Europe · UK · PCI DSS v4.0.1 · PCI 3DS

PCI DSS assessments across Europe and the UK, by an independent QSA.

Cianaa is a PCI Qualified Security Assessor company and 3DS QSA listed for the PCI SSC Europe region, which includes the United Kingdom. We have worked with organisations in the UK, Ireland, the Netherlands and Germany, and we assess payment institutions, e-money firms, processors, fintechs and merchants across Europe.

Report on CompliancePCI 3DS assessmentUK and EURemote and on-site

Why our assessment carries weight

One assessor for Europe and beyond

What stands behind a Cianaa assessment in Europe.

A PCI Qualified Security Assessor company on the PCI Security Standards Council register since 2014
Listed for the PCI SSC Europe, Asia Pacific and Canada regions, including the UK
3DS QSA qualified, for PCI 3DS Core Security Standard assessments
Penetration testing by independent CREST and OSCP certified testers
Founded by Dr Rizwan Ahmad, PhD, a practising QSA and MSECB Auditor of the Year 2024 for Asia Pacific

Verify any QSA company, including us, on the PCI SSC register before you engage them.

QSASince 2014

Listed for Europe on the PCI SSC register

Cianaa has been a PCI Qualified Security Assessor company since 2014. Our Europe listing makes our Report on Compliance and Attestation of Compliance valid for entities across Europe and the UK, and because we are also listed for Asia Pacific and Canada, a group operating in several of those regions can work with one assessor.

Verify us on the PCI SSC register →
Trusted by payments and security teams across Australia and New Zealand
Spark Datacom Vodafone Humm Group CCL Fidelity Illion Plan B Xplore

Overview

PCI DSS in a regulated European payments market

European payment firms work under more overlapping regulation than almost anywhere else. PCI DSS is still set by the card industry, required by the card brands and your acquirer for anyone who stores, processes or transmits card data. Level 1 merchants and service providers validate each year with a QSA’s Report on Compliance.

Alongside it sit EU and national rules: the Digital Operational Resilience Act (DORA) for financial entities, strong customer authentication under PSD2, GDPR, and NIS2 for digital infrastructure. In the UK, the FCA’s operational resilience rules and UK GDPR play the same role.

None of these frameworks require PCI DSS, and a PCI assessment is not a regulatory review. But the technical controls overlap heavily, so an assessment planned with those frameworks in mind gives your compliance team evidence it can use more than once.

The European picture

How PCI DSS fits European regulation

Where the card industry’s standard meets the rules your regulators set.

EU financial entities

DORA

Since January 2025, DORA sets requirements for ICT risk management, incident reporting, resilience testing and third-party risk. Many of the controls a QSA tests under PCI DSS map directly onto it.

Payments

PSD2 strong customer authentication

For card payments online, 3-D Secure is the main way issuers and merchants meet SCA. The security of the 3DS systems themselves is what a PCI 3DS assessment covers.

Privacy

GDPR and UK GDPR

Card data is personal data. Encryption, minimisation, retention and access controls tested under PCI DSS support your data protection duties in the EU and UK.

Digital infrastructure

NIS2

The NIS2 Directive, implemented through national laws, raises cyber security obligations for many providers in and around payments.

United Kingdom

FCA operational resilience

UK firms must identify important business services and stay within impact tolerances. Card payment services are often among them, and PCI evidence helps show they are protected.

Beyond PCI

ISO/IEC 27001 and 42001

Where a certificate is needed, our auditors conduct the audit and an independently accredited certification body issues the certificate.

What we assess

Where we work in Europe

Four markets we already know, and the rest of the Europe region under the same listing.

United Kingdom

Payment and e-money institutions, acquirers and merchants under FCA supervision. Covered by our Europe listing, as the UK sits within the PCI SSC Europe region.

Ireland

Dublin is home to the EU headquarters of many payment and e-money firms, supervised by the Central Bank of Ireland and within DORA scope.

The Netherlands

A major European payments hub, with payment institutions and processors supervised by De Nederlandsche Bank.

Germany

Payment institutions, card issuers and merchants supervised by BaFin, where DORA now sets the ICT risk framework for financial entities.

PCI 3DS across Europe

SCA makes 3-D Secure central to European card payments. Our 3DS QSA assesses access control server and 3DS server environments across the region.

Europe plus Asia Pacific or Canada

For European groups with entities in Asia Pacific or Canada, and for Asia Pacific groups expanding into Europe, one assessor across all three regions.

Process

How a European assessment runs

Remote-first, with European mornings and New Zealand evenings as the working overlap.

1
First call

Entities and validation route

We confirm which entities are in scope, which countries they sit in, and whether each needs a Report on Compliance or an SAQ.

2
Mapping

Regulatory overlap

We note where the controls under test also matter for DORA, FCA resilience or GDPR, so your team can reuse the evidence.

3
Optional

Pre-assessment

A dry run against the applicable requirements before fieldwork begins.

4
Fieldwork

Remote review and site visit

Live sessions in your morning, evidence reviewed overnight, and a planned visit to your site where the environment or acquirer requires one.

5
Reporting

ROC and AOC

Report on Compliance and Attestation of Compliance, issued once every applicable requirement is met.

6
Next year

Reassessment

Annual validation, planned early so travel and time zones never delay the attestation.

Why Cianaa

Why European firms work with Cianaa

A specialist QSA that can follow your group beyond Europe.

Three regions, one assessor

Listed for Europe, Asia Pacific and Canada. Few assessors your size can cover a group across all three.

3DS specialists

With SCA driving 3-D Secure across Europe, having a 3DS QSA and a PCI DSS QSA in the same team simplifies both assessments.

A working overlap

New Zealand evenings overlap European mornings. Live sessions happen then, and evidence review continues while you are offline.

PhD-led and published

Our founder holds a PhD in cybersecurity, and our team has ten DOI registered research papers you can read before engaging us.

Independent testers

Penetration testing is performed by independent CREST and OSCP certified testers, separate from the assessor.

Experience in four markets

We have worked with organisations in the UK, Ireland, the Netherlands and Germany, and plan site visits wherever they are needed.

Free resources

Check where you stand first

Free tools and guidance written by our QSAs. No sign-up needed.

Free tool

PCI DSS SAQ Selector

Find the right Self-Assessment Questionnaire in about a minute.

Open the tool →
Service

PCI 3DS assessments

How we assess 3DS environments against the PCI 3DS Core Security Standard.

Read more →
Guidance

SAQ A, iframes and redirects

What PCI SSC FAQ 1604 means for e-commerce payment pages and ASV scans.

Read the article →
Guidance

Vulnerability scan or penetration test?

The difference, and what PCI DSS actually requires of each.

Read the article →
Guidance

One audit trail, three frameworks

Integrating PCI DSS, ISO/IEC 27001 and SOC 2 evidence.

Read the article →
Research

Ten DOI registered papers

Our published research on security, privacy and AI governance.

Browse the research →

Complimentary · no obligation

Scope your PCI DSS assessment in Europe

A 30 minute call, in your morning, to confirm your entities, validation route and a realistic timeline, including any site visit.

Book a scoping call
30 minutesIn your morningNo obligation
  • Your entitiesWhich countries and legal entities are in scope.
  • Your validation routeReport on Compliance or SAQ for each one.
  • A realistic timelineIncluding travel and the time zone overlap.
  • Where evidence overlapsWhere PCI evidence also serves DORA, FCA or GDPR work.

An independent QSA for your European operations

Talk to a QSA about your PCI DSS or PCI 3DS assessment in Europe or the UK.

FAQ

Frequently asked questions

Can Cianaa perform PCI DSS assessments in Europe and the UK?

Yes. Cianaa is a PCI Qualified Security Assessor company listed for the PCI SSC Europe region, which includes the United Kingdom. Our listing is on the PCI SSC register.

Does DORA require PCI DSS?

No. DORA is EU law on digital operational resilience for financial entities; PCI DSS is the card industry’s standard, required by the card brands and acquirers. They overlap in ICT risk management, access control, logging, vulnerability management and third-party oversight, so evidence from one supports the other.

Is PCI penetration testing the same as DORA threat-led penetration testing?

No. Requirement 11.4 of PCI DSS calls for internal, external and segmentation testing of your card environment. DORA’s threat-led penetration testing is a separate, intelligence-led exercise required of certain significant financial entities. One does not replace the other.

How does PSD2 strong customer authentication relate to PCI 3DS?

SCA is a regulatory requirement on how customers are authenticated; 3-D Secure is the main way card payments meet it online. PCI 3DS is the security standard for the systems that run 3-D Secure, such as access control servers and 3DS servers, and is assessed by a 3DS QSA.

Does the UK still fall under the PCI SSC Europe region?

Yes. The PCI SSC Europe region includes the United Kingdom, so our listing covers UK entities as well as those in the EU.

We have entities in Europe and in Asia Pacific or Canada. Can you assess all of them?

Yes. We are listed for Europe, Asia Pacific and Canada, so all of those entities can share one assessor and one calendar. Entities in the United States, the Middle East or Africa fall in regions we are not listed for.

How do you handle the time difference?

New Zealand evenings overlap European mornings, which is when we hold interviews and live walkthroughs. Evidence review continues outside your hours, and site visits are planned as single trips.

Which language are assessments conducted in?

In English. Documentation in other languages can be reviewed where your team provides translations or walks us through it.