PCI DSS assessment for payment aggregators
If you are an RBI-authorised payment aggregator or payment gateway, PCI DSS is not optional — RBI’s PA-PG guidelines require PCI DSS compliance before authorisation, and acquirers almost always insist on Level 1 (an on-site Report on Compliance) because you touch other people’s card flows. CyberSigma is a PCI SSC-listed QSA Company that takes aggregators and gateways end to end through PCI DSS v4.0.1 — scoping and CDE reduction, gap assessment, remediation support, the on-site QSA assessment, and the signed RoC and Attestation of Compliance (AoC) your bank and the card networks require.
Who this is for
Scope and the rules that apply
Scope is your Cardholder Data Environment (CDE): every system that stores, processes or transmits card data, plus anything connected to it. For aggregators the CDE often sprawls across onboarding, routing, settlement and reconciliation — scope reduction (segmentation and tokenisation, aligned to RBI’s Card-on-File Tokenisation mandate) is the biggest cost lever.
Applicable: PCI DSS v4.0.1, under RBI’s PA-PG guidelines and the Master Direction on Digital Payment Security Controls, enforced through your acquiring bank and Visa/Mastercard/RuPay(NPCI)/Amex.
How long it takes
What drives cost
- CDE size after scope reduction — the single biggest driver
- First-time vs repeat assessment and the maturity of existing evidence
- Remediation and tooling (typically far larger than the QSA fee)
- Recurring quarterly ASV scans and annual penetration testing
What you provide and receive
Where aggregators fail
- Under-scoped CDE that unravels when the assessor samples settlement/reconciliation flows
- Storing card data that tokenisation should have removed
- MFA not enforced for all CDE access (a v4.0.1 hardening)
- Missing quarterly ASV scans or overdue penetration testing
See how we’ve done it before
Not sure how close you are to a clean ROC?
Get a free PCI DSS v4.0.1 readiness snapshot from a listed QSA — share your work email and we map your gaps and scope before the assessment.
PCI DSS for payment aggregators — FAQs
Does RBI require PCI DSS for payment aggregators?
Yes. RBI’s Payment Aggregator and Payment Gateway guidelines require PCI DSS compliance as a precondition for authorisation. Compliance is evidenced by the official PCI SSC AoC/RoC, not an unofficial certificate.
Will our acquirer insist on Level 1?
Almost always. Because aggregators and gateways touch other parties’ card flows, acquirers typically require Level 1 — an on-site assessment and Report on Compliance — regardless of your own transaction volume.
Can tokenisation reduce our scope?
Yes. Removing stored card data via tokenisation (aligned to RBI’s Card-on-File mandate) and segmenting the CDE are the most effective ways to reduce scope, cost and audit effort.
Talk to a listed QSA about your PA-PG obligation
Get a clear read on your CDE scope, gaps and the fastest path to a clean RoC/AoC for RBI authorisation. Reply within four business hours.
Book a 20-minute QSA consultation →Ready to discuss your PCI DSS for payment aggregators requirement?
CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.
