We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

PCI SSC-qualified QSA Company

PCI DSS assessment for payment aggregators

If you are an RBI-authorised payment aggregator or payment gateway, PCI DSS is not optional — RBI’s PA-PG guidelines require PCI DSS compliance before authorisation, and acquirers almost always insist on Level 1 (an on-site Report on Compliance) because you touch other people’s card flows. CyberSigma is a PCI SSC-listed QSA Company that takes aggregators and gateways end to end through PCI DSS v4.0.1 — scoping and CDE reduction, gap assessment, remediation support, the on-site QSA assessment, and the signed RoC and Attestation of Compliance (AoC) your bank and the card networks require.

Get a free PA-PG readiness snapshot →Book a 20-minute QSA call
Who needs it

Who this is for

Payment aggregators
RBI PA-authorised or in-application entities that collect and settle card payments for merchants.
Payment gateways
Technology providers routing card transactions who must evidence PCI DSS to partners and banks.
Acquirer-driven Level 1
Any fintech pushed to Level 1 by its acquirer or after a card-data compromise.
Scope & regulation

Scope and the rules that apply

Scope is your Cardholder Data Environment (CDE): every system that stores, processes or transmits card data, plus anything connected to it. For aggregators the CDE often sprawls across onboarding, routing, settlement and reconciliation — scope reduction (segmentation and tokenisation, aligned to RBI’s Card-on-File Tokenisation mandate) is the biggest cost lever.

Applicable: PCI DSS v4.0.1, under RBI’s PA-PG guidelines and the Master Direction on Digital Payment Security Controls, enforced through your acquiring bank and Visa/Mastercard/RuPay(NPCI)/Amex.

Timeline

How long it takes

Scoping & gap — 3–6 weeks
CDE definition, data-flow mapping and a prioritised remediation roadmap.
Remediation — variable
The bulk of the effort; we support your engineering and security teams throughout.
On-site RoC/AoC — 2–4 weeks
Evidence sampling, testing and production of the signed RoC and AoC.
Cost factors

What drives cost

  • CDE size after scope reduction — the single biggest driver
  • First-time vs repeat assessment and the maturity of existing evidence
  • Remediation and tooling (typically far larger than the QSA fee)
  • Recurring quarterly ASV scans and annual penetration testing
Evidence & deliverables

What you provide and receive

Required evidence
Segmentation proof, key management, MFA into the CDE, ASV scans, pentest reports, change tickets, logs with retention, and targeted risk analyses.
Deliverables
Gap-assessment report, evidence request list, the Report on Compliance (RoC) and the signed Attestation of Compliance (AoC).
Common failures

Where aggregators fail

  • Under-scoped CDE that unravels when the assessor samples settlement/reconciliation flows
  • Storing card data that tokenisation should have removed
  • MFA not enforced for all CDE access (a v4.0.1 hardening)
  • Missing quarterly ASV scans or overdue penetration testing
Proof

See how we’ve done it before

Relevant case study
A payment company reduced its CDE by 35% before assessment, cutting cost and audit effort. Read case studies →
Redacted sample deliverable
Inspect a redacted gap report first. Request a redacted sample →

Not sure how close you are to a clean ROC?

Get a free PCI DSS v4.0.1 readiness snapshot from a listed QSA — share your work email and we map your gaps and scope before the assessment.

PCI DSS for payment aggregators — FAQs

Does RBI require PCI DSS for payment aggregators?

Yes. RBI’s Payment Aggregator and Payment Gateway guidelines require PCI DSS compliance as a precondition for authorisation. Compliance is evidenced by the official PCI SSC AoC/RoC, not an unofficial certificate.

Will our acquirer insist on Level 1?

Almost always. Because aggregators and gateways touch other parties’ card flows, acquirers typically require Level 1 — an on-site assessment and Report on Compliance — regardless of your own transaction volume.

Can tokenisation reduce our scope?

Yes. Removing stored card data via tokenisation (aligned to RBI’s Card-on-File mandate) and segmenting the CDE are the most effective ways to reduce scope, cost and audit effort.

Talk to a listed QSA about your PA-PG obligation

Get a clear read on your CDE scope, gaps and the fastest path to a clean RoC/AoC for RBI authorisation. Reply within four business hours.

Book a 20-minute QSA consultation →

Ready to discuss your PCI DSS for payment aggregators requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.