🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
PCI DSSCR-PCI-01

PCI DSS Self-Assessment Support

PCI DSS v4.0 SAQ completion: determine correct type, walk through all requirements, document controls, produce submission-ready SAQ. €319.

PCI DSS Self-Assessment Support by Optimum Web is a fixed-price compliance service covering PCI DSS v4.0 — Self-Assessment Questionnaire support. It costs €319 with 5–7 business days delivery by senior security engineers. Completed PCI DSS SAQ (correct type for your business). 14-day warranty included.

€319
Fixed price, VAT excluded
5–7 business daysSenior only
Completed PCI DSS SAQ (correct type for your business)
Gap analysis: requirements not yet met with remediation plan
Compensating controls documentation where applicable
Attestation of Compliance (AOC) preparation
🛡️
14-Day Warranty
If the delivered pack does not match your ISMS scope and Statement of Applicability, we rework it at no cost, or refund in full within 14 days of delivery.

Secured by PayPal · 256-bit SSL encryption

or order without payment
+373 22 843569
PayPal · SSL
👨‍💻 Senior only
14-day warranty
🆔 CR-PCI-01

This Service Covers

PCI DSSSAQ A/A-EP/D — Self-Assessment Questionnaire

What You Get

Guided completion of PCI DSS v4.0 Self-Assessment Questionnaire (SAQ). We determine your correct SAQ type (A, A-EP, B, C, D), walk through each requirement, help document your controls and compensating controls, identify gaps requiring remediation, and produce a completed SAQ ready for submission to your acquiring bank. Includes gap analysis with remediation guidance for any requirements not yet met.

Optimum Web provides audit preparation, documentation and technical verification. We are not a certification body, we do not employ auditors, and we do not perform internal or certification audits. The Clause 9.2 internal audit is conducted by a person independent of the area audited within your organisation, or by an auditor you appoint; the certification audit is conducted by an accredited certification body. Our role is to make sure you are ready for both.

Who Needs This

  • E-commerce businesses accepting card payments needing PCI compliance
  • Companies whose acquiring bank or payment processor requested PCI SAQ
  • Businesses confused about which SAQ type applies to their payment setup
  • Organizations that failed a previous PCI assessment and need remediation

How It Works

  1. 1
    SAQ Type

    Determine correct SAQ type based on your payment acceptance methods

  2. 2
    Walkthrough

    Go through each requirement: document existing controls, identify gaps

  3. 3
    Remediation

    Provide guidance for any gaps; implement quick fixes where possible

  4. 4
    Submission

    Produce completed SAQ + AOC ready for acquirer submission

NEXT STEP

Ready to Implement the Findings?

After the assessment, our fixed-price implementation services cover every gap — from GDPR backup (€449) to incident response (€359). No surprises.

Browse Fix Services

Ready to Start?

€319 · 5–7 business days · 14-day warranty

Secured by PayPal · 256-bit SSL encryption

or order without payment

Ready to implement? Browse individual fix services

Learn more

Frequently Asked Questions

Which PCI DSS SAQ type do I need?+
SAQ A: fully outsourced payment (Stripe Checkout, PayPal hosted). SAQ A-EP: website redirects but partially touches card data. SAQ D: full card data handling. We determine the correct type based on your payment flow.
Is PCI DSS mandatory for all businesses?+
If you accept, process, store, or transmit credit card data — yes. Even if you use Stripe or PayPal, you need at minimum SAQ A. Your acquiring bank/payment processor enforces compliance.
What changed in PCI DSS v4.0?+
Major changes: custom approach option (prove security intent without specific controls), expanded MFA requirements, authentication enhancements, and new e-commerce/anti-phishing requirements. New requirements phase in by March 2025.
What if we don't pass the self-assessment?+
Common — most companies have gaps on first assessment. We identify gaps, provide remediation guidance, and help implement fixes. Once remediated, we re-complete the SAQ.
Do I also need quarterly vulnerability scans?+
SAQ types A-EP and D require quarterly ASV (Approved Scanning Vendor) scans. SAQ A does not. See CR-NIS2-08 for vulnerability management program setup.

Service page last reviewed 11 August 2026 by the Optimum Web compliance team.

Secured by PayPal · 256-bit SSL encryption

or order without payment