Canada · PCI DSS v4.0.1 · PCI 3DS
PCI DSS assessments in Canada, by an independent QSA.
Cianaa is a PCI Qualified Security Assessor company listed for the Canada region. We assess payment service providers, fintechs, financial institutions and merchants in Canada against PCI DSS v4.0.1 and the PCI 3DS Core Security Standard, and issue the Report on Compliance and Attestation of Compliance your acquirer and the card brands ask for.
Why our assessment carries weight
Licensed for Canada, working across time zones
What stands behind a Cianaa assessment in Canada.
Verify any QSA company, including us, on the PCI SSC register before you engage them.
On the PCI SSC register since 2014
Cianaa has been a PCI Qualified Security Assessor company for more than a decade, assessing some of the largest payment environments in Australia and New Zealand. Our Canada listing means our Report on Compliance and Attestation of Compliance are valid for entities in Canada, and our Asia Pacific and Europe listings let one assessor cover a group across all three.
Verify us on the PCI SSC register →Overview
PCI DSS in Canada’s payments market
Any organisation that stores, processes or transmits payment card data, or can affect the security of that data, must comply with the Payment Card Industry Data Security Standard (PCI DSS). The card brands and your acquiring bank decide how you validate: Level 1 merchants and service providers need an annual assessment by a QSA, resulting in a Report on Compliance.
In Canada that includes payment service providers supervised by the Bank of Canada under the Retail Payment Activities Act, payment processors and gateways, fintechs and card issuers, financial institutions, and e-commerce, travel and retail merchants with high card volumes.
Many of these organisations already answer to other frameworks, such as the Bank of Canada’s operational risk requirements for payment service providers or OSFI’s Guideline B-13 for federally regulated financial institutions. PCI DSS does not replace them, and a PCI DSS assessment is not a regulatory review. But many of the controls overlap, so a well-run assessment produces independent evidence your team can reuse.
The Canadian picture
Where PCI DSS meets Canadian regulation
Canada has added payment-specific oversight in recent years. PCI DSS is not part of it, but a well-run PCI assessment produces a lot of the evidence these frameworks ask for.
Bank of Canada
Retail Payment Activities Act
Registered payment service providers must run an operational risk management and incident response framework, with safeguarding of end-user funds. PCI DSS controls cover much of the technical ground.
OSFI
Guideline B-13
Federally regulated financial institutions follow OSFI’s technology and cyber risk guideline. Card environments assessed under PCI DSS feed directly into that picture.
Card brands and acquirers
Validation requirements
Visa, Mastercard and your acquirer decide whether you need a Report on Compliance or an SAQ, and when it is due. That is the requirement a QSA fulfils.
Privacy
PIPEDA and Quebec Law 25
Cardholder data is personal information under federal and provincial privacy law. Encryption, access and retention controls tested under PCI DSS support those duties.
Cross-border groups
Canada and the US are separate PCI regions
A Canadian entity and a US parent fall in different PCI SSC regions. We assess the Canadian side and say plainly when a US entity needs a USA-listed QSA.
Beyond PCI
PCI 3DS and ISO audits
PCI 3DS assessments by a 3DS QSA, and ISO/IEC 27001 or 42001 audits with certificates issued by independently accredited certification bodies.
What we assess
What we assess in Canada
Services shaped around Canadian payment firms and their regulators.
Report on Compliance for PSPs
For payment service providers, processors and gateways validating as service providers, a full QSA assessment and Attestation of Compliance.
Evidence that serves two purposes
We structure the assessment so the controls and artefacts reviewed can also support your Bank of Canada or OSFI obligations, without turning it into a regulatory review.
Fintech card programmes
Scoping and assessment for fintechs issuing prepaid, debit or credit cards through a sponsor bank or processor.
Penetration and segmentation testing
Requirement 11.4 testing by independent CREST and OSCP certified testers, scheduled to suit Canadian business hours.
PCI 3DS
Assessment of access control server and 3DS server environments by a 3DS QSA.
Canada plus Asia Pacific or Europe
For groups operating in Canada and in our other regions, one assessor, one calendar and shared evidence.
Process
How we run a Canadian assessment from New Zealand
Remote-first, with the time zones planned in rather than worked around.
Scope and region check
We confirm your validation route and which entities are Canadian, so nothing in a separate PCI region slips into scope by mistake.
Pre-assessment
A dry run against the applicable requirements, so gaps surface early.
A shared calendar
Interviews scheduled in the overlap between New Zealand mornings and Canadian afternoons, with evidence exchanged securely in between.
Remote review and on-site week
Remote testing and document review, then a planned on-site week in Canada where your environment or acquirer needs it.
ROC and AOC
Report on Compliance and Attestation of Compliance, issued once every applicable requirement is met.
Reassessment
Annual validation, booked well ahead so travel and time zones never cause a late AOC.
Why Cianaa
Why Canadian firms choose a QSA from New Zealand
Distance is a scheduling question, not a quality one. Here is what you get.
Licensed for Canada
Cianaa is listed for the PCI SSC Canada region, as well as Asia Pacific and Europe. Your ROC and AOC are valid for your Canadian entities.
Time zones planned in
New Zealand mornings overlap Canadian afternoons, which is where live sessions happen. Evidence review runs while you sleep, so fieldwork moves quickly.
Payments is our core
PCI DSS and PCI 3DS have been our specialism since 2014, not a sideline to a broader audit practice.
PhD-led and published
Our founder holds a PhD in cybersecurity and our team has ten DOI registered research papers you can read before engaging us.
Independent testers
Penetration testing is performed by independent CREST and OSCP certified testers, separate from the assessor.
Straight about the US
If part of your group sits in the US, we tell you at the start that it needs a USA-listed QSA, rather than finding out at report time.
Free resources
Check where you stand first
Free tools and guidance written by our QSAs. No sign-up needed.
PCI DSS SAQ Selector
Find the right Self-Assessment Questionnaire in about a minute.
Open the tool →What a QSA assessment looks like
The ROC and AOC timeline, from kick-off to sign-off.
Read the walkthrough →PCI DSS in the cloud
Shared responsibility between you and your cloud providers under PCI DSS.
Read the article →Customised versus defined approach
When the customised approach makes sense, and what assessors need to see.
Read the article →PCI pre-audit maturity self-check
See where you stand before the assessment starts.
Start the self-check →Ten DOI registered papers
Our published research on security, privacy and AI governance.
Browse the research →Complimentary · no obligation
Scope your PCI DSS assessment in Canada
A 30 minute call, scheduled in your afternoon, to confirm your validation route, which entities are in scope and a realistic timeline including any on-site week.
Book a scoping call- Your validation routeReport on Compliance or SAQ, confirmed against your level.
- Your scopeWhich systems, people and third parties are in scope.
- A realistic timelineFrom kick-off to Attestation of Compliance.
- Where you can reuse evidenceWhere existing Bank of Canada, OSFI or ISO evidence carries across.
An independent QSA for your Canadian operations
Talk to a QSA about scoping your Canadian PCI DSS assessment.
FAQ
Frequently asked questions
Can Cianaa perform PCI DSS assessments in Canada?
Yes. Cianaa is a PCI Qualified Security Assessor company listed for the PCI SSC Canada region. Our listing is on the PCI SSC register.
We are registered under the Retail Payment Activities Act. Where does PCI DSS fit?
The RPAA, supervised by the Bank of Canada, requires an operational risk and incident response framework. It does not require PCI DSS, but if you handle card data the card brands and your acquirer do. The two overlap heavily, so a PCI DSS assessment produces evidence you can reuse for RPAA purposes.
Does OSFI require PCI DSS?
No. OSFI’s Guideline B-13 sets technology and cyber risk expectations for federally regulated financial institutions. PCI DSS is separate, but card environments assessed under it support your B-13 evidence.
Our parent company is in the United States. Can you assess us?
We can assess your Canadian entity. The United States is a separate PCI SSC region that Cianaa is not listed for, so a US entity needs a QSA listed for the USA. We will tell you at the scoping stage exactly where that line falls.
How does working from New Zealand affect the schedule?
Live interviews happen in the overlap between New Zealand mornings and Canadian afternoons, and evidence review continues overnight your time. On-site work is planned as a single visit where your environment or acquirer requires it.
Do we need a Report on Compliance or an SAQ?
Your acquirer and the card brands decide, based on your transaction volume and whether you are a merchant or a service provider. Our SAQ Selector gives a first answer and we confirm it on the scoping call.
Who performs the penetration testing?
Independent CREST and OSCP certified testers, separate from the QSA, as PCI DSS v4.0.1 Requirement 11.4 expects.
Do you assess PCI 3DS in Canada?
Yes. Our 3DS QSA assesses access control server and 3DS server environments against the PCI 3DS Core Security Standard.
