explore PCI DSS QSA assessment · more case studies

Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne see all locations & addresses →