Pacific Islands · PCI DSS · SWIFT CSP

PCI DSS and SWIFT assessments for the Pacific, from your time zone.

Cianaa is a PCI Qualified Security Assessor company listed for Asia Pacific and an independent SWIFT CSP assessor, based in New Zealand and Australia. We assess banks, processors, airlines, hotels and merchants across Fiji, Papua New Guinea, Samoa, Tonga, Vanuatu and the wider Pacific, working your hours and a short flight away.

PCI DSS Report on ComplianceSWIFT CSP assessmentSame or nearby time zoneShort flights from Auckland and Brisbane

Why our assessment carries weight

Close by, licensed, independent

What stands behind a Cianaa assessment.

A PCI Qualified Security Assessor company on the PCI Security Standards Council register since 2014
Listed for the PCI SSC Asia Pacific, Europe and Canada regions
Independent assessor for the SWIFT Customer Security Programme
Penetration testing by independent CREST and OSCP certified testers
Founded by Dr Rizwan Ahmad, PhD, a practising QSA and MSECB Auditor of the Year 2024 for Asia Pacific

Verify any QSA company, including us, on the PCI SSC register before you engage them.

QSASince 2014

A Pacific neighbour on the PCI SSC register

Cianaa has been a PCI Qualified Security Assessor company since 2014, assessing large payment environments across Australia and New Zealand. Our Asia Pacific listing covers the Pacific Island nations, so our Report on Compliance and Attestation of Compliance are valid for your entities without bringing in an assessor from the other side of the world.

Verify us on the PCI SSC register →
Trusted by payments and security teams across Australia and New Zealand
Spark Datacom Vodafone Humm Group CCL Fidelity Illion Plan B Xplore

Overview

Card payments and SWIFT in the Pacific

Card payments are growing fast across the Pacific, driven by tourism, e-commerce and the move away from cash. Any organisation that stores, processes or transmits card data must comply with PCI DSS, as required by the card brands and acquiring banks. For banks and processors that issue cards or acquire merchants, that usually means an annual Report on Compliance from a QSA.

Banks that connect to SWIFT for international payments and remittances face a second annual obligation: attesting compliance with the SWIFT Customer Security Controls Framework, supported by an independent assessment.

Finding an independent assessor who is qualified, available and familiar with the region has often meant flying someone in from far away. We are based in New Zealand and Australia, in the same or a neighbouring time zone, and can be on site in a few hours.

Who we assess

Built for the Pacific’s payment sector

The organisations across the region that handle card data or connect to SWIFT.

Banks and credit institutions

Card issuing and acquiring

Banks that issue cards or acquire merchants need PCI DSS validation, and SWIFT users need an annual CSP attestation. We can assess both in one programme.

Processors and switches

Service providers

Payment processors, switches and gateways serving merchants and banks in the region, typically validating as Level 1 service providers.

Airlines and tourism

Hotels, resorts, airlines, duty free

High card volumes from international visitors, both card-present and online, make tourism businesses a priority for acquirers.

Mobile money and fintech

Wallets and remittance

Mobile money and remittance providers linking to card networks or SWIFT, where cardholder or payment data flows through their platforms.

Merchants and e-commerce

Online and in-store

Merchants validating with a Self-Assessment Questionnaire, where a QSA review before signing reduces the risk of errors.

Government-linked entities

Payment and revenue services

Public entities that accept card payments for services and fees, and need independent assurance over how they do it.

What we assess

What we assess in the Pacific

Assessment and testing services, combined where it saves your team time.

PCI DSS Report on Compliance

Full QSA assessment against PCI DSS v4.0.1, resulting in a Report on Compliance and Attestation of Compliance for your acquirer and the card brands.

SWIFT CSP independent assessment

Independent assessment of your SWIFT environment against the mandatory and applicable advisory controls of the Customer Security Controls Framework, supporting your annual attestation.

Combined PCI DSS and SWIFT programme

Both assessments planned together, so your team prepares overlapping evidence once and our assessors visit once.

Penetration and segmentation testing

Internal, external and segmentation testing for Requirements 11.4.1 to 11.4.5, performed by independent CREST and OSCP certified testers.

PCI 3DS assessment

Assessment of 3DS environments against the PCI 3DS Core Security Standard, led by a 3DS QSA.

Self-Assessment Questionnaire review

A QSA review of merchant and service provider SAQs and evidence before you sign.

Process

The assessment, step by step

A predictable path from first call to attestation, planned around your team and any travel.

1
Week 1

Scoping call

We confirm what is in scope for PCI DSS, SWIFT or both, and the validation route your acquirer or SWIFT requires.

2
Optional

Pre-assessment

An independent look at where you stand before the formal assessment, so there are no surprises.

3
Planning

Evidence and visit

We agree the evidence list, interviews and on-site days, combining PCI DSS and SWIFT where possible.

4
Assessment

Testing and interviews

Remote review first, then focused on-site work where the environment requires it.

5
Reporting

Reports and attestation

Report on Compliance and Attestation of Compliance for PCI DSS, and an independent assessment report supporting your SWIFT attestation.

6
Every year

Annual cycle

Both PCI DSS and SWIFT CSP are annual. We plan the next cycle early, well ahead of the 31 December SWIFT deadline.

Why Cianaa

Why Pacific organisations choose Cianaa

Qualified, independent and close by.

Your working hours

Fiji, Tonga and Samoa share or sit within an hour or two of New Zealand time, and Papua New Guinea and Vanuatu are close to eastern Australia. Calls and reviews happen in your day, not overnight.

A short flight away

Auckland and Brisbane connect directly to most Pacific capitals, so on-site work is a short trip rather than a long-haul expedition.

Two obligations, one assessor

PCI DSS and SWIFT CSP from the same team, planned together, with evidence prepared once.

Payments specialists

We have assessed large payment environments in Australia and New Zealand since 2014. PCI DSS is our heritage, not a side line.

Independent testing

Penetration testing is performed by independent CREST and OSCP certified testers, keeping testing and assessment separate.

Research-led

Our founder holds a PhD in cybersecurity and our team has published ten DOI registered research papers.

Free resources

Check where you stand first

Free tools and guidance written by our QSAs. No sign-up needed.

Free tool

PCI DSS SAQ Selector

Find which Self-Assessment Questionnaire applies to your business, in under a minute.

Open the tool →
Free tool

PCI DSS pre-audit maturity self-check

See how prepared you are for a PCI DSS assessment, area by area.

Start the self-check →
Service

SWIFT CSP assessments

How our independent SWIFT Customer Security Programme assessments work.

Read more →
Guidance

Scoping and segmentation

How to define and reduce your cardholder data environment before the assessment.

Read the guide →
Guidance

MFA under Requirement 8.4

What PCI DSS v4.0.1 expects of multi-factor authentication.

Read the article →
Research

Ten DOI registered papers

Original research by our team, openly licensed and permanently citable.

Browse the research →

Complimentary · no obligation

Scope your PCI DSS or SWIFT assessment

A 30 minute call with one of our assessors to confirm what is in scope, whether PCI DSS and SWIFT can be combined, and a realistic timeline, including travel.

Book a scoping call
30 minute callWith a QSANo obligation
  • Your obligationsPCI DSS, SWIFT CSP or both, and the validation route for each.
  • Your scopeWhich systems, sites and third parties are in scope.
  • A realistic timelineIncluding on-site days and the 31 December SWIFT deadline.
  • Where evidence overlapsWhere one piece of evidence serves both assessments.

An independent assessor in your own time zone

Talk to our team about PCI DSS and SWIFT assessments for your organisation.

FAQ

Frequently asked questions

Can Cianaa perform PCI DSS assessments in the Pacific Islands?

Yes. Cianaa is a PCI Qualified Security Assessor company listed for the PCI SSC Asia Pacific region, which covers the Pacific Island nations. You can confirm our listing on the PCI SSC register.

Which countries do you cover?

Fiji, Papua New Guinea, Samoa, Tonga, Vanuatu, the Solomon Islands, the Cook Islands and the wider Pacific, from our bases in New Zealand and Australia.

What is the SWIFT Customer Security Programme?

Every organisation connected to the SWIFT network must attest each year to its compliance with the Customer Security Controls Framework, by 31 December. The attestation must be supported by an independent assessment, which we can perform.

Can PCI DSS and SWIFT be assessed together?

Yes. The two frameworks cover different scopes but share many control areas, such as access control, logging and vulnerability management. Planning them together means your team prepares overlapping evidence once and our assessors travel once.

Do you need to come on site?

Often only for part of the work. Much of the assessment can be done remotely where it gives sufficient assurance, and on-site days are planned for the parts that need them, such as data centres or card-present environments.

Do we need a Report on Compliance or a Self-Assessment Questionnaire?

Banks, processors and Level 1 merchants usually need a Report on Compliance. Smaller merchants often validate with an SAQ, depending on what their acquirer requires. Our SAQ Selector gives a quick first answer.

Who performs the penetration testing?

Independent CREST and OSCP certified testers, separate from the QSA assessment, as PCI DSS v4.0.1 Requirement 11.4 expects.

How far ahead should we plan for the SWIFT deadline?

Ideally start by the third quarter. Independent assessments take time to schedule and complete, and the attestation must be submitted by 31 December.