PCI DSS and security assurance for retailers across the UK, Europe, US and APAC.
End-to-end PCI compliance, penetration testing, and store-level security advisory for high-street retailers, e-commerce platforms, and hospitality groups.

Compliance and security challenges for retail.
PCI DSS scope reduction across multi-channel card environments.
E-commerce platform security (PCI DSS Requirement 6.4.3 and 11.6.1).
POS terminal estate management and ASV scanning.
Vendor and integrator risk for outsourced payment flows.
The services we lead with for retail.
Three engagements most often chosen by buyers in this sector. The full catalogue is below.
PCI DSS
QSAC-led SAQ, ROC, gap analysis, remediation advisory and ongoing PCI compliance support.
ASV Scanning
PCI-approved external vulnerability scanning with validation, reporting and remediation support.
Penetration Testing
Manual testing across infrastructure, web apps, APIs, cloud, mobile and red-team scenarios.
- PCI DSS 4.0.1
- UK GDPR
Full service catalogue
The complete set of compliance and security services we deliver.
PCI DSS
QSAC-led SAQ, ROC, gap analysis, remediation advisory and ongoing PCI compliance support.
Penetration Testing
Manual testing across infrastructure, web apps, APIs, cloud, mobile and red-team scenarios.
ISO 27001
ISMS implementation, internal audits, readiness reviews and certification support.
SOC 2
SOC 2 Type 2 readiness and attestation support, with an AICPA-licensed CPA partner.
SOC as a Service
24/7 monitoring, threat detection, and incident triage by UK analysts.
ASV Scanning
PCI-approved external vulnerability scanning with validation, reporting and remediation support.
vCISO
Fractional CISO leadership for security strategy, governance, board reporting and risk reduction.
Data Privacy / GDPR
Privacy assessments, DPIAs, accountability support and ongoing data protection programme guidance.
SWIFT CSP
SWIFT Customer Security Programme attestation support for financial institutions.
Frequently asked questions — Retail
Ready to scope a retail engagement?
Speak directly with a senior practitioner. We'll confirm scope, evidence requirements, timelines and fixed-fee options before work begins.