Home » Services & Solutions » Cybersecurity » PCI Data Security Standards
PCI DSS Compliance and QSA Services
Your QSA should make PCI compliance clearer — not harder.
Many organizations come to LBMC after working with another QSA. They aren’t new to PCI DSS. They’re looking for clearer communication, more consistent guidance, and an assessment process that works with their business rather than creating unnecessary surprises.
LBMC provides PCI DSS assessments, readiness support, security testing, and ongoing guidance for merchants and service providers. Our team works to understand your environment early, clarify expectations, and surface issues while there is still time to address them.
Considering a Change in QSA Firms?
If your current QSA relationship isn’t meeting your needs, changing firms doesn’t have to disrupt your PCI compliance program. Talk with our team about your current environment, assessment timeline, and what a transition to LBMC would involve.
Why Organizations Consider Changing QSA Firms
A QSA relationship should provide consistency and clarity throughout the assessment — not introduce uncertainty as deadlines approach.
Lack of Responsiveness
Important questions remain unanswered until fieldwork or reporting deadlines are approaching.
Inconsistent Guidance
Interpretations change depending on the assessor assigned or from one assessment year to the next.
Late Surprises
Scope concerns, evidence gaps, or potential findings are raised too late for your team to respond effectively.
Assessor Turnover
Your team must repeatedly explain its environment, business model, and prior decisions to new assessment personnel.
Need for Greater Technical Depth
Cloud migrations, payment application changes, segmentation, acquisitions, or third-party relationships require assessors who can work effectively with technical teams.
You do not have to wait until the next assessment begins.
A focused transition discussion can help you understand timing, documentation needs, and potential differences before you commit to changing firms.What to Expect When You Move to LBMC
Changing QSA firms doesn’t mean starting over.We begin with the work you’ve already done, review your current environment and assessment history, and establish what needs to happen next.
Understand your current environment
Review your card data flows, systems, applications, vendors, prior assessments, open remediation, and upcoming deadlines.
Confirm scope and segmentation
Validate the cardholder data environment and identify scope or segmentation questions early.
Identify gaps and priorities
Surface evidence gaps, potential findings, remediation needs, and material differences from the prior assessment approach while there is still time to address them.
Coordinate the assessment
Align testing, evidence collection, responsibilities, and timing with potential findings and significant questions raised during the assessment — not saved for the final report.
Complete reporting and plan ahead
Complete applicable reporting and establish a clear path for ongoing PCI support and the next assessment cycle.
CLIENT TESTIMONIAL
“Working with LBMC on our PCI Compliance has helped us deliver a more secure product to our insurance-based customers.”
Senior Manager of Information Security Audit for a leading software company
PCI Assessment, Readiness, Testing and Advisory Services
LBMC provides PCI services for organizations preparing for an assessment, completing formal PCI DSS validation, or managing compliance throughout the year. We tailor the work to your payment environment, scope, and specific PCI requirements.

PCI DSS Assessment and Report on Compliance (ROC)
LBMC QSAs guide your organization through the assessment process, from confirming scope and reviewing evidence through interviews, testing coordination, reporting, and completion of the Report on Compliance.
PCI Readiness and Gap Assessment
Identify potential compliance gaps before your formal assessment begins. We review your PCI scope, controls, policies, evidence, and applicable testing results, then provide prioritized recommendations to help your team address issues before assessment.
PCI Scope and Segmentation Review
Confirm what is — and isn’t — within your PCI environment. We review card-data flows, connected systems, applications, cloud environments, third parties, people and processes, and segmentation controls to help validate the boundaries of your cardholder data environment.
Facilitated SAQ Support
For organizations eligible to complete a Self-Assessment Questionnaire (SAQ), LBMC can help validate scope, review documentation and evidence, clarify applicable requirements, and support accurate completion of the appropriate SAQ.
Virtual QSA Advisory
Get ongoing access to PCI expertise as your environment changes. LBMC QSAs can advise on new payment channels, architecture and cloud changes, acquisitions, third-party service providers, targeted risk analyses, customized approaches, and other changes that may affect PCI compliance.
PCI Security Testing and ASV Scanning
Coordinate PCI-related security testing alongside your broader compliance efforts. LBMC supports ASV scanning, penetration testing, segmentation testing, vulnerability assessment, and remediation validation to help your team address applicable testing requirements.
Not Sure Which PCI Service You Need?
Talk with our team about your PCI requirements and where you are in the process. We’ll help you figure out the right next step.
Experience with Complex Payment Environments
LBMC works with organizations whose PCI responsibilities extend across complex technology, payment channels, business structures, and compliance requirements.
SaaS and Payment Technology Providers
Multi-tenant platforms, cloud environments, integrated payment functionality, customer compliance requests and service-provider reporting obligations.
Insurance and InsurTech
Payment acceptance across policyholder, agent, call-center, online, and third-party channels.
Healthcare Technology
Payment-card requirements managed alongside healthcare security, privacy, HITRUST and customer assurance obligations.
Multi-Entity and Distributed Organizations
Coordination across business units, brands, locations, payment channels and separate cardholder data environments.

More Than $175,000 in Annual PCI Assessment Savings
$175K+
A healthcare technology organization engaged LBMC to reduce audit fatigue and overlapping assessment costs across multiple business units and compliance programs.
LBMC aligned assessment schedules, coordinated testing across PCI environments, consolidated cardholder data where appropriate and simplified PCI scope. The changes produced more than $175,000 in annual PCI assessment savings as part of more than $550,000 in total cybersecurity assessment savings.
Direct Access to PCI Leadership
Shareholder, Cybersecurity and PCI Compliance Practice Leader
Stewart leads LBMC’s PCI Compliance practice and has 20 years of experience in IT security and compliance. His background includes PCI DSS assessment, penetration testing, enterprise security leadership and experience within a Fortune 100 healthcare organization.
He focuses on helping organizations balance defensible compliance decisions with technical risk, growth and operational realities.
PCI Scope Explained: What’s In Scope, What’s Out, and Why
PCI scope decisions drive cost, effort, and outcomes. In this on-demand session, we break down what’s truly in scope, what’s not, and how to right-size your PCI approach, so you avoid wasted time and reduce gaps that lead to findings.
Cybersecurity Sense Podcast: PCI Pen Testing
In this episode Bill Dean and Stewart Fey discuss penetration testing for PCI compliance. Learn about the differences between penetration testing and vulnerability assessments, and what is needed to meet requirements for PCI compliance.
Ready to simplify PCI compliance?
If you’re preparing for an assessment, questioning scope, or working through remediation, our team can help you clarify next steps and reduce rework.
PCI DSS and QSA Transition FAQs
Why should an organization consider changing QSA firms?
Organizations often evaluate alternatives because of poor responsiveness, repeated assessor turnover, inconsistent interpretations, late findings, or a need for stronger technical expertise.
A leadership change, acquisition, cloud migration, new payment channel, or major scope change can also be an appropriate time to obtain a fresh independent perspective.
How difficult is it to change QSA firms?
A QSA transition is manageable when it begins early and the new assessor has access to relevant prior documentation.
Useful transition materials include the previous ROC or SAQ, AOC, scope documentation, network and data-flow diagrams, responsibility matrices, testing reports, evidence repositories and open remediation items.
For additional guidance on evaluating an existing PCI program, read How to Take Over a PCI Compliance Program.
Will LBMC accept decisions made by our previous QSA?
LBMC will review prior conclusions and supporting evidence, but it must perform an independent assessment.
When LBMC reaches a materially different conclusion about scope, requirement applicability or control effectiveness, we explain the rationale and raise the issue as early as possible.
Do we need a ROC or an SAQ?
The appropriate validation method depends on factors including entity type, transaction volume, eligibility criteria and requirements imposed by payment brands, acquirers, customers or other requesting organizations.
LBMC can help evaluate the likely validation path, but the requesting organization or compliance authority has final responsibility for determining required reporting.
How is PCI scope determined?
PCI scope includes people, processes and technologies that store, process or transmit account data, as well as systems that could affect the security of the cardholder data environment.
Scoping normally requires analysis of payment flows, connected systems, segmentation, identity and security services, cloud environments, applications and third-party relationships.
Learn more about how network diagrams support PCI DSS scoping and compliance.
Can LBMC help reduce PCI scope?
Yes, when the technology and operating model support it.
Potential strategies may include payment outsourcing, tokenization, validated segmentation, architecture changes and removal of unnecessary data storage. Scope reduction must be supported by the actual design and operation of the environment—not only by documentation.
What security testing is required for PCI DSS?
Testing depends on the environment and applicable requirements. It may include external ASV scans, internal vulnerability scans, penetration testing, segmentation testing, wireless testing and application-security testing.
PCI DSS Requirement 11.3.2 requires applicable external vulnerability scans to be performed by an Approved Scanning Vendor at least once every three months, with rescans as needed to achieve a passing result.
Can LBMC coordinate PCI with SOC 2, HITRUST, or other compliance initiatives?
Yes. Where testing objectives and evidence overlap, LBMC can help coordinate PCI with SOC audits, HITRUST assessments, and other applicable compliance initiatives.
Organizations may also be managing NIST cybersecurity requirements or CMMC compliance alongside their PCI program.
Each framework retains its own scope, criteria, and reporting requirements, so coordination can reduce duplicate effort but does not make one assessment a substitute for another.
What is PCI DSS and who needs to comply?
PCI DSS is a set of security requirements designed to protect payment account data. It applies to organizations that store, process, or transmit cardholder data, as well as organizations that can affect the security of the cardholder data environment.
Learn more about PCI DSS requirements and compliance.
How do organizations maintain PCI DSS compliance between assessments?
PCI compliance requires ongoing attention throughout the year, not just preparation for an annual assessment. Recurring activities, changes to the payment environment, new third parties, remediation efforts, and required testing can all affect continued compliance.
Review the recurring and periodic tasks required for PCI DSS compliance.
What are common PCI compliance mistakes?
Scoping errors, incomplete documentation, missed recurring activities, changes to the payment environment, and unresolved findings can all create problems during an assessment. Identifying these issues earlier gives your team more time to address them.
Review common PCI compliance mistakes and how to avoid them.
Is PCI DSS compliance required by law?
PCI DSS is an industry security standard rather than a law itself. Compliance obligations generally arise through payment-card industry requirements and contractual relationships, although separate laws and regulations may also apply to an organization’s handling of payment or personal data.
Learn more about common myths about PCI DSS compliance and enforcement.
Ready for a Different QSA Experience?
Replacing an incumbent QSA, preparing for formal validation, or making significant changes to your payment environment? Start with a direct discussion about your scope, deadlines, and what is not working today.

