PCI DSS compliance for businesses in Uganda & East Africa
The Payment Card Industry Data Security Standard (PCI DSS) applies to any organisation that stores, processes or transmits cardholder data. We take you from scoping and gap analysis to a completed Self-Assessment Questionnaire (SAQ) or a Report on Compliance — reducing your scope, hardening your systems, and preparing the evidence so you can process card payments with confidence.
Who PCI DSS is for
Banks, fintechs, payment aggregators, merchants, e-commerce businesses, and any organisation that stores, processes or transmits cardholder data or influences the security of card transactions.
Why get certified
- Meet the requirements of banks and payment schemes (Visa, Mastercard)
- Reduce the scope — and cost — of your card-data environment
- Lower the risk of card-data breaches and fines
- Unlock the ability to process card payments at scale
What our PCI DSS engagement covers
A complete engagement — from the first gap analysis to keeping you compliant year after year.
Scoping & merchant/SP level assessment
We determine your PCI DSS scope, merchant or service-provider level, and the right validation route (SAQ vs RoC).
Gap analysis against PCI DSS
We assess your cardholder-data environment against the current PCI DSS requirements and prioritise remediation.
Scope reduction & segmentation
We help reduce and segment your card-data environment to cut both risk and ongoing compliance effort.
Remediation & documentation
We implement the required technical and policy controls and assemble the evidence.
SAQ / RoC preparation
We prepare your Self-Assessment Questionnaire or support your Report on Compliance and Attestation of Compliance.
The road to PCI DSS
A clear, five-stage path. We stay with you through every stage.
Scoping
We define your cardholder-data environment, validation level and the correct SAQ or RoC route.
Gap analysis
We assess your environment against PCI DSS and deliver a prioritised remediation plan.
Remediation
We implement and document the required controls and reduce your scope where possible.
Validation
We prepare your SAQ, or support a QSA through the Report on Compliance and Attestation of Compliance.
Maintain
We keep you compliant through ongoing scans, reviews and your annual re-validation.
Request a PCI DSS quote
Every engagement is fixed-scope — no open-ended billing. Because cost depends on your size, systems and current maturity, we prepare a tailored proposal after a short scoping call. Send us your details and we'll get back to you within 24 hours.
Request a quoteGet a free PCI DSS consultation
Tell us where your organisation is today and we'll get back to you within 24 hours with a clear, practical next step — no obligation.
Request a quote
We'll be in touch within 24 hours.
PCI DSS — frequently asked questions
Which PCI DSS level applies to us?
It depends on your transaction volume and role (merchant vs service provider). We determine your level during scoping and confirm whether you need a Self-Assessment Questionnaire or a full Report on Compliance.
Is PCI DSS an ISO standard?
No — PCI DSS is maintained by the PCI Security Standards Council, not ISO. It is a compliance requirement of the payment card brands and acquiring banks, and it pairs well with an ISO 27001 ISMS.
Do you issue the certification?
Formal validation is done via a Self-Assessment Questionnaire or by a Qualified Security Assessor (QSA). Our role is to reduce your scope, remediate the gaps and prepare all the evidence so validation is straightforward.