PCI-DSS compliance starts with precisely scoping the Cardholder Data Environment (CDE) — the systems that actually touch card data — since that scope drives everything that follows.
Work typically covers network segmentation review, a gap assessment against the 12 PCI-DSS v4.0 requirements, and remediation guidance, followed by support through either a Self-Assessment Questionnaire or a full Report on Compliance led by a Qualified Security Assessor, depending on transaction volume.
Requirements assessed
PCI Security Standards Council
PCI-DSS v4.0