Europe · UK · PCI DSS v4.0.1 · PCI 3DS
PCI DSS assessments across Europe and the UK, by an independent QSA.
Cianaa is a PCI Qualified Security Assessor company and 3DS QSA listed for the PCI SSC Europe region, which includes the United Kingdom. We have worked with organisations in the UK, Ireland, the Netherlands and Germany, and we assess payment institutions, e-money firms, processors, fintechs and merchants across Europe.
Why our assessment carries weight
One assessor for Europe and beyond
What stands behind a Cianaa assessment in Europe.
Verify any QSA company, including us, on the PCI SSC register before you engage them.
Listed for Europe on the PCI SSC register
Cianaa has been a PCI Qualified Security Assessor company since 2014. Our Europe listing makes our Report on Compliance and Attestation of Compliance valid for entities across Europe and the UK, and because we are also listed for Asia Pacific and Canada, a group operating in several of those regions can work with one assessor.
Verify us on the PCI SSC register →Overview
PCI DSS in a regulated European payments market
European payment firms work under more overlapping regulation than almost anywhere else. PCI DSS is still set by the card industry, required by the card brands and your acquirer for anyone who stores, processes or transmits card data. Level 1 merchants and service providers validate each year with a QSA’s Report on Compliance.
Alongside it sit EU and national rules: the Digital Operational Resilience Act (DORA) for financial entities, strong customer authentication under PSD2, GDPR, and NIS2 for digital infrastructure. In the UK, the FCA’s operational resilience rules and UK GDPR play the same role.
None of these frameworks require PCI DSS, and a PCI assessment is not a regulatory review. But the technical controls overlap heavily, so an assessment planned with those frameworks in mind gives your compliance team evidence it can use more than once.
The European picture
How PCI DSS fits European regulation
Where the card industry’s standard meets the rules your regulators set.
EU financial entities
DORA
Since January 2025, DORA sets requirements for ICT risk management, incident reporting, resilience testing and third-party risk. Many of the controls a QSA tests under PCI DSS map directly onto it.
Payments
PSD2 strong customer authentication
For card payments online, 3-D Secure is the main way issuers and merchants meet SCA. The security of the 3DS systems themselves is what a PCI 3DS assessment covers.
Privacy
GDPR and UK GDPR
Card data is personal data. Encryption, minimisation, retention and access controls tested under PCI DSS support your data protection duties in the EU and UK.
Digital infrastructure
NIS2
The NIS2 Directive, implemented through national laws, raises cyber security obligations for many providers in and around payments.
United Kingdom
FCA operational resilience
UK firms must identify important business services and stay within impact tolerances. Card payment services are often among them, and PCI evidence helps show they are protected.
Beyond PCI
ISO/IEC 27001 and 42001
Where a certificate is needed, our auditors conduct the audit and an independently accredited certification body issues the certificate.
What we assess
Where we work in Europe
Four markets we already know, and the rest of the Europe region under the same listing.
United Kingdom
Payment and e-money institutions, acquirers and merchants under FCA supervision. Covered by our Europe listing, as the UK sits within the PCI SSC Europe region.
Ireland
Dublin is home to the EU headquarters of many payment and e-money firms, supervised by the Central Bank of Ireland and within DORA scope.
The Netherlands
A major European payments hub, with payment institutions and processors supervised by De Nederlandsche Bank.
Germany
Payment institutions, card issuers and merchants supervised by BaFin, where DORA now sets the ICT risk framework for financial entities.
PCI 3DS across Europe
SCA makes 3-D Secure central to European card payments. Our 3DS QSA assesses access control server and 3DS server environments across the region.
Europe plus Asia Pacific or Canada
For European groups with entities in Asia Pacific or Canada, and for Asia Pacific groups expanding into Europe, one assessor across all three regions.
Process
How a European assessment runs
Remote-first, with European mornings and New Zealand evenings as the working overlap.
Entities and validation route
We confirm which entities are in scope, which countries they sit in, and whether each needs a Report on Compliance or an SAQ.
Regulatory overlap
We note where the controls under test also matter for DORA, FCA resilience or GDPR, so your team can reuse the evidence.
Pre-assessment
A dry run against the applicable requirements before fieldwork begins.
Remote review and site visit
Live sessions in your morning, evidence reviewed overnight, and a planned visit to your site where the environment or acquirer requires one.
ROC and AOC
Report on Compliance and Attestation of Compliance, issued once every applicable requirement is met.
Reassessment
Annual validation, planned early so travel and time zones never delay the attestation.
Why Cianaa
Why European firms work with Cianaa
A specialist QSA that can follow your group beyond Europe.
Three regions, one assessor
Listed for Europe, Asia Pacific and Canada. Few assessors your size can cover a group across all three.
3DS specialists
With SCA driving 3-D Secure across Europe, having a 3DS QSA and a PCI DSS QSA in the same team simplifies both assessments.
A working overlap
New Zealand evenings overlap European mornings. Live sessions happen then, and evidence review continues while you are offline.
PhD-led and published
Our founder holds a PhD in cybersecurity, and our team has ten DOI registered research papers you can read before engaging us.
Independent testers
Penetration testing is performed by independent CREST and OSCP certified testers, separate from the assessor.
Experience in four markets
We have worked with organisations in the UK, Ireland, the Netherlands and Germany, and plan site visits wherever they are needed.
Free resources
Check where you stand first
Free tools and guidance written by our QSAs. No sign-up needed.
PCI DSS SAQ Selector
Find the right Self-Assessment Questionnaire in about a minute.
Open the tool →PCI 3DS assessments
How we assess 3DS environments against the PCI 3DS Core Security Standard.
Read more →SAQ A, iframes and redirects
What PCI SSC FAQ 1604 means for e-commerce payment pages and ASV scans.
Read the article →Vulnerability scan or penetration test?
The difference, and what PCI DSS actually requires of each.
Read the article →One audit trail, three frameworks
Integrating PCI DSS, ISO/IEC 27001 and SOC 2 evidence.
Read the article →Ten DOI registered papers
Our published research on security, privacy and AI governance.
Browse the research →Complimentary · no obligation
Scope your PCI DSS assessment in Europe
A 30 minute call, in your morning, to confirm your entities, validation route and a realistic timeline, including any site visit.
Book a scoping call- Your entitiesWhich countries and legal entities are in scope.
- Your validation routeReport on Compliance or SAQ for each one.
- A realistic timelineIncluding travel and the time zone overlap.
- Where evidence overlapsWhere PCI evidence also serves DORA, FCA or GDPR work.
An independent QSA for your European operations
Talk to a QSA about your PCI DSS or PCI 3DS assessment in Europe or the UK.
FAQ
Frequently asked questions
Can Cianaa perform PCI DSS assessments in Europe and the UK?
Yes. Cianaa is a PCI Qualified Security Assessor company listed for the PCI SSC Europe region, which includes the United Kingdom. Our listing is on the PCI SSC register.
Does DORA require PCI DSS?
No. DORA is EU law on digital operational resilience for financial entities; PCI DSS is the card industry’s standard, required by the card brands and acquirers. They overlap in ICT risk management, access control, logging, vulnerability management and third-party oversight, so evidence from one supports the other.
Is PCI penetration testing the same as DORA threat-led penetration testing?
No. Requirement 11.4 of PCI DSS calls for internal, external and segmentation testing of your card environment. DORA’s threat-led penetration testing is a separate, intelligence-led exercise required of certain significant financial entities. One does not replace the other.
How does PSD2 strong customer authentication relate to PCI 3DS?
SCA is a regulatory requirement on how customers are authenticated; 3-D Secure is the main way card payments meet it online. PCI 3DS is the security standard for the systems that run 3-D Secure, such as access control servers and 3DS servers, and is assessed by a 3DS QSA.
Does the UK still fall under the PCI SSC Europe region?
Yes. The PCI SSC Europe region includes the United Kingdom, so our listing covers UK entities as well as those in the EU.
We have entities in Europe and in Asia Pacific or Canada. Can you assess all of them?
Yes. We are listed for Europe, Asia Pacific and Canada, so all of those entities can share one assessor and one calendar. Entities in the United States, the Middle East or Africa fall in regions we are not listed for.
How do you handle the time difference?
New Zealand evenings overlap European mornings, which is when we hold interviews and live walkthroughs. Evidence review continues outside your hours, and site visits are planned as single trips.
Which language are assessments conducted in?
In English. Documentation in other languages can be reviewed where your team provides translations or walks us through it.
