The fee you did not notice
Many merchants pay a monthly PCI non-compliance fee on their processing statement right now, for skipping a questionnaire nobody explained. That money stops when validation is done right.
PCI DSS 4.0 readiness
Most small businesses overpay for PCI or quietly pay non-compliance fees every month. We map your card-data flows, shrink your scope, pick the right self-assessment questionnaire, and close the real gaps.
Scope, timing, and fees are documented before work begins.
Many merchants pay a monthly PCI non-compliance fee on their processing statement right now, for skipping a questionnaire nobody explained. That money stops when validation is done right.
Your processor's compliance portal nags you with a questionnaire in audit language. Answer it wrong and you have attested falsely; ignore it and you pay fees and carry breach liability.
PCI's size depends on how card data flows through your business. Hosted payment pages and modern terminals can cut the requirements dramatically; most merchants never learn this.
Best fit: any business taking card payments, especially practices and firms whose processor is charging non-compliance fees or whose questionnaire has never been answered accurately.
Not the right fit: Level 1 merchants (over six million transactions a year) needing a QSA-led report on compliance; we refer those to a Qualified Security Assessor firm and can coordinate the engagement.
PCI DSS is the card brands' security standard, enforced through your payment processor. Most small and midsize merchants validate through a Self-Assessment Questionnaire (SAQ): you attest to the requirements that apply to your setup. Which SAQ applies, and how many requirements it carries, depends entirely on how card data touches your systems.
Two things are commonly misunderstood. First, the merchant signs the attestation, not the consultant; our job is making sure every answer you sign is true. Second, most SAQ types require quarterly external vulnerability scans by a PCI Approved Scanning Vendor (ASV), a specific accredited scan service we set up and read for you.
The craft is scope reduction: moving card data out of your environment with hosted payment pages and point-to-point encrypted terminals, so the standard applying to you shrinks from hundreds of requirements to a short, keepable list.
Every engagement includes
Example scope summary
Illustrative structure only. Your findings, owners, evidence, and priorities are based on your environment.
See what your scope includesWe learn how cards flow through your business and what your processor is demanding, then fix the price in writing.
Data flows mapped, scope reduced where possible, the right SAQ picked, and the real gaps closed with your IT or MSP.
You sign an accurate SAQ, quarterly ASV scans run on schedule, and the processor portal finally goes green.
How pricing works
Your quote is built from your headcount, your systems, and how far you are from the bar. It is fixed in writing at the free 30-minute call, before any work starts, and it never changes after you approve it.
Separately scoped, always disclosed
ASV scan subscriptions are a third-party service (typically a few hundred dollars a year) billed directly to you; QSA audit fees, new hardware, and remediation labor are separate line items when they apply. Nothing external hides inside our quote.
No one 'certifies' most merchants: you validate through a Self-Assessment Questionnaire that you sign, backed by quarterly ASV scans. We make sure the questionnaire is the right one, the answers are true, and the scans actually run. At Level 1 volumes a QSA firm audits; we refer and coordinate.
An Approved Scanning Vendor is a company accredited by the PCI council to run the quarterly external scans most SAQ types require. It is a subscription service, not a Hardenwell product; we set it up, schedule it, and translate the results into fixes.
The portal is a form, not advice. It will happily let you attest to the wrong SAQ with wrong answers, which is worse than not filing. We make the answers true, shrink what you are attesting to, and stop the non-compliance fees.
Yes. The controls PCI demands (segmentation, MFA, scanning, policies) map onto NIST and CIS, and everything lands in the same evidence index our other services use.
We cover your organization, your deadline, and who is asking for what. You leave knowing the likely scope, the timeline, and your next step, with the price fixed in writing before any work starts.
Prefer phone or email?
(754) 216-9664 info@hardenwell.com
Do not include PHI or sensitive records in booking notes. See our Privacy Policy.