Canada · PCI DSS v4.0.1 · PCI 3DS

PCI DSS assessments in Canada, by an independent QSA.

Cianaa is a PCI Qualified Security Assessor company listed for the Canada region. We assess payment service providers, fintechs, financial institutions and merchants in Canada against PCI DSS v4.0.1 and the PCI 3DS Core Security Standard, and issue the Report on Compliance and Attestation of Compliance your acquirer and the card brands ask for.

Report on ComplianceAttestation of ComplianceRemote and on-siteCanada licence

Why our assessment carries weight

Licensed for Canada, working across time zones

What stands behind a Cianaa assessment in Canada.

A PCI Qualified Security Assessor company on the PCI Security Standards Council register since 2014
Listed for the PCI SSC Canada, Asia Pacific and Europe regions
3DS QSA qualified, for PCI 3DS Core Security Standard assessments
Penetration testing by independent CREST and OSCP certified testers
Founded by Dr Rizwan Ahmad, PhD, a practising QSA and MSECB Auditor of the Year 2024 for Asia Pacific

Verify any QSA company, including us, on the PCI SSC register before you engage them.

QSASince 2014

On the PCI SSC register since 2014

Cianaa has been a PCI Qualified Security Assessor company for more than a decade, assessing some of the largest payment environments in Australia and New Zealand. Our Canada listing means our Report on Compliance and Attestation of Compliance are valid for entities in Canada, and our Asia Pacific and Europe listings let one assessor cover a group across all three.

Verify us on the PCI SSC register →
Trusted by payments and security teams across Australia and New Zealand
Spark Datacom Vodafone Humm Group CCL Fidelity Illion Plan B Xplore

Overview

PCI DSS in Canada’s payments market

Any organisation that stores, processes or transmits payment card data, or can affect the security of that data, must comply with the Payment Card Industry Data Security Standard (PCI DSS). The card brands and your acquiring bank decide how you validate: Level 1 merchants and service providers need an annual assessment by a QSA, resulting in a Report on Compliance.

In Canada that includes payment service providers supervised by the Bank of Canada under the Retail Payment Activities Act, payment processors and gateways, fintechs and card issuers, financial institutions, and e-commerce, travel and retail merchants with high card volumes.

Many of these organisations already answer to other frameworks, such as the Bank of Canada’s operational risk requirements for payment service providers or OSFI’s Guideline B-13 for federally regulated financial institutions. PCI DSS does not replace them, and a PCI DSS assessment is not a regulatory review. But many of the controls overlap, so a well-run assessment produces independent evidence your team can reuse.

The Canadian picture

Where PCI DSS meets Canadian regulation

Canada has added payment-specific oversight in recent years. PCI DSS is not part of it, but a well-run PCI assessment produces a lot of the evidence these frameworks ask for.

Bank of Canada

Retail Payment Activities Act

Registered payment service providers must run an operational risk management and incident response framework, with safeguarding of end-user funds. PCI DSS controls cover much of the technical ground.

OSFI

Guideline B-13

Federally regulated financial institutions follow OSFI’s technology and cyber risk guideline. Card environments assessed under PCI DSS feed directly into that picture.

Card brands and acquirers

Validation requirements

Visa, Mastercard and your acquirer decide whether you need a Report on Compliance or an SAQ, and when it is due. That is the requirement a QSA fulfils.

Privacy

PIPEDA and Quebec Law 25

Cardholder data is personal information under federal and provincial privacy law. Encryption, access and retention controls tested under PCI DSS support those duties.

Cross-border groups

Canada and the US are separate PCI regions

A Canadian entity and a US parent fall in different PCI SSC regions. We assess the Canadian side and say plainly when a US entity needs a USA-listed QSA.

Beyond PCI

PCI 3DS and ISO audits

PCI 3DS assessments by a 3DS QSA, and ISO/IEC 27001 or 42001 audits with certificates issued by independently accredited certification bodies.

What we assess

What we assess in Canada

Services shaped around Canadian payment firms and their regulators.

Report on Compliance for PSPs

For payment service providers, processors and gateways validating as service providers, a full QSA assessment and Attestation of Compliance.

Evidence that serves two purposes

We structure the assessment so the controls and artefacts reviewed can also support your Bank of Canada or OSFI obligations, without turning it into a regulatory review.

Fintech card programmes

Scoping and assessment for fintechs issuing prepaid, debit or credit cards through a sponsor bank or processor.

Penetration and segmentation testing

Requirement 11.4 testing by independent CREST and OSCP certified testers, scheduled to suit Canadian business hours.

PCI 3DS

Assessment of access control server and 3DS server environments by a 3DS QSA.

Canada plus Asia Pacific or Europe

For groups operating in Canada and in our other regions, one assessor, one calendar and shared evidence.

Process

How we run a Canadian assessment from New Zealand

Remote-first, with the time zones planned in rather than worked around.

1
First call

Scope and region check

We confirm your validation route and which entities are Canadian, so nothing in a separate PCI region slips into scope by mistake.

2
Optional

Pre-assessment

A dry run against the applicable requirements, so gaps surface early.

3
Planning

A shared calendar

Interviews scheduled in the overlap between New Zealand mornings and Canadian afternoons, with evidence exchanged securely in between.

4
Fieldwork

Remote review and on-site week

Remote testing and document review, then a planned on-site week in Canada where your environment or acquirer needs it.

5
Reporting

ROC and AOC

Report on Compliance and Attestation of Compliance, issued once every applicable requirement is met.

6
Next year

Reassessment

Annual validation, booked well ahead so travel and time zones never cause a late AOC.

Why Cianaa

Why Canadian firms choose a QSA from New Zealand

Distance is a scheduling question, not a quality one. Here is what you get.

Licensed for Canada

Cianaa is listed for the PCI SSC Canada region, as well as Asia Pacific and Europe. Your ROC and AOC are valid for your Canadian entities.

Time zones planned in

New Zealand mornings overlap Canadian afternoons, which is where live sessions happen. Evidence review runs while you sleep, so fieldwork moves quickly.

Payments is our core

PCI DSS and PCI 3DS have been our specialism since 2014, not a sideline to a broader audit practice.

PhD-led and published

Our founder holds a PhD in cybersecurity and our team has ten DOI registered research papers you can read before engaging us.

Independent testers

Penetration testing is performed by independent CREST and OSCP certified testers, separate from the assessor.

Straight about the US

If part of your group sits in the US, we tell you at the start that it needs a USA-listed QSA, rather than finding out at report time.

Free resources

Check where you stand first

Free tools and guidance written by our QSAs. No sign-up needed.

Free tool

PCI DSS SAQ Selector

Find the right Self-Assessment Questionnaire in about a minute.

Open the tool →
Guidance

What a QSA assessment looks like

The ROC and AOC timeline, from kick-off to sign-off.

Read the walkthrough →
Guidance

PCI DSS in the cloud

Shared responsibility between you and your cloud providers under PCI DSS.

Read the article →
Guidance

Customised versus defined approach

When the customised approach makes sense, and what assessors need to see.

Read the article →
Free tool

PCI pre-audit maturity self-check

See where you stand before the assessment starts.

Start the self-check →
Research

Ten DOI registered papers

Our published research on security, privacy and AI governance.

Browse the research →

Complimentary · no obligation

Scope your PCI DSS assessment in Canada

A 30 minute call, scheduled in your afternoon, to confirm your validation route, which entities are in scope and a realistic timeline including any on-site week.

Book a scoping call
30 minutesIn your afternoonNo obligation
  • Your validation routeReport on Compliance or SAQ, confirmed against your level.
  • Your scopeWhich systems, people and third parties are in scope.
  • A realistic timelineFrom kick-off to Attestation of Compliance.
  • Where you can reuse evidenceWhere existing Bank of Canada, OSFI or ISO evidence carries across.

An independent QSA for your Canadian operations

Talk to a QSA about scoping your Canadian PCI DSS assessment.

FAQ

Frequently asked questions

Can Cianaa perform PCI DSS assessments in Canada?

Yes. Cianaa is a PCI Qualified Security Assessor company listed for the PCI SSC Canada region. Our listing is on the PCI SSC register.

We are registered under the Retail Payment Activities Act. Where does PCI DSS fit?

The RPAA, supervised by the Bank of Canada, requires an operational risk and incident response framework. It does not require PCI DSS, but if you handle card data the card brands and your acquirer do. The two overlap heavily, so a PCI DSS assessment produces evidence you can reuse for RPAA purposes.

Does OSFI require PCI DSS?

No. OSFI’s Guideline B-13 sets technology and cyber risk expectations for federally regulated financial institutions. PCI DSS is separate, but card environments assessed under it support your B-13 evidence.

Our parent company is in the United States. Can you assess us?

We can assess your Canadian entity. The United States is a separate PCI SSC region that Cianaa is not listed for, so a US entity needs a QSA listed for the USA. We will tell you at the scoping stage exactly where that line falls.

How does working from New Zealand affect the schedule?

Live interviews happen in the overlap between New Zealand mornings and Canadian afternoons, and evidence review continues overnight your time. On-site work is planned as a single visit where your environment or acquirer requires it.

Do we need a Report on Compliance or an SAQ?

Your acquirer and the card brands decide, based on your transaction volume and whether you are a merchant or a service provider. Our SAQ Selector gives a first answer and we confirm it on the scoping call.

Who performs the penetration testing?

Independent CREST and OSCP certified testers, separate from the QSA, as PCI DSS v4.0.1 Requirement 11.4 expects.

Do you assess PCI 3DS in Canada?

Yes. Our 3DS QSA assesses access control server and 3DS server environments against the PCI 3DS Core Security Standard.