How well is payment security actually embedded in your business?
Passing an assessment tells you a control existed on the day someone looked. Maturity tells you whether it will still be running in eight months, whether you would notice if it stopped, and whether the evidence exists without a scramble. PCI DSS v4.0.1 leans hard in this direction, so the gap between compliant and mature is now where most of the real risk sits. Rate twenty-four practices across eight domains and take your profile away as a report.
Rate what is true today, not what is intended
For each practice, choose the level that honestly describes how it works now. Most organisations that pass assessments sit somewhere around level 2 or 3. That is not a failure, it is the normal starting point, and knowing it is what lets you plan rather than react.
Rate the practices above to build your maturity profile
Your profile updates as you go. Everything stays in your browser until you choose to download it.
Download your results
Take away a dated report with your overall level, your score in each domain, and the practices holding you back. Useful for a board paper, a budget case, or a conversation with your acquirer.
We send the report to your company email so we know it reached a real inbox. To do that we store the ratings you selected, your email and your organisation name. Free webmail addresses are not accepted. We do not sell your details, and the newsletter tick box above is entirely separate from getting the report. See our privacy policy.
Talk through your profile with a QSA
Thirty minutes with a practising Qualified Security Assessor on what it would take to move your weakest domain up one level, and whether that is the right place to spend the effort.
About this assessment. The five capability levels follow the ordinary process-maturity convention used across management system practice, applied here to the operational disciplines that PCI DSS v4.0.1 expects to run continuously. The practices assessed are Cianaa’s own formulation. This is not a PCI Security Standards Council product, the Council does not define or endorse a PCI DSS maturity model, and no text from Council documents is reproduced here.
A maturity level is not a compliance status and carries no standing with your acquirer or any payment brand. Only a completed assessment against PCI DSS by an appropriate party can establish compliance.
Cianaa Technologies is an independent certification and assessment body headquartered in Auckland. We have been a PCI Qualified Security Assessor on the PCI Security Standards Council register since 2014 and are a PCI 3DS Assessor.
