We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

PCI SSC-qualified QSA Company · CERT-In empanelled

PCI DSS QSA assessment company in India

CyberSigma is a PCI SSC-listed Qualified Security Assessor (QSA) Company, authorised across CEMEA, Asia Pacific and the USA. If you are a bank, payment aggregator, payment gateway or fintech that stores, processes or transmits cardholder data, we take you end to end through PCI DSS v4.0.1 — scoping and gap assessment, remediation support, the on-site QSA assessment, and the signed Report on Compliance (RoC) and Attestation of Compliance (AoC) your acquiring bank and the card networks require. We assess and validate; the official AoC/RoC is your evidence of compliance.

Get a free PCI DSS readiness snapshot →Book a 20-minute QSA call
Who needs it

Who needs a PCI DSS QSA assessment

If you store, process or transmit cardholder data, your acquiring bank contractually obliges you to comply with PCI DSS. In India, RBI reinforces it — the Payment Aggregator and Payment Gateway (PA-PG) guidelines require PCI DSS compliance before authorisation, and any entity that suffers a card-data compromise is pushed to Level 1 and a mandatory on-site QSA audit.

Payment aggregators & gateways
Acquirers almost always insist on Level 1 (on-site RoC) regardless of your own volume, because you touch other people’s card flows.
Banks & NBFCs
Card issuing, acquiring and processing environments under RBI’s Master Direction on Digital Payment Security Controls.
FinTechs & merchants
Level 2–4 depending on annual card transaction volume — SAQ or RoC plus quarterly ASV scans.
Scope & regulation

What is in scope, and which rules apply

Scope (the CDE): every system that stores, processes or transmits cardholder data, plus anything connected to it. Getting the Cardholder Data Environment right is the highest-value decision you make — scope drives cost. We map data flows, define the CDE and use segmentation and tokenisation to shrink it.

Applicable regulation: PCI DSS v4.0.1 (the current standard; v3.2.1 retired March 2024, and a large block of v4.0.1 future-dated requirements became mandatory 31 March 2025). In India this sits underneath RBI’s PA-PG guidelines, the Card-on-File Tokenisation mandate and the Master Direction on Digital Payment Security Controls, all enforced through your acquiring bank and the card networks (Visa, Mastercard, RuPay/NPCI, American Express).

Timeline

How long a PCI DSS assessment takes

Scoping & gap assessment — 3–6 weeks
CDE definition, data-flow mapping, gap analysis against all applicable requirements, and a prioritised remediation roadmap.
Remediation — variable
The bulk of the effort. Depends on how far your controls and evidence are from the standard; we support your teams throughout.
On-site assessment & RoC/AoC — 2–4 weeks
Evidence sampling, testing procedures, and production of the signed Report on Compliance and Attestation of Compliance.

A first-time Level 1 assessment commonly runs three to six months end to end. PCI DSS compliance must generally be revalidated annually, with quarterly ASV scans and continuous control operation in between.

Cost factors

What drives PCI DSS assessment cost

  • Your PCI level and validation type (SAQ vs on-site RoC)
  • CDE size — number of in-scope systems, applications and data stores
  • Whether you have done this before, and the maturity of your existing evidence
  • Remediation and tooling (usually the largest line item — far larger than the QSA fee)
  • Recurring costs: quarterly ASV scans, annual penetration testing, continuous monitoring

Indicative ranges: first-time Level 1 payment aggregator ≈ 10–30 lakh QSA fee plus 25 lakh–1 crore+ remediation and tooling; Level 2 fintechs ≈ 4–10 lakh for assessment plus remediation. We give you a firm scope and quote before any commitment.

Evidence & responsibilities

What the assessment requires from you

Required evidence
Firewall/router rulesets with business justification, hardening baselines, key-management and data-retention proof, TLS configuration, MFA into the CDE, quarterly ASV scans, penetration-test reports, access reviews, change-management tickets, centralised logs with retention, and documented policies and targeted risk analyses.
Customer responsibilities
Provide system access and evidence, nominate a project owner, remediate identified gaps, run quarterly ASV scans, and maintain controls continuously between assessments. We lead the assessment; you own the environment.
Deliverables

What you receive

Gap assessment report
Control-by-control findings against PCI DSS v4.0.1, with a prioritised remediation roadmap.
Evidence request list
Exactly what to collect, so your teams are never guessing at assessment time.
Report on Compliance (RoC)
The formal on-site assessment output for Level 1 entities and aggregators.
Attestation of Compliance (AoC)
The signed PCI SSC form — the recognised evidence your acquirer and card schemes require.
Common audit failures

Where teams that passed v3.2.1 now fail v4.0.1

  • MFA not enforced for all access into the CDE (a v4.0.1 hardening)
  • No evidence of the new targeted risk analyses v4.0.1 requires
  • Firewall rules without documented business justification or six-monthly review
  • Missing quarterly ASV scans or overdue penetration testing
  • Under-scoped CDE that unravels on day two when the assessor samples evidence
  • Controls that pass on assessment day but drift the rest of the year
Proof

See how we’ve done it before

Relevant case study
A payment company reduced its CDE by 35% before assessment, cutting cost and audit effort. Read PCI DSS case studies →
Redacted sample deliverable
Want to inspect the quality of the work first? Request a redacted sample gap report →

Not sure how close you are to a clean ROC?

Get a free PCI DSS v4.0.1 readiness snapshot from a listed QSA — share your work email and we map your gaps and scope before the assessment.

PCI DSS QSA assessment — FAQs

Is CyberSigma a PCI SSC-qualified QSA Company?

Yes. CyberSigma Consulting Services LLP is a PCI SSC-listed Qualified Security Assessor (QSA) Company, authorised across CEMEA, Asia Pacific and the USA, staffed by qualified QSA Employees. We perform on-site PCI DSS assessments and sign the Report on Compliance (RoC) and Attestation of Compliance (AoC).

How much does a PCI DSS QSA assessment cost in India?

For a first-time Level 1 payment aggregator, expect roughly 10–30 lakh for the QSA assessment fee, plus 25 lakh to over 1 crore in remediation and tooling depending on your cardholder-data environment (CDE) size. Level 2 fintechs typically run 4–10 lakh for assessment plus remediation. The audit fee is usually the smallest line item — scope reduction is where the real savings are.

How long does a PCI DSS assessment take?

A first-time Level 1 assessment commonly runs three to six months end to end: scoping and gap assessment (3–6 weeks), remediation (variable), then the on-site assessment and RoC/AoC production. Well-scoped, evidence-ready environments finish faster.

Does CyberSigma issue a “PCI DSS certificate”?

No — and neither does any QSA. PCI SSC does not recognise unofficial “PCI DSS compliance certificates” as validation documents. The recognised evidence of PCI DSS validation is the official PCI SSC forms: the Attestation of Compliance (AoC) and Report on Compliance (RoC), which we produce as your QSA.

Can you help reduce our PCI DSS scope?

Yes. Scope reduction — segmentation, tokenisation and removing card data you do not need to store — is the single most valuable thing we do, because scope drives cost. Reducing your CDE from eighty servers to eight shrinks the assessment accordingly.

Talk to a listed QSA — not a sales rep

Get a clear read on your PCI DSS scope, gaps and the fastest path to a clean RoC/AoC. We reply within four business hours.

Book a 20-minute QSA consultation →

Ready to discuss your PCI DSS QSA assessment requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.