Executive Summary
This is a named client story, published with ZenithPay’s consent. ZenithPay Technologies Pvt Ltd, an Indian payments company, needed PCI DSS compliance with a hard business clock. The engagement ran April to June: gap closure, policy uplift, VAPT and the formal audit — ending in a passed audit and an issued Attestation of Compliance. Commercially sensitive details (transaction volumes, application specifics) are intentionally excluded at the client’s request.
Client Overview
ZenithPay Technologies Pvt Ltd is an Indian payments technology company. The engagement covered PCI DSS compliance end to end, with VAPT delivered by the same team.
- Client: ZenithPay Technologies Pvt Ltd (named with consent)
- Industry: Payments / Fintech
- Region: India
- Scope: PCI DSS compliance + VAPT
- Timeline: April – June (one quarter)
Challenge
ZenithPay came in with operational gaps against PCI DSS requirements and policies that did not match what the standard actually demands — a common state for payments companies that grew faster than their compliance documentation.
- Operational gaps against PCI DSS requirements
- Policy set not aligned to the standard’s actual requirements
- Security testing needed to satisfy the assessment
- A fixed business window: compliance had to land within the quarter
Objectives
- Close the operational gaps against PCI DSS
- Rebuild the policy set to match the standard
- Complete VAPT with findings remediated
- Pass the audit and obtain the Attestation of Compliance within the quarter
Our Approach
1. Gap Assessment
Mapped the environment against PCI DSS requirements and scored the operational and documentation gaps by audit risk.
2. Policy & Control Uplift
Rewrote the policy set to match the standard’s actual requirements and closed the operational gaps with named owners.
3. VAPT & Remediation
Ran vulnerability assessment and penetration testing, with findings remediated and retested by the same team.
4. Audit & AOC
Took the engagement through the formal audit to a passing result and the issued Attestation of Compliance.
Solution
- Requirement-mapped gap assessment with audit-risk scoring
- Policy set rebuilt to match PCI DSS requirements, with control owners assigned
- VAPT executed, findings remediated and retest-verified
- Formal audit completed to a passing result
Results
- Audit passed within the planned window
- Attestation of Compliance (AOC) issued
- Policy and operational baseline now matches the standard — maintainable, not one-off
- Kickoff to AOC inside one quarter (April–June)
Timelines and outcomes reflect the documented engagement record for this client; results vary with scope and readiness.
What We Delivered
- Scope definition and network/data-flow diagrams for the cardholder data environment
- Gap assessment against PCI DSS v4.0.1 with risk-ranked remediation plan
- Evidence pack per requirement (configurations, records, sampled artefacts)
- Formal validation deliverable — Report on Compliance or Self-Assessment Questionnaire with Attestation of Compliance
- Quarterly ASV scan coordination and remediation verification
The standard artefact set for this engagement type; per-client environment and architecture details are shared under NDA during procurement, not published.
Lessons Learned
- Scope decided the budget: every environment that touched cardholder data unnecessarily was cost — segmentation work done early paid for itself before the assessment started.
- v4.0.1’s future-dated controls (MFA for all CDE access, payment-page script controls) were the schedule risk; treating them as day-one requirements removed the crunch.
- Evidence produced continuously beat evidence assembled before the audit — the requests that stall assessments are always for artefacts nobody collected at the time.
Talk to the team that ran this engagement
This was a real PCI DSS Compliance & VAPT engagement. If you are preparing for the same, speak to a specialist who has delivered it — not a sales rep. We will give you a clear read on your scope, gaps and the fastest path, and reply within four business hours.
Explore PCI DSS QSA assessment · more case studies
Liked the case study? Share on:


