We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

ZenithPay Technologies case study hero background

ZenithPay Technologies: PCI DSS Audit Passed and AOC Issued in One Quarter

PCI SSC Qualified Security Assessor — CYBERSIGMA CONSULTING SERVICES LLP

QSA Authorised
CEMEA · Asia Pacific · USA

Executive Summary

This is a named client story, published with ZenithPay’s consent. ZenithPay Technologies Pvt Ltd, an Indian payments company, needed PCI DSS compliance with a hard business clock. The engagement ran April to June: gap closure, policy uplift, VAPT and the formal audit — ending in a passed audit and an issued Attestation of Compliance. Commercially sensitive details (transaction volumes, application specifics) are intentionally excluded at the client’s request.

Client Overview

ZenithPay Technologies Pvt Ltd is an Indian payments technology company. The engagement covered PCI DSS compliance end to end, with VAPT delivered by the same team.

  • Client: ZenithPay Technologies Pvt Ltd (named with consent)
  • Industry: Payments / Fintech
  • Region: India
  • Scope: PCI DSS compliance + VAPT
  • Timeline: April – June (one quarter)

Challenge

ZenithPay came in with operational gaps against PCI DSS requirements and policies that did not match what the standard actually demands — a common state for payments companies that grew faster than their compliance documentation.

  • Operational gaps against PCI DSS requirements
  • Policy set not aligned to the standard’s actual requirements
  • Security testing needed to satisfy the assessment
  • A fixed business window: compliance had to land within the quarter

Objectives

  • Close the operational gaps against PCI DSS
  • Rebuild the policy set to match the standard
  • Complete VAPT with findings remediated
  • Pass the audit and obtain the Attestation of Compliance within the quarter

Our Approach

1. Gap Assessment

Mapped the environment against PCI DSS requirements and scored the operational and documentation gaps by audit risk.

2. Policy & Control Uplift

Rewrote the policy set to match the standard’s actual requirements and closed the operational gaps with named owners.

3. VAPT & Remediation

Ran vulnerability assessment and penetration testing, with findings remediated and retested by the same team.

4. Audit & AOC

Took the engagement through the formal audit to a passing result and the issued Attestation of Compliance.

Solution

  • Requirement-mapped gap assessment with audit-risk scoring
  • Policy set rebuilt to match PCI DSS requirements, with control owners assigned
  • VAPT executed, findings remediated and retest-verified
  • Formal audit completed to a passing result

Results

  • Audit passed within the planned window
  • Attestation of Compliance (AOC) issued
  • Policy and operational baseline now matches the standard — maintainable, not one-off
  • Kickoff to AOC inside one quarter (April–June)

Timelines and outcomes reflect the documented engagement record for this client; results vary with scope and readiness.

What We Delivered

  • Scope definition and network/data-flow diagrams for the cardholder data environment
  • Gap assessment against PCI DSS v4.0.1 with risk-ranked remediation plan
  • Evidence pack per requirement (configurations, records, sampled artefacts)
  • Formal validation deliverable — Report on Compliance or Self-Assessment Questionnaire with Attestation of Compliance
  • Quarterly ASV scan coordination and remediation verification

The standard artefact set for this engagement type; per-client environment and architecture details are shared under NDA during procurement, not published.

Lessons Learned

  • Scope decided the budget: every environment that touched cardholder data unnecessarily was cost — segmentation work done early paid for itself before the assessment started.
  • v4.0.1’s future-dated controls (MFA for all CDE access, payment-page script controls) were the schedule risk; treating them as day-one requirements removed the crunch.
  • Evidence produced continuously beat evidence assembled before the audit — the requests that stall assessments are always for artefacts nobody collected at the time.
Facing a similar challenge?

Talk to the team that ran this engagement

This was a real PCI DSS Compliance & VAPT engagement. If you are preparing for the same, speak to a specialist who has delivered it — not a sales rep. We will give you a clear read on your scope, gaps and the fastest path, and reply within four business hours.

Abhay Singh, Director — Compliance & Penetration Testing
Led by our PCI DSS specialists — Abhay Singh · PCI SSC-qualified QSA professional

Explore PCI DSS QSA assessment · more case studies

Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne see all locations & addresses →