PCI DSS Compliance

Person using laptop computer

IRM is one of the country's leading Qualified Security Assessor  Companies (QSAC). Over the years we have gained a considerable amount of expertise in helping organisations with their PCI programmes and have the experience to apply a tailored and structured approach to helping organisations deliver successful PCI DSS projects that are risk based, proportionate, pragmatic and sustainable.

IRM treats every PCI DSS engagement as a unique undertaking that requires an understanding of the organisation and its culture to enable pragmatic and cost effective solutions for regulatory/contractual compliance. We have provided PCI services for many UK High Street names and across all industry sectors. Furthermore, we have the ability to leverage considerable expertise and apply 'lessons learned' experience for all types of merchant and service providers who may store, transmit or process credit card data.

Our approach

Methodology diagram

Why IRM?

IRM offers a well established and trusted service for managing merchant and service provider's payment card industry data security standard (PCI DSS) compliance objectives. With over 20 qualified security assessors (QSAs) from a cross section of the information security professional fraternity.

IRM is able to offer additional services to meet mandated requirements and leverage our core competency in security testing, such as scheduled quarterly external and internal vulnerability analysis and yearly network layer and application layer penetration testing, this effectively makes IRM a potential 'one-stop' shop for all your PCI DSS compliance needs. Our stated goal is to become trusted advisors to organisations for all things relating to PCI.

IRM has established long standing partnerships with the credit card payment brands such a Visa and MasterCard, along with most of the UK acquiring banks, actively involved in special interest groups and cross industry forums that continually strive to make the PCI standard more relevant and aligned to current thinking on risk, whilst actively lobbying for the adoption of realistic and appropriate controls for a continually changing threat landscape.