Transform Customer Experience with Virtual Agents + Data + AI — Discover Now
>>

PCI Compliance & Assessment

Online is pleased to be recognized as a PCI DSS Qualified Security Assessor Company in Gartner’s Market Guide for PCI DSS Qualified Security Assessment Services.

Payment Card Industry (PCI) compliance is the by-product of a robust security program. We help ensure that your program is sustainable while aligning with business objectives.

If you are an entity that stores, processes, or transmits cardholder data, or if your company provides services to organizations where you could impact the security of their payment card data environments, you are required to comply with the PCI DSS.

Organizations that don’t protect cardholder data are subject to penalties and fines, not to mention increased financial and reputational risk. Online's proven risk-based approach to PCI assessments while focusing strongly on business objectives, people, processes technology, and culture has helped hundreds of clients achieve and maintain PCI compliance.

Online speaks PCI DSS v4.0!

Our consultants have spent thousands of hours reviewing v4.0 and are prepared to help you interpret how these changes affect your environment.

To learn more about how these changes will impact you, visit our PCI v4.0 Resource Center. And remember - the sooner you fall behind, the more time you have to catch up!

Show me more
PCI SERVICES AT ONLINE

Asset Management

Cardholder and PII Data Discovery

Secure Code Training

PCI Readiness Assessments

PCI Trusted Advisor Consulting Services

Risk Assessments

Remediation Consulting including Prioritized Roadmaps

Penetration Test Services (Network, Application, and Segmentation)

PCI Assessments with Attestations of Compliance

Security Awareness Training

CASE STUDY: Asset Management and PCI Compliance

A Service Provider handling customer cardholder data (CHD) engaged with Online to address multiple significant technical, procedural, and time-based requirements.

To address these problems, Online's Service Management team performed a comprehensive evaluation of the network and application environment that included both on-prem and cloud based systems, utilizing the BMC Discovery platform coupled with expert analysis from our team of consultants.

Online was pleased to be able to help the Client obtain an Attestation of Compliance, avoiding fines and potentially costly contractual issues with their customers. The Client has improved their security and compliance posture and is well positioned to leverage this work to create a sustainable and optimized program in the future.

Read this story
REPORT: Payment Security Insights – Online Contributes to Verizon’s Payment Security Report

Online proudly contributed to Verizon Business’s 2024 Payment Security Report, offering expert analysis and anonymized Report on Compliance data.

This comprehensive report highlights global trends and benchmarks in payment data security. Discover how this report provides invaluable insights to strengthen your payment security programs.

Keep Reading
BLOG: PCI 4.0 Requirements Are Here – Are You Ready?

Online’s Dan Lapierre, a seasoned QSA, dives into the upcoming changes to PCI DSS requirements taking effect on April 1, 2025.

From stronger password rules to advanced phishing defenses and tamper-detection mechanisms, 52 controls will soon be mandatory. Learn how these updates will impact your security framework, why compliance is critical, and steps your organization can take to stay ahead.

Don’t wait—get insights to ensure a seamless transition to PCI 4.0 compliance.

Keep Reading
Expand Your Security Processes Past Compliance

Our Risk, Security and Privacy (RSP) team is committed to delivering RIGHT-SIZED SECURITY and helping our clients create and manage cost-efficient and risk-effective information security programs that are aligned with their unique needs and risk appetite.

Show me more

CONNECT WITH OUR TEAM

ADAM GAYDOSH

Director

PCI Services, Risk, Security and Privacy

let's talk
Adam Gaydosh

STEVE LEVINSON

Vice President

Risk, Security and Privacy

let's talk