Home / Consulting / PCI DSS
Information Security & Data Protection

PCI DSS compliance for businesses in Uganda & East Africa

The Payment Card Industry Data Security Standard (PCI DSS) applies to any organisation that stores, processes or transmits cardholder data. We take you from scoping and gap analysis to a completed Self-Assessment Questionnaire (SAQ) or a Report on Compliance — reducing your scope, hardening your systems, and preparing the evidence so you can process card payments with confidence.

Who PCI DSS is for

Banks, fintechs, payment aggregators, merchants, e-commerce businesses, and any organisation that stores, processes or transmits cardholder data or influences the security of card transactions.

Why get certified

  • Meet the requirements of banks and payment schemes (Visa, Mastercard)
  • Reduce the scope — and cost — of your card-data environment
  • Lower the risk of card-data breaches and fines
  • Unlock the ability to process card payments at scale

What our PCI DSS engagement covers

A complete engagement — from the first gap analysis to keeping you compliant year after year.

Scoping & merchant/SP level assessment

We determine your PCI DSS scope, merchant or service-provider level, and the right validation route (SAQ vs RoC).

Gap analysis against PCI DSS

We assess your cardholder-data environment against the current PCI DSS requirements and prioritise remediation.

Scope reduction & segmentation

We help reduce and segment your card-data environment to cut both risk and ongoing compliance effort.

Remediation & documentation

We implement the required technical and policy controls and assemble the evidence.

SAQ / RoC preparation

We prepare your Self-Assessment Questionnaire or support your Report on Compliance and Attestation of Compliance.

The road to PCI DSS

A clear, five-stage path. We stay with you through every stage.

01

Scoping

We define your cardholder-data environment, validation level and the correct SAQ or RoC route.

02

Gap analysis

We assess your environment against PCI DSS and deliver a prioritised remediation plan.

03

Remediation

We implement and document the required controls and reduce your scope where possible.

04

Validation

We prepare your SAQ, or support a QSA through the Report on Compliance and Attestation of Compliance.

05

Maintain

We keep you compliant through ongoing scans, reviews and your annual re-validation.

Request a PCI DSS quote

Every engagement is fixed-scope — no open-ended billing. Because cost depends on your size, systems and current maturity, we prepare a tailored proposal after a short scoping call. Send us your details and we'll get back to you within 24 hours.

Request a quote

Get a free PCI DSS consultation

Tell us where your organisation is today and we'll get back to you within 24 hours with a clear, practical next step — no obligation.

Accredited consultants and practising auditors
Case studies from real East African industry
Fixed-scope proposals — no open-ended billing

Request a quote

We'll be in touch within 24 hours.

PCI DSS — frequently asked questions

Which PCI DSS level applies to us?

It depends on your transaction volume and role (merchant vs service provider). We determine your level during scoping and confirm whether you need a Self-Assessment Questionnaire or a full Report on Compliance.

Is PCI DSS an ISO standard?

No — PCI DSS is maintained by the PCI Security Standards Council, not ISO. It is a compliance requirement of the payment card brands and acquiring banks, and it pairs well with an ISO 27001 ISMS.

Do you issue the certification?

Formal validation is done via a Self-Assessment Questionnaire or by a Qualified Security Assessor (QSA). Our role is to reduce your scope, remediate the gaps and prepare all the evidence so validation is straightforward.