The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.
Proposal
The biggest win in PCI DSS usually comes from taking systems out of scope rather than adding new controls. We map where cardholder data travels, shrink the territory, close the gaps in what remains and organise the evidence file. You do not need to know which self-assessment applies: we identify it from your flow.
No price appears on this page. Scope does: what we do, how we run it, who runs it and what is not included. The people who read your request are the ones who will look after you, and they come back with the proposal and with time to talk it through.
First we shrink the scope. Then we protect what is left.
The biggest win in PCI DSS usually comes from taking systems out of scope rather than adding new controls. We map where cardholder data travels, shrink the territory, close the gaps in what remains and organise the evidence file. You do not need to know which self-assessment applies: we identify it from your flow.
Scope definition
We agree in writing what is in and what is out, and why. A badly defined scope is the most common cause of a project running over.
Scope reduction
Before protecting anything, we take out of scope everything that does not need to be there. That is where the biggest saving lives, and almost nobody does it first.
Gap assessment
We compare what exists today with what the standard requires and order it by risk and effort.
Implementation
We stand the controls up, write what has to exist on paper and train the people who operate them.
Evidence routine
We set out how each control proves it worked, with an owner and a frequency, so the audit does not turn into a scramble.
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.