Our PCI DSS segmentation auditing service combines software that runs inside your own environment with independent, qualified validation reporting from our team. The software regularly audits the boundaries around your Cardholder Data Environment (CDE), and our qualified staff review the results and produce the technical validation reporting your assessor needs.
Why it matters
PCI DSS does not just ask you to design segmentation, it requires you to prove it keeps working. Merchants must validate their segmentation controls at least every twelve months, and service providers every six, as well as after any change to the controls that enforce them. If that evidence is missing or out of date, your assessor cannot rely on the boundary, and out-of-scope systems can be pulled straight back into your assessment, multiplying its time, cost, and risk. Regular auditing keeps that evidence current, which helps keep your compliance costs down.
How it works
You deploy the auditing software into your environment, where it runs on a regular, automated schedule. From each out-of-scope segment it reaches for systems inside your CDE, exactly as an attacker or a misconfigured host would, and records whether any route exists that should not. Our qualified staff then review the findings and produce clear, independent validation reporting covering what was tested, what was found, and the evidence your QSA needs to sign off your reduced scope with confidence.
Key features
- Segmentation auditing software that runs in your own environment, on-premises or in Google Cloud, AWS, and Azure environments
- Compatible with Kubernetes and as standalone deployment
- Regular, automated audits of every segmentation boundary
- Independent, qualified technical validation reporting for compliance