Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →PCI DSS, the Payment Card Industry Data Security Standard, is a set of security requirements for any organization that stores, processes, or transmits payment card data. It is mandated by the major card brands and enforced through contracts with payment processors and banks. Compliance is validated annually, with requirements scaled to transaction volume.
The single most effective PCI move is to shrink scope: by routing card data through a compliant payment processor and never touching it directly, most companies sharply reduce what they have to secure and document.
Validation ranges from a Self-Assessment Questionnaire for smaller merchants to an audit by a Qualified Security Assessor for the largest. PCI DSS explicitly requires both regular vulnerability scanning and annual penetration testing.
traztech delivers PCI DSS scoping and readiness for startups and growth-stage companies, led by a published security researcher.
Book a callFor a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.
PCI DSS work almost always starts in the wrong place. Teams begin with controls before establishing their SAQ type, when the SAQ type determines how much of the standard applies at all.
Scope reduction saves more than any control implementation. Moving card data out of your environment, through a hosted page or an iframe, changes which questions you have to answer rather than how well you answer them.
It reduces your scope substantially but does not remove the obligation. You still complete and attest to a Self-Assessment Questionnaire, and if anything on your side ever touches a card number the picture changes.
PCI DSS v4.0.1, and several requirements that were future-dated have since come into force, so an assessment from a couple of years ago will be out of date.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.
Before you go
Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.
From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.