Singapore · PCI DSS v4.0.1 · PCI 3DS
PCI DSS assessments in Singapore, by an independent QSA.
Cianaa is a PCI Qualified Security Assessor company listed for the Asia Pacific region. We assess payment institutions, payment service providers and merchants in Singapore against PCI DSS v4.0.1 and the PCI 3DS Core Security Standard, and issue the Report on Compliance and Attestation of Compliance your acquirer and the card brands ask for.
Why our assessment carries weight
Licensed, independent, published
What stands behind a Cianaa Report on Compliance.
Verify any QSA company, including us, on the PCI SSC register before you engage them.
On the PCI SSC register since 2014
Cianaa has been a PCI Qualified Security Assessor company for more than a decade, assessing some of the largest payment environments in Australia and New Zealand. Our Asia Pacific listing means our Report on Compliance and Attestation of Compliance are valid for entities in Singapore, and our Europe and Canada listings let one assessor cover a regional group across all three.
Verify us on the PCI SSC register →Overview
PCI DSS in Singapore’s payments market
Any organisation that stores, processes or transmits payment card data, or can affect the security of that data, must comply with the Payment Card Industry Data Security Standard (PCI DSS). The card brands and your acquiring bank decide how you validate: Level 1 merchants and service providers need an annual assessment by a QSA, resulting in a Report on Compliance.
In Singapore that includes payment institutions licensed under the Payment Services Act 2019, payment gateways and processors, e-wallets, fintechs, e-commerce and travel merchants, and the regional headquarters that run card-processing platforms for Asia Pacific.
These organisations already work to the Monetary Authority of Singapore’s technology risk expectations. PCI DSS does not replace them, and a PCI DSS assessment is not a regulatory review. But many of the controls overlap, so a well-run assessment produces independent evidence your team can reuse.
How it fits
Where PCI DSS meets what you already do
Singapore payment firms answer to several frameworks at once. These are the ones a PCI DSS assessment touches most.
Card brands
PCI DSS v4.0.1
Twelve requirements covering network security, data protection, vulnerability management, access control, monitoring and policy. Validated annually.
MAS
Technology Risk Management Guidelines
MAS expectations for technology risk governance, access control, cryptography, logging and vulnerability management overlap heavily with PCI DSS controls.
MAS
Cyber hygiene requirements
Baseline controls such as administrator account security, patching, perimeter defence, malware protection and multi-factor authentication, which PCI DSS also tests.
PDPC
Personal Data Protection Act
Card data is personal data. PCI DSS controls over storage, encryption and access support your PDPA protection obligations.
EMVCo and PCI SSC
PCI 3DS
For 3DS server and access control server environments, a separate assessment against the PCI 3DS Core Security Standard by a 3DS QSA.
ISO
ISO/IEC 27001 and 42001
Where you also need certification, our auditors can conduct the audit, with the certificate issued by an independently accredited certification body.
What we assess
What we assess in Singapore
Assessment and testing services, delivered remotely with on-site visits where the standard or your environment requires them.
PCI DSS Report on Compliance
Full QSA assessment of your cardholder data environment against PCI DSS v4.0.1, resulting in a Report on Compliance and Attestation of Compliance for your acquirer and the card brands.
PCI 3DS assessment
Assessment of 3DS server, access control server and directory server environments against the PCI 3DS Core Security Standard, led by a 3DS QSA.
Penetration and segmentation testing
Internal, external and segmentation testing for Requirements 11.4.1 to 11.4.5, performed by independent CREST and OSCP certified testers.
Self-Assessment Questionnaire review
For merchants and service providers who validate with an SAQ, a QSA review of your answers and evidence before you sign.
Multi-region programmes
One assessment timetable for groups with entities in Singapore and elsewhere in Asia Pacific, Europe or Canada.
ISO/IEC 27001 and 42001 audits
Certification audits for information security and AI management systems, with certificates issued by independently accredited certification bodies.
Process
The assessment, step by step
A predictable path from first call to Attestation of Compliance, then every year after.
Scoping call
We confirm your merchant or service provider level, the systems in scope, and whether you need a Report on Compliance or an SAQ.
Pre-assessment
An independent look at where you stand before the formal assessment, so there are no surprises on the day.
Evidence and schedule
We agree the evidence list, interview schedule and any on-site visits, planned around your team’s calendar.
Testing and interviews
We test each applicable requirement, sample systems and interview the people who operate the controls.
Report on Compliance
We issue the Report on Compliance and Attestation of Compliance once all applicable requirements are met.
Annual reassessment
PCI DSS compliance is validated annually. We plan the next cycle early so compliance stays continuous.
Why Cianaa
Why Singapore firms choose Cianaa
A specialist QSA with the licence, the depth and the working hours to serve you well.
Licensed where you operate
Our Asia Pacific, Europe and Canada listings let one assessor cover your Singapore entity and your group entities elsewhere, with one timetable and one evidence set.
Hours that overlap
Our teams work from New Zealand and Australia, two to five hours ahead of Singapore, so your working day and ours overlap for most of it.
Payments specialists
PCI DSS and PCI 3DS are our heritage, not a side line. We have assessed large payment environments since 2014.
Research, not just opinion
Our founder holds a PhD in cybersecurity, and our team has published ten DOI registered research papers. You can read how we think before you engage us.
Independent testing
Penetration testing is performed by independent CREST and OSCP certified testers, so testing and assessment stay separate.
On site when it matters
Remote assessment where the standard allows it, and planned visits to Singapore where your environment or your acquirer needs us there.
Free resources
Check where you stand first
Free tools and guidance written by our QSAs. No sign-up needed.
PCI DSS SAQ Selector
Answer a few questions and find which Self-Assessment Questionnaire applies to you, in under a minute.
Open the tool →PCI DSS pre-audit maturity self-check
See how prepared you are for a PCI DSS assessment, area by area.
Start the self-check →Scoping and segmentation
How to define and reduce your cardholder data environment before the assessment.
Read the guide →PCI DSS v4.0.1 future-dated requirements
What changed when the future-dated requirements came into force, and what assessors now test.
Read the article →MFA under Requirement 8.4
What PCI DSS v4.0.1 expects of multi-factor authentication, and where teams go wrong.
Read the article →Ten DOI registered papers
Original research by our team, openly licensed and permanently citable.
Browse the research →Complimentary · no obligation
Scope your PCI DSS assessment in Singapore
A 30 minute call with one of our QSAs to confirm your level, what is in scope and a realistic timeline to your Attestation of Compliance.
Book a scoping call- Your validation routeReport on Compliance or SAQ, confirmed against your level.
- Your scopeWhich systems, people and third parties are in scope.
- A realistic timelineFrom kick-off to Attestation of Compliance.
- Where you can reuse evidenceWhere existing MAS or ISO evidence carries across.
An independent QSA for your Singapore operations
Talk to our QSAs about scoping your PCI DSS or PCI 3DS assessment.
FAQ
Frequently asked questions
Can Cianaa perform PCI DSS assessments in Singapore?
Yes. Cianaa is a PCI Qualified Security Assessor company listed for the PCI SSC Asia Pacific region, which includes Singapore. You can confirm our listing on the PCI SSC register.
Does MAS require PCI DSS?
PCI DSS is a card industry standard, required by the card brands and your acquiring bank rather than by MAS. MAS sets its own technology risk and cyber hygiene expectations. The two overlap substantially, so evidence from a PCI DSS assessment can support your wider technology risk work.
Do we need a Report on Compliance or a Self-Assessment Questionnaire?
It depends on your transaction volume, whether you are a merchant or a service provider, and what your acquirer requires. Level 1 merchants and service providers generally need a Report on Compliance from a QSA. Our SAQ Selector gives a quick first answer, and we confirm it on the scoping call.
Can the assessment be done remotely?
Much of it can. PCI SSC guidance allows remote assessment techniques where they give the assessor sufficient assurance. Some environments, such as physical data centres or card-present operations, may need an on-site visit, which we plan with you.
Do you assess PCI 3DS as well?
Yes. Our 3DS QSA assesses 3DS server, access control server and directory server environments against the PCI 3DS Core Security Standard.
We have entities in Singapore and in other countries. Can you assess all of them?
If they are in the Asia Pacific, Europe or Canada regions, yes, under one programme and timetable. Entities in the United States, the Middle East or Africa fall in PCI SSC regions we are not listed for.
Who performs the penetration testing?
Penetration and segmentation testing is performed by independent CREST and OSCP certified testers, separate from the QSA assessment, as PCI DSS v4.0.1 Requirement 11.4 expects.
How long does a PCI DSS assessment take?
For a well-prepared Level 1 environment, typically a few weeks of assessment activity, spread over one to three months from kick-off to Attestation of Compliance. Scope and preparedness are the biggest factors.
