Skip to content

PCI DSS Gap Assessment Services

PCI DSS Gap Assessment Services

PCI Gap Assessment Services

Is your company PCI compliant?

A better question is whether you can prove your security controls meet PCI DSS requirements for your payment environment.

A PCI gap assessment gives your business an independent perspective of how your current security practices match PCI DSS, where the gaps are, and what you should fix before your next assessment or validation.

Tanner Security provides PCI DSS gap assessment services for businesses that accept, process, store, or transmit payment card data. We review your security controls, policies, procedures, payment environment, and supporting processes against applicable PCI DSS requirements.

Our consultants do more than just find missing controls. We explain why each gap matters, help you set priorities for fixing them, and give you a clear plan to improve your payment security program.

Schedule a PCI Gap Assessment

Talk with Tanner Security about your PCI environment, controls, and PCI requirements.

What Is a PCI Gap Assessment?

A PCI gap assessment compares your company’s existing security controls and practices against the PCI DSS requirements that apply to your environment.

The purpose is to identify the difference between where your security program is today and where it needs to be to address applicable PCI DSS requirements.

A gap assessment can help your company get ready for a formal PCI assessment, respond to customer needs, move to PCI DSS v4.0.1, address past assessment findings, or just understand weaknesses in your payment environment.

The assessment can examine both technical and administrative controls.

That may include access control, authentication, vulnerability management, network security, security policies, logging and monitoring, incident response, security testing, employee awareness, third-party relationships, and other controls relevant to your PCI scope.

The exact scope depends on how your business handles payment card data.

Why Conduct a PCI Gap Assessment?

PCI DSS has many detailed requirements, and many businesses find it hard to figure out which ones apply to them.

A gap assessment gives your company a way to answer that question before the validation process begins.

It can uncover issues such as outdated policies, incomplete documentation, insufficient access reviews, weak network vulnerability management processes, missing security evidence, inadequate network segmentation, or security controls that exist but do not operate as intended.

It can also reveal a bigger issue: having the wrong PCI scope.

A company that includes too many systems may create unnecessary compliance work. A company that excludes a system that can affect payment security may create a much more serious problem.

Tanner Security helps businesses understand their requirements and the associated security risks.

PCI DSS 4.0

PCI DSS 4.0.1 Gap Assessments

PCI DSS v4.0.1 is the latest version of the standard. PCI SSC released v4.0.1 to clarify requirements and fix errors. The v4.0 materials were retired on December 31, 2024.

For companies still using older PCI processes, this presents an opportunity to review existing controls against current requirements and identify controls that need attention.

Tanner Security can perform a gap assessment against the applicable PCI DSS v4.0.1 requirements and help your team understand what has changed from its previous compliance approach.

The objective is not simply to produce a longer checklist.

The objective is to identify the gaps that create meaningful compliance or security risk.

We were fortunate to have collaborated with Tanner IT Security Consultants. From the outset, John’s team exhibited a remarkable depth of knowledge and a clear understanding of our specific requirements.  

Andy W. – Chief Information Security Officer

Understanding Your PCI Scope

Before evaluating controls, your company needs to understand which systems and processes are included in the assessment.

The Cardholder Data Environment (CDE) includes systems and components that store, process, or transmit payment account data, along with other components that can affect the security of that environment.

PCI scope can be very different from one business to another.

An e-commerce company may rely on web applications, APIs, cloud infrastructure, payment-page integrations, and third-party processors.

A retailer may rely primarily on POS systems, payment terminals, internal networks, and supporting infrastructure.

A service provider may have entirely different responsibilities based on the services it provides and the systems it can access.

Tanner Security reviews your payment environment and helps you see where PCI requirements apply. This helps your company avoid wasting time on systems that are not in scope and ensures you do not miss systems that are.

Why Choose Tanner Security Consultants?

  1. Specialized Expertise: Our team of PCI experts brings extensive experience conducting PCI gap assessments across diverse business sectors. We stay updated with the ever-evolving PCI DSS requirements to provide accurate and relevant reviews.
  2. Tailored Solutions: Recognizing the uniqueness of each business, we offer personalized PCI gap assessments customized to your specific business needs and payment card data processes.
  3. Holistic Assessments: Our assessments delve into every aspect of your payment card data security, from network configurations and access controls to encryption protocols and employee training. We leave no stone unturned to ensure your compliance.
  4. Risk Mitigation: Identifying and addressing compliance gaps is critical to reducing the risk of data breaches and the associated financial and reputational damage. Our assessments offer actionable insights to help you prioritize security enhancements.
  5. Cost-Effective Approaches: Our cost-effective solutions will help you implement essential security measures efficiently and cost-effectively.

Ensure Your PCI DSS Compliance with Tanner Security

PCI DSS compliance protects payment card data and maintains customer trust. Partner with Tanner Security for expert PCI consulting services and ensure your organization meets the highest security and compliance standards. Contact us today to learn more about our services and how we can help you achieve PCI DSS compliance.

Identify Your PCI Compliance Gaps.

Get a roadmap for addressing all the PCI compliance the issues that matter most.

What Does a PCI Gap Assessment Evaluate?

A PCI gap assessment focuses on the controls that apply to your environment.

Depending on scope, Tanner Security can evaluate areas such as network security controls, secure configurations, account-data protection, encryption, malware protection, web application security, access control, authentication, physical security, logging and monitoring, vulnerability management, security testing, incident response, employee awareness, policies, and third-party service-provider management.

We also evaluate evidence supporting those controls.

For example, a business may have a written access-control policy but no documented evidence for reviews of privileged accounts.

A company may perform vulnerability scans but lack a consistent process for remediating critical findings.

A firm may maintain an incident-response plan but never test whether employees know what to do during an actual event.

A gap assessment uncovers these issues.

PCI CDE Penetration Testing Services

PCI Gap Assessment vs. PCI Penetration Testing

A gap assessment evaluates your cybersecurity controls and processes against applicable PCI DSS requirements.

A PCI penetration test takes a different approach by attempting controlled exploitation of technical weaknesses.

For example, a gap assessment may identify a weakness in network security controls. A penetration test can then determine whether an attacker could exploit that weakness to gain access to other systems.

The two services complement each other.

A gap assessment examines whether your controls address the requirements.

A penetration test examines what an attacker could actually do.

Our PCI Gap Assessment Process

Step 1: Understand Your Payment Environment: We begin by learning how your business accepts and processes payment card data. We review systems, applications, networks, payment providers, workflows, and relevant third-party relationships.

Step 2: Define PCI Scope: We help identify the Cardholder Data Environment and the systems and controls that can affect its security.

Step 3: Assess Current Controls: We compare your current security practices with the applicable PCI DSS requirements and document areas that require attention.

Step 4: Prioritize Gaps: We help your team prioritize remediation according to security risk, business impact, compliance requirements, and available resources.

Step 5: Remediate: Your team addresses identified deficiencies. Tanner Security can provide guidance with security controls, policies, technical remediation, vulnerability management, penetration testing, and other related activities.

Step 6: Prepare for Validation: We help your team prepare the evidence, documentation, testing results, and other materials required by your applicable PCI assessment process.

Step 7: Maintain Compliance: PCI compliance does not end when the assessment is complete. Updates to payment applications, infrastructure, vendors, networks, and security controls can all impact your PCI environment.

We help businesses view PCI compliance as an ongoing security process rather than just an annual paperwork task.

Who Needs a PCI Gap Assessment?

A PCI gap assessment can benefit businesses of many sizes and industries that handle payment card data.

Retailers, e-commerce companies, healthcare businesses, financial services firms, hospitality companies, professional services firms, software providers, and other small to medium sized businesses may use gap assessments to prepare for PCI validation or strengthen their payment security program.

Usually, how complex your payment environment is matters more than how many employees you have.

A small business with a simple outsourced payment process may have a relatively straightforward PCI environment. A larger business that operates its own payment applications, networks, databases, and integrations may require a much more detailed assessment.

PCI DSS Compliance for E-Commerce Businesses

E-commerce businesses face additional considerations because online payment transactions can involve web applications, payment pages, JavaScript, APIs, third-party scripts, payment processors, cloud infrastructure, and customer browsers.

PCI SSC provides specific guidance and validation criteria for e-commerce payment environments, including requirements related to payment-page scripts and their protection. The applicable SAQ and requirements depend on the company’s payment architecture and eligibility.

Tanner Security can review the IT environment and processes surrounding your online payment systems and help identify gaps that could affect PCI scope or security.

Get a Fixed-Fee PCI Gap Assessment Proposal

Talk with Tanner Security about your payment environment and assessment requirements.

PCI Gap Assessments and Third-Party Payment Providers

Using a third-party payment processor can make your payment environment simpler, but it does not automatically remove your PCI responsibilities.

Your company still needs to understand what systems remain in scope, what security responsibilities the provider assumes, and what evidence your business needs to maintain.

PCI SSC advises businesses completing SAQs to confirm their eligibility with the entity to which the SAQ will be submitted and to understand any more requirements or instructions.

Tanner Security can help your business evaluate these relationships and document the responsibilities that remain with your company.

Why Choose Tanner Security for a PCI Gap Assessment?

Tanner Security brings more than two decades of cybersecurity consulting experience to PCI assessments and related security projects.

Our broader services include PCI consulting, PCI CDE penetration testing, network penetration testing, vulnerability assessments, IT audits, IT risk assessments, policy development, and other cybersecurity services.

This broad experience helps our consultants understand how PCI requirements connect to real-world technology.

We do not treat a PCI gap as an isolated compliance issue.

A weakness in identity management, network segmentation, vulnerability management, cloud security, or application security can affect PCI compliance and create broader cybersecurity risks.

Our job is to explain these links and help your company focus on what matters most.

We also provide fixed-fee proposals based on the defined scope of work.

Additional PCI Consulting Services

Our PCI consulting services support your company from the initial scoping steps through compliance.

PCI 4.0 ConsultingWe provide expert guidance on navigating the new requirements and changes introduced in PCI DSS 4.0. Our consultants help you understand and implement these updates to ensure continued compliance and security.

PCI DSS Compliance AssessmentsA PCI compliance assessment provides a wider review of your security controls against applicable PCI DSS requirements. Tanner Security evaluates areas such as access control, authentication, vulnerability management, network security, security policies, logging, monitoring, incident response, and security testing. The goal goes beyond simply answering “yes” or “no.” We want your leadership team to understand where risks exist, why the controls matter, and what your company should do next.

PCI Policy ConsultingPCI DSS requires more than technical controls. Your company also needs policies and procedures that support the security of payment card data. Tanner Security can review and develop policies covering information security, acceptable use, access management, vulnerability management, incident response, third-party risk, security awareness, data retention, and other areas relevant to your PCI program. We focus on practical policies your employees can use, not just generic documents that get ignored.

PCI CDE Penetration TestingPenetration testing goes beyond identifying possible vulnerabilities. It attempts to determine whether an attacker can exploit weaknesses and what access that attacker could obtain. Tanner Security performs PCI CDE penetration testing to evaluate the security of systems and networks that support payment card processing. Our testing can include vulnerability identification, manual validation, exploitation, privilege escalation, lateral movement, and other techniques that fit the approved scope.

Network Vulnerability Assessment: Identify known vulnerabilities across systems, network infrastructure, and other technologies that support your payment environment.

Network Penetration Testing: Evaluate internal and external attack paths to determine whether attackers can exploit weaknesses and move through your environment.

Web Application Penetration Testing: Evaluate web applications and APIs for vulnerabilities involving authentication, authorization, session management, input validation, business logic, and other application-security risks.

Schedule Your PCI Gap Assessment

Talk with Tanner Security about your PCI environment and receive a clear, fixed-fee proposal.

PCI DSS Gap Assessment Services FAQ's

A PCI gap assessment compares your company’s current security controls and practices against applicable PCI DSS requirements. It identifies deficiencies and provides recommendations for closing those gaps.

A gap assessment helps your company identify issues before a formal PCI compliance audit, know its current compliance position, prioritize remediation, and reduce the risk of discovering significant issues late in the assessment process. Read more about navigating PCI compliance for small businesses.

A gap assessment focuses on identifying deficiencies and preparing for compliance. A formal PCI assessment or audit may involve a different validation methodology, evidence requirements, and reporting process. Your payment brand, acquirer, or other compliance-accepting entity determines the validation requirements.

Yes. PCI DSS v4.0.1 is the current version of the Payment Card Industry Data Security Standard. PCI SSC published it in June 2024 as a limited revision that clarified portions of the standard and corrected errors. PCI DSS v4.0 is a guide to help small businesses become compliant, if this is the direction your company is going.

No universal rule requires every business to hire an outside consultant for a gap assessment. However, businesses use gap assessments to prepare for validation, address customer requirements, understand their security posture, or identify deficiencies before an assessment.

The assessment can review network security, access controls, authentication, vulnerability management, encryption, secure configurations, logging, monitoring, policies, incident response, employee security practices, application security, third-party relationships, and other controls relevant to the company’s PCI scope.

A gap assessment can help your company understand and document PCI scope, which is one of the most important aspects of PCI compliance. Tanner Security reviews payment flows, systems, networks, applications, third parties, and security boundaries to help identify which environments require assessment.

The assessment itself does not automatically reduce scope. However, it can identify opportunities related to payment architecture, network segmentation, outsourcing, and security controls that may affect the scope. Your company should validate any scope decision through the applicable PCI assessment and compliance process.

No. Outsourcing payment processing can reduce certain responsibilities, but it does not automatically eliminate all PCI obligations. Your company still needs to understand which systems and controls remain within scope.

No. A gap assessment evaluates compliance controls and processes. A PCI penetration test evaluates technical security by attempting controlled exploitation. Companies may need both services.

No. A network vulnerability assessment identifies technical weaknesses, while a gap assessment evaluates the larger PCI security and compliance program.

The timeline depends on the complexity of the payment environment, existing security controls, scope, number of systems and applications, third-party relationships, and the amount of remediation required.

A straightforward environment may require a relatively focused engagement and could get completed in a week or two, while a complex CDE can require a longer assessment and remediation program and may take a few months to complete.

Pricing depends on scope rather than simply company size. Tanner Security provides fixed-fee proposals based on the systems, controls, payment environment, and level of assessment required. Read more about the typical penetration test costs for a PCI assessment.

PCI does not establish one universal requirement for every company to conduct an external gap assessment on a specific schedule. Many businesses perform a gap assessment before formal validation and repeat the review when significant changes affect the payment environment.

Yes. A gap assessment can help identify deficiencies and organize remediation before the formal assessment process. The specific validation method depends on your business, payment environment, and requirements established by the applicable compliance-accepting entity.