Singapore · PCI DSS v4.0.1 · PCI 3DS

PCI DSS assessments in Singapore, by an independent QSA.

Cianaa is a PCI Qualified Security Assessor company listed for the Asia Pacific region. We assess payment institutions, payment service providers and merchants in Singapore against PCI DSS v4.0.1 and the PCI 3DS Core Security Standard, and issue the Report on Compliance and Attestation of Compliance your acquirer and the card brands ask for.

Report on ComplianceAttestation of ComplianceRemote and on-siteAsia Pacific licence

Why our assessment carries weight

Licensed, independent, published

What stands behind a Cianaa Report on Compliance.

A PCI Qualified Security Assessor company on the PCI Security Standards Council register since 2014
Listed for the PCI SSC Asia Pacific, Europe and Canada regions
3DS QSA qualified, for PCI 3DS Core Security Standard assessments
Penetration testing by independent CREST and OSCP certified testers
Founded by Dr Rizwan Ahmad, PhD, a practising QSA and MSECB Auditor of the Year 2024 for Asia Pacific

Verify any QSA company, including us, on the PCI SSC register before you engage them.

QSASince 2014

On the PCI SSC register since 2014

Cianaa has been a PCI Qualified Security Assessor company for more than a decade, assessing some of the largest payment environments in Australia and New Zealand. Our Asia Pacific listing means our Report on Compliance and Attestation of Compliance are valid for entities in Singapore, and our Europe and Canada listings let one assessor cover a regional group across all three.

Verify us on the PCI SSC register →
Trusted by payments and security teams across Australia and New Zealand
Spark Datacom Vodafone Humm Group CCL Fidelity Illion Plan B Xplore

Overview

PCI DSS in Singapore’s payments market

Any organisation that stores, processes or transmits payment card data, or can affect the security of that data, must comply with the Payment Card Industry Data Security Standard (PCI DSS). The card brands and your acquiring bank decide how you validate: Level 1 merchants and service providers need an annual assessment by a QSA, resulting in a Report on Compliance.

In Singapore that includes payment institutions licensed under the Payment Services Act 2019, payment gateways and processors, e-wallets, fintechs, e-commerce and travel merchants, and the regional headquarters that run card-processing platforms for Asia Pacific.

These organisations already work to the Monetary Authority of Singapore’s technology risk expectations. PCI DSS does not replace them, and a PCI DSS assessment is not a regulatory review. But many of the controls overlap, so a well-run assessment produces independent evidence your team can reuse.

How it fits

Where PCI DSS meets what you already do

Singapore payment firms answer to several frameworks at once. These are the ones a PCI DSS assessment touches most.

Card brands

PCI DSS v4.0.1

Twelve requirements covering network security, data protection, vulnerability management, access control, monitoring and policy. Validated annually.

MAS

Technology Risk Management Guidelines

MAS expectations for technology risk governance, access control, cryptography, logging and vulnerability management overlap heavily with PCI DSS controls.

MAS

Cyber hygiene requirements

Baseline controls such as administrator account security, patching, perimeter defence, malware protection and multi-factor authentication, which PCI DSS also tests.

PDPC

Personal Data Protection Act

Card data is personal data. PCI DSS controls over storage, encryption and access support your PDPA protection obligations.

EMVCo and PCI SSC

PCI 3DS

For 3DS server and access control server environments, a separate assessment against the PCI 3DS Core Security Standard by a 3DS QSA.

ISO

ISO/IEC 27001 and 42001

Where you also need certification, our auditors can conduct the audit, with the certificate issued by an independently accredited certification body.

What we assess

What we assess in Singapore

Assessment and testing services, delivered remotely with on-site visits where the standard or your environment requires them.

PCI DSS Report on Compliance

Full QSA assessment of your cardholder data environment against PCI DSS v4.0.1, resulting in a Report on Compliance and Attestation of Compliance for your acquirer and the card brands.

PCI 3DS assessment

Assessment of 3DS server, access control server and directory server environments against the PCI 3DS Core Security Standard, led by a 3DS QSA.

Penetration and segmentation testing

Internal, external and segmentation testing for Requirements 11.4.1 to 11.4.5, performed by independent CREST and OSCP certified testers.

Self-Assessment Questionnaire review

For merchants and service providers who validate with an SAQ, a QSA review of your answers and evidence before you sign.

Multi-region programmes

One assessment timetable for groups with entities in Singapore and elsewhere in Asia Pacific, Europe or Canada.

ISO/IEC 27001 and 42001 audits

Certification audits for information security and AI management systems, with certificates issued by independently accredited certification bodies.

Process

The assessment, step by step

A predictable path from first call to Attestation of Compliance, then every year after.

1
Week 1

Scoping call

We confirm your merchant or service provider level, the systems in scope, and whether you need a Report on Compliance or an SAQ.

2
Optional

Pre-assessment

An independent look at where you stand before the formal assessment, so there are no surprises on the day.

3
Planning

Evidence and schedule

We agree the evidence list, interview schedule and any on-site visits, planned around your team’s calendar.

4
Assessment

Testing and interviews

We test each applicable requirement, sample systems and interview the people who operate the controls.

5
Reporting

Report on Compliance

We issue the Report on Compliance and Attestation of Compliance once all applicable requirements are met.

6
Every year

Annual reassessment

PCI DSS compliance is validated annually. We plan the next cycle early so compliance stays continuous.

Why Cianaa

Why Singapore firms choose Cianaa

A specialist QSA with the licence, the depth and the working hours to serve you well.

Licensed where you operate

Our Asia Pacific, Europe and Canada listings let one assessor cover your Singapore entity and your group entities elsewhere, with one timetable and one evidence set.

Hours that overlap

Our teams work from New Zealand and Australia, two to five hours ahead of Singapore, so your working day and ours overlap for most of it.

Payments specialists

PCI DSS and PCI 3DS are our heritage, not a side line. We have assessed large payment environments since 2014.

Research, not just opinion

Our founder holds a PhD in cybersecurity, and our team has published ten DOI registered research papers. You can read how we think before you engage us.

Independent testing

Penetration testing is performed by independent CREST and OSCP certified testers, so testing and assessment stay separate.

On site when it matters

Remote assessment where the standard allows it, and planned visits to Singapore where your environment or your acquirer needs us there.

Free resources

Check where you stand first

Free tools and guidance written by our QSAs. No sign-up needed.

Free tool

PCI DSS SAQ Selector

Answer a few questions and find which Self-Assessment Questionnaire applies to you, in under a minute.

Open the tool →
Free tool

PCI DSS pre-audit maturity self-check

See how prepared you are for a PCI DSS assessment, area by area.

Start the self-check →
Guidance

Scoping and segmentation

How to define and reduce your cardholder data environment before the assessment.

Read the guide →
Guidance

PCI DSS v4.0.1 future-dated requirements

What changed when the future-dated requirements came into force, and what assessors now test.

Read the article →
Guidance

MFA under Requirement 8.4

What PCI DSS v4.0.1 expects of multi-factor authentication, and where teams go wrong.

Read the article →
Research

Ten DOI registered papers

Original research by our team, openly licensed and permanently citable.

Browse the research →

Complimentary · no obligation

Scope your PCI DSS assessment in Singapore

A 30 minute call with one of our QSAs to confirm your level, what is in scope and a realistic timeline to your Attestation of Compliance.

Book a scoping call
30 minute callWith a QSANo obligation
  • Your validation routeReport on Compliance or SAQ, confirmed against your level.
  • Your scopeWhich systems, people and third parties are in scope.
  • A realistic timelineFrom kick-off to Attestation of Compliance.
  • Where you can reuse evidenceWhere existing MAS or ISO evidence carries across.

An independent QSA for your Singapore operations

Talk to our QSAs about scoping your PCI DSS or PCI 3DS assessment.

FAQ

Frequently asked questions

Can Cianaa perform PCI DSS assessments in Singapore?

Yes. Cianaa is a PCI Qualified Security Assessor company listed for the PCI SSC Asia Pacific region, which includes Singapore. You can confirm our listing on the PCI SSC register.

Does MAS require PCI DSS?

PCI DSS is a card industry standard, required by the card brands and your acquiring bank rather than by MAS. MAS sets its own technology risk and cyber hygiene expectations. The two overlap substantially, so evidence from a PCI DSS assessment can support your wider technology risk work.

Do we need a Report on Compliance or a Self-Assessment Questionnaire?

It depends on your transaction volume, whether you are a merchant or a service provider, and what your acquirer requires. Level 1 merchants and service providers generally need a Report on Compliance from a QSA. Our SAQ Selector gives a quick first answer, and we confirm it on the scoping call.

Can the assessment be done remotely?

Much of it can. PCI SSC guidance allows remote assessment techniques where they give the assessor sufficient assurance. Some environments, such as physical data centres or card-present operations, may need an on-site visit, which we plan with you.

Do you assess PCI 3DS as well?

Yes. Our 3DS QSA assesses 3DS server, access control server and directory server environments against the PCI 3DS Core Security Standard.

We have entities in Singapore and in other countries. Can you assess all of them?

If they are in the Asia Pacific, Europe or Canada regions, yes, under one programme and timetable. Entities in the United States, the Middle East or Africa fall in PCI SSC regions we are not listed for.

Who performs the penetration testing?

Penetration and segmentation testing is performed by independent CREST and OSCP certified testers, separate from the QSA assessment, as PCI DSS v4.0.1 Requirement 11.4 expects.

How long does a PCI DSS assessment take?

For a well-prepared Level 1 environment, typically a few weeks of assessment activity, spread over one to three months from kick-off to Attestation of Compliance. Scope and preparedness are the biggest factors.