PCI DSS preparation for anyone who takes card payments.
F Creative Studio 360 helps merchants and service providers in any country see how cardholder data is handled, and what still sits in scope. We do not issue the attestation of compliance.
The card brands set the standard. Your bank enforces it.
PCI DSS applies where cardholder data is stored, processed or transmitted, in any country. The level, and whether a qualified security assessor is required, depends on volume and on the acquirer. F Creative Studio 360 prepares and reviews. The formal attestation, where one is required, is signed by the party the standard names.
Using a hosted payment page can shrink the scope. It does not remove the checkout, the scripts on that page, or the network that reaches the provider.
- Scope is the first decision
- What touches card data, and what can be kept away from it.
- Stores and websites together
- Point-of-sale and the online checkout are one programme when both take cards.
- We are not the assessor of record
- Unless a formal assessment is separately agreed with a party allowed to sign it, our work is a gap review and remediation support.
- A breach is a different engagement
- Forensic investigation after a card incident is not included by default, and we do not file a card-brand report unless instructed, and not as policy advice.
What the review covers
The cardholder-data environment you describe. We do not assume every system in the company.
- Where card data flows
- Checkout, terminals, gateways, and any place a number is stored.
- Segmentation
- Whether the payment systems are separated from the rest of the business.
- The requirements in scope
- Mapped to the version of PCI DSS the acquirer expects.
- Evidence
- What you could show, and what is missing.
How an engagement runs
Merchants with shops or sites in more than one country can scope one brand or all of them.
- 1
Draw the flow
From the card to the acquirer, including third parties.
- 2
Cut the scope
Where a hosted field or a token can take data out of your systems.
- 3
Compare with the standard
Gaps, not a pass mark.
- 4
Hand back the order
What to fix before an assessor, if you need one, arrives.
What you receive
- A scope description of the cardholder environment.
- A gap list against PCI DSS.
- A note of what would still need a qualified assessor.
- No attestation of compliance from F Creative Studio 360.
Payment security is the neighbour
Testing the checkout and the scripts on it is a payment-security engagement. This page is the standard and the scope.
Common questions
Does PCI DSS apply outside one country?+
Yes. It is a card-brand rule for anyone who handles cardholder data. Local privacy law can sit beside it when that law applies.
Will you sign our attestation?+
No. We prepare the gaps and the evidence. The attestation is signed by the party the standard and your acquirer require.
Where do you deliver this?+
For organisations in any country. A local rule is used only when that organisation is actually subject to it. F Creative Studio 360 does not limit the work to one jurisdiction.
How much does it cost, and how long does it take?+
It depends on the systems in scope and whether you want an assessment only or help afterwards. A scoping conversation with F Creative Studio 360 is the way to get a quote. There is no obligation to proceed.
Draw the card flow before you buy a tool.
F Creative Studio 360 will look at how you take payments, then say what is still in scope.
