Qantid
Class CScoped engagementSigned by an accredited partnerRenews

PCI DSS Report on Compliance

A managed route to a PCI DSS Report on Compliance: scoping, remediation and evidence assembly, with the assessment performed by a Qualified Security Assessor.

Start in the portal

Sign in, complete the intake form for this service, then pay the engagement fee before submitting. You can save a draft so your answers are not lost.

Renews
Every 12 months

Regulatory and standards basis

This engagement is performed against the following instruments. Each is cited in the deliverable at the point it is relied on.

  • PCI DSS v4.0.1
  • PCI SSC Report on Compliance reporting template

Who this is for

  • Level 1 service providers and merchants

What you receive

  1. 01Scoping, segmentation and remediation programme
  2. 02Evidence assembly against every applicable requirement
  3. 03QSA assessment coordination and finding closure
  4. 04Report on Compliance and Attestation of Compliance

How the engagement runs

  1. Phase 1

    Intake and scoping

    You complete an intake form. We issue a scoped quote within 3 business days.

  2. Phase 2

    Engagement start

    On acceptance and first milestone payment, the engagement team is assigned and introduced by name.

  3. Phase 3

    Fieldwork

    Document preparation, testing or application assembly, depending on the engagement. Progress and outstanding requests are visible in the portal throughout.

  4. Phase 4

    Review and sign-off

    Internal quality review, then partner approval. Where a signature is a regulated act, the named accredited partner firm reviews and signs.

  5. Phase 5

    Submission and closure

    Filing or delivery, then support through any regulator or assessor queries until the matter closes.

Accreditation disclosure

A Report on Compliance may only be issued by a PCI SSC-registered Qualified Security Assessor company. Qantid manages the programme; the named QSA performs the assessment and signs the report.

Questions

Who approves the deliverable?

A named member of the engagement team reviews it and a partner approves it. Their name, title and credentials are printed on the report, and the approval is recorded against the engagement in the portal.

Who signs it?

A Report on Compliance may only be issued by a PCI SSC-registered Qualified Security Assessor company. Qantid manages the programme; the named QSA performs the assessment and signs the report.

What happens next year?

The portal reminds you 90, 60 and 30 days before it is due, and you start a new version of this engagement pre-filled from the answers you gave last time. You update only what has changed, and you see a side-by-side of what changed before you submit.

Where do our documents live?

In private storage, accessible only through short-lived signed links, with every view and download logged. Nothing is attached to email. Our security posture and data residency are published on the trust page.

How do we pay?

Sign in to the portal, choose this service, complete the intake form, then pay by card through Stripe. You can save a draft at any time before payment.

Related engagements in Cybersecurity and Assurance

Business Continuity and Disaster Recovery Plan

Continuity and recovery planning built from a business impact analysis, with recovery objectives that reflect what your infrastructure can actually deliver.

CBN Risk-Based Cybersecurity Framework Assessment

An assessment against the CBN Risk-Based Cybersecurity Framework, producing the evidence base for your annual return.

Incident Response Plan and Playbooks

An incident response plan with scenario playbooks, written so an on-call engineer at 3am can follow it.