Qantid
Class CScoped engagementRenews

PCI DSS Report on Compliance

A managed route to a PCI DSS Report on Compliance: scoping, remediation and evidence assembly, with the assessment performed by a Qualified Security Assessor.

Fee & intake

Sign in to see the engagement fee (plus 7.5% VAT), complete the intake form, save a draft if you need to, then pay to submit.

Renews
Every 12 months

Regulatory and standards basis

This engagement is performed against the following instruments. Each is cited in the deliverable at the point it is relied on.

  • PCI DSS v4.0.1
  • PCI SSC Report on Compliance reporting template

Who this is for

  • Level 1 service providers and merchants

What you receive

  1. 01Scoping, segmentation and remediation programme
  2. 02Evidence assembly against every applicable requirement
  3. 03QSA assessment coordination and finding closure
  4. 04Report on Compliance and Attestation of Compliance

How the engagement runs

  1. Phase 1

    Intake and scoping

    You complete an intake form. We issue a scoped quote within 3 business days.

  2. Phase 2

    Engagement start

    On acceptance and first milestone payment, the engagement team is assigned and introduced by name.

  3. Phase 3

    Fieldwork

    Document preparation, testing or application assembly, depending on the engagement. Progress and outstanding requests are visible in the portal throughout.

  4. Phase 4

    Review and sign-off

    Internal quality review, then approval under Qantid Limited's signature. For licence-application work, we prepare and facilitate the filing; the regulator decides the outcome.

  5. Phase 5

    Submission and closure

    Filing or delivery, then support through any regulator queries until the matter closes.

Accreditation disclosure

A Report on Compliance may only be issued by a PCI SSC-registered Qualified Security Assessor company. Qantid manages the programme; the named QSA performs the assessment and signs the report.

Questions

Who approves the deliverable?

A named member of the engagement team reviews it and a partner approves it. Their name, title and credentials are printed on the report, and the approval is recorded against the engagement in the portal.

Who signs it?

A Report on Compliance may only be issued by a PCI SSC-registered Qualified Security Assessor company. Qantid manages the programme; the named QSA performs the assessment and signs the report.

How is this priced?

The engagement fee is shown in your portal after you choose this service. You complete an intake form, pay the charge shown, then submit. Milestone billing may apply where the intake confirms a Class C schedule.

What happens next year?

The portal reminds you 90, 60 and 30 days before it is due, and you start a new version of this engagement pre-filled from the answers you gave last time. You update only what has changed, and you see a side-by-side of what changed before you submit.

Where do our documents live?

In private storage, accessible only through short-lived signed links, with every view and download logged. Nothing is attached to email. Our sub-processors and data residency are published on the trust page.

How do we pay?

By card through Stripe after you complete intake in the portal. You can save a draft without paying; submission happens only after payment succeeds.

Related engagements in Cybersecurity and Assurance

Business Continuity and Disaster Recovery Plan

Continuity and recovery planning built from a business impact analysis, with recovery objectives that reflect what your infrastructure can actually deliver.

CBN Risk-Based Cybersecurity Framework Assessment

An assessment against the CBN Risk-Based Cybersecurity Framework, producing the evidence base for your annual return.

Incident Response Plan and Playbooks

An incident response plan with scenario playbooks, written so an on-call engineer at 3am can follow it.