
PCI services
PCI DSS v4.0.1 introduces updated requirements and enhanced validation methods that help organisations strengthen their data protection practices while improving reporting transparency.
- The PCI Data Scurity Standard (PCI DSS) sets the minimum standards, but it can be hard to follow and report on. Bastion's Qualified Security Assesors (QSAs) help your business secure payment card data and meet your PCI DSS requirements in a simplified manner.
- We have been a QSA (Qualified Security Assessor) company since 2017 (previously under Quantum) and a PCI 3D-Secure assessor since 2024.
- We have 2 QSAs and 2 AQSAs as well as a PCI 3D-Secure assessor.
PCI DSS V4.0.1
What's new in PCI DSS v4.0.1
Key updates every business needs to understand
PCI DSS v4.0.1 introduces updated requirements and enhanced validation methods that help organisations strengthen their data protection practices while improving reporting transparency.
- Brings major updates to how businesses validate and report on PCI DSS compliance.
- Helps ensure data security controls stay effective as threats and technology evolve.
- Introduces new requirements for ongoing assessments and stronger validation processes.
- Supports flexible, risk-based security by allowing customised controls with clear outcomes.
Our process
Why work with us
Frequently asked questions
What is PCI DSS and who needs to comply?
PCI DSS (Payment Card Industry Data Security Standard) is a global framework designed to protect cardholder data. Any organisation that stores, processes or transmits payment card information is required to comply with PCI DSS.
What are the new requirements in PCI DSS v4.0?
PCI DSS v4.0 introduces new validation methods, more flexible requirements, and greater emphasis on continuous security. Key changes include targeted risk analysis, expanded multi-factor authentication, and enhanced password and access controls.
How do I know if my business needs a Self-Assessment Questionnaire (SAQ) or a full QSA audit?
It depends on how your organisation processes card payments. Smaller or lower-risk merchants may qualify for an SAQ, while larger or more complex environments typically require a Qualified Security Assessor (QSA) to perform a full audit.
What happens if we fail a PCI DSS assessment?
Failing an assessment doesn’t automatically mean penalties, but it does expose your organisation to risk and potential non-compliance consequences. We’ll work with you to understand the gaps and develop a remediation plan to get you back on track.
How long does a PCI DSS assessment take?
The timeline depends on the size and complexity of your environment. A straightforward SAQ can take a few days, while a full QSA-led assessment may take several weeks from scoping through to reporting.
Talk to an expert
Shortland Street,
Auckland 1010 New Zealand
Brandon Street
Wellington 6011 New Zealand
120 Spencer Street
Melbourne 3000 Australia