Pacific Islands · PCI DSS · SWIFT CSP
PCI DSS and SWIFT assessments for the Pacific, from your time zone.
Cianaa is a PCI Qualified Security Assessor company listed for Asia Pacific and an independent SWIFT CSP assessor, based in New Zealand and Australia. We assess banks, processors, airlines, hotels and merchants across Fiji, Papua New Guinea, Samoa, Tonga, Vanuatu and the wider Pacific, working your hours and a short flight away.
Why our assessment carries weight
Close by, licensed, independent
What stands behind a Cianaa assessment.
Verify any QSA company, including us, on the PCI SSC register before you engage them.
A Pacific neighbour on the PCI SSC register
Cianaa has been a PCI Qualified Security Assessor company since 2014, assessing large payment environments across Australia and New Zealand. Our Asia Pacific listing covers the Pacific Island nations, so our Report on Compliance and Attestation of Compliance are valid for your entities without bringing in an assessor from the other side of the world.
Verify us on the PCI SSC register →Overview
Card payments and SWIFT in the Pacific
Card payments are growing fast across the Pacific, driven by tourism, e-commerce and the move away from cash. Any organisation that stores, processes or transmits card data must comply with PCI DSS, as required by the card brands and acquiring banks. For banks and processors that issue cards or acquire merchants, that usually means an annual Report on Compliance from a QSA.
Banks that connect to SWIFT for international payments and remittances face a second annual obligation: attesting compliance with the SWIFT Customer Security Controls Framework, supported by an independent assessment.
Finding an independent assessor who is qualified, available and familiar with the region has often meant flying someone in from far away. We are based in New Zealand and Australia, in the same or a neighbouring time zone, and can be on site in a few hours.
Who we assess
Built for the Pacific’s payment sector
The organisations across the region that handle card data or connect to SWIFT.
Banks and credit institutions
Card issuing and acquiring
Banks that issue cards or acquire merchants need PCI DSS validation, and SWIFT users need an annual CSP attestation. We can assess both in one programme.
Processors and switches
Service providers
Payment processors, switches and gateways serving merchants and banks in the region, typically validating as Level 1 service providers.
Airlines and tourism
Hotels, resorts, airlines, duty free
High card volumes from international visitors, both card-present and online, make tourism businesses a priority for acquirers.
Mobile money and fintech
Wallets and remittance
Mobile money and remittance providers linking to card networks or SWIFT, where cardholder or payment data flows through their platforms.
Merchants and e-commerce
Online and in-store
Merchants validating with a Self-Assessment Questionnaire, where a QSA review before signing reduces the risk of errors.
Government-linked entities
Payment and revenue services
Public entities that accept card payments for services and fees, and need independent assurance over how they do it.
What we assess
What we assess in the Pacific
Assessment and testing services, combined where it saves your team time.
PCI DSS Report on Compliance
Full QSA assessment against PCI DSS v4.0.1, resulting in a Report on Compliance and Attestation of Compliance for your acquirer and the card brands.
SWIFT CSP independent assessment
Independent assessment of your SWIFT environment against the mandatory and applicable advisory controls of the Customer Security Controls Framework, supporting your annual attestation.
Combined PCI DSS and SWIFT programme
Both assessments planned together, so your team prepares overlapping evidence once and our assessors visit once.
Penetration and segmentation testing
Internal, external and segmentation testing for Requirements 11.4.1 to 11.4.5, performed by independent CREST and OSCP certified testers.
PCI 3DS assessment
Assessment of 3DS environments against the PCI 3DS Core Security Standard, led by a 3DS QSA.
Self-Assessment Questionnaire review
A QSA review of merchant and service provider SAQs and evidence before you sign.
Process
The assessment, step by step
A predictable path from first call to attestation, planned around your team and any travel.
Scoping call
We confirm what is in scope for PCI DSS, SWIFT or both, and the validation route your acquirer or SWIFT requires.
Pre-assessment
An independent look at where you stand before the formal assessment, so there are no surprises.
Evidence and visit
We agree the evidence list, interviews and on-site days, combining PCI DSS and SWIFT where possible.
Testing and interviews
Remote review first, then focused on-site work where the environment requires it.
Reports and attestation
Report on Compliance and Attestation of Compliance for PCI DSS, and an independent assessment report supporting your SWIFT attestation.
Annual cycle
Both PCI DSS and SWIFT CSP are annual. We plan the next cycle early, well ahead of the 31 December SWIFT deadline.
Why Cianaa
Why Pacific organisations choose Cianaa
Qualified, independent and close by.
Your working hours
Fiji, Tonga and Samoa share or sit within an hour or two of New Zealand time, and Papua New Guinea and Vanuatu are close to eastern Australia. Calls and reviews happen in your day, not overnight.
A short flight away
Auckland and Brisbane connect directly to most Pacific capitals, so on-site work is a short trip rather than a long-haul expedition.
Two obligations, one assessor
PCI DSS and SWIFT CSP from the same team, planned together, with evidence prepared once.
Payments specialists
We have assessed large payment environments in Australia and New Zealand since 2014. PCI DSS is our heritage, not a side line.
Independent testing
Penetration testing is performed by independent CREST and OSCP certified testers, keeping testing and assessment separate.
Research-led
Our founder holds a PhD in cybersecurity and our team has published ten DOI registered research papers.
Free resources
Check where you stand first
Free tools and guidance written by our QSAs. No sign-up needed.
PCI DSS SAQ Selector
Find which Self-Assessment Questionnaire applies to your business, in under a minute.
Open the tool →PCI DSS pre-audit maturity self-check
See how prepared you are for a PCI DSS assessment, area by area.
Start the self-check →SWIFT CSP assessments
How our independent SWIFT Customer Security Programme assessments work.
Read more →Scoping and segmentation
How to define and reduce your cardholder data environment before the assessment.
Read the guide →MFA under Requirement 8.4
What PCI DSS v4.0.1 expects of multi-factor authentication.
Read the article →Ten DOI registered papers
Original research by our team, openly licensed and permanently citable.
Browse the research →Complimentary · no obligation
Scope your PCI DSS or SWIFT assessment
A 30 minute call with one of our assessors to confirm what is in scope, whether PCI DSS and SWIFT can be combined, and a realistic timeline, including travel.
Book a scoping call- Your obligationsPCI DSS, SWIFT CSP or both, and the validation route for each.
- Your scopeWhich systems, sites and third parties are in scope.
- A realistic timelineIncluding on-site days and the 31 December SWIFT deadline.
- Where evidence overlapsWhere one piece of evidence serves both assessments.
An independent assessor in your own time zone
Talk to our team about PCI DSS and SWIFT assessments for your organisation.
FAQ
Frequently asked questions
Can Cianaa perform PCI DSS assessments in the Pacific Islands?
Yes. Cianaa is a PCI Qualified Security Assessor company listed for the PCI SSC Asia Pacific region, which covers the Pacific Island nations. You can confirm our listing on the PCI SSC register.
Which countries do you cover?
Fiji, Papua New Guinea, Samoa, Tonga, Vanuatu, the Solomon Islands, the Cook Islands and the wider Pacific, from our bases in New Zealand and Australia.
What is the SWIFT Customer Security Programme?
Every organisation connected to the SWIFT network must attest each year to its compliance with the Customer Security Controls Framework, by 31 December. The attestation must be supported by an independent assessment, which we can perform.
Can PCI DSS and SWIFT be assessed together?
Yes. The two frameworks cover different scopes but share many control areas, such as access control, logging and vulnerability management. Planning them together means your team prepares overlapping evidence once and our assessors travel once.
Do you need to come on site?
Often only for part of the work. Much of the assessment can be done remotely where it gives sufficient assurance, and on-site days are planned for the parts that need them, such as data centres or card-present environments.
Do we need a Report on Compliance or a Self-Assessment Questionnaire?
Banks, processors and Level 1 merchants usually need a Report on Compliance. Smaller merchants often validate with an SAQ, depending on what their acquirer requires. Our SAQ Selector gives a quick first answer.
Who performs the penetration testing?
Independent CREST and OSCP certified testers, separate from the QSA assessment, as PCI DSS v4.0.1 Requirement 11.4 expects.
How far ahead should we plan for the SWIFT deadline?
Ideally start by the third quarter. Independent assessments take time to schedule and complete, and the attestation must be submitted by 31 December.
