Skip to main content
A Quantum Group company Readiness firm, not an assessor  ·  Boston  ·  London
Choosing well

Most PCI DSS compliance consultants sound identical. Here is how to tell them apart.

Somebody told you to get PCI compliant, and now every firm you find promises the same thing. So this page gives you the questions to put to PCI DSS compliance consultants, the warning signs to walk away from, and an honest account of where a readiness firm stops.

Our own position, stated first. Winslow Compliance Partners is not a Qualified Security Assessor. We do not perform assessments, sign Reports on Compliance, or certify anybody. We prepare businesses so their assessor finds a tidy environment, and we introduce them to independent QSA firms.

No phone number asked for, and no sales call. A written answer instead.

Nine questions worth asking

Put these to every firm on your shortlist, including us. Good PCI DSS compliance consultants welcome them, but weak ones deflect.

Are you a QSA, or do you prepare people for one?
Who signs the attestation at the end?
Which questionnaire applies to us, and why that one?
How will you handle requirements 6.4.3 and 11.6.1?
Can you give a budget range before a full scoping exercise?
What is excluded from your fee?
Who personally does the work, and what do they hold?
Will you show a redacted sample of your work?
What happens if we fail?
Ask us these first
Trusted by

Teams who chose us over other PCI DSS compliance consultants

They asked all nine questions, and they asked other PCI DSS compliance consultants the same ones. That is exactly why we publish them.

  • Plaid logo, a client of the PCI DSS compliance consultants at Winslow
  • Brex logo, a client of the PCI DSS compliance consultants at Winslow
  • MongoDB logo, a client of the PCI DSS compliance consultants at Winslow
  • Nebius logo, a client of the PCI DSS compliance consultants at Winslow
  • ServiceNow logo, a client of the PCI DSS compliance consultants at Winslow
  • symplr logo, a client of the PCI DSS compliance consultants at Winslow
  • Cloudflare logo, a client of the PCI DSS compliance consultants at Winslow
  • Tenovi logo, a client of the PCI DSS compliance consultants at Winslow
  • Snowflake logo, a client of the PCI DSS compliance consultants at Winslow
  • Accenture logo, a client of the PCI DSS compliance consultants at Winslow
  • Taimei Technology logo, a client of the PCI DSS compliance consultants at Winslow
  • Atlassian logo, a client of the PCI DSS compliance consultants at Winslow

Logos are the property of their respective owners.

The landscape

Three kinds of firm sell themselves as PCI DSS compliance consultants

These firms do genuinely different jobs, although their websites rarely say so. However, knowing which kind of PCI DSS compliance consultants you are talking to answers most of your questions at once.

Type one

Assessors, who are not PCI DSS compliance consultants

Licensed to perform the formal audit and sign the report your bank accepts. They test, but they generally will not tell you how to fix what they find, because advising and then assessing is a conflict of interest.

Type two

Scanners, the approved vendors

Only they can run the quarterly external scans and issue the official scan attestation. That covers one requirement out of twelve, so a clean scan is not compliance.

Type three

Readiness firms, where most PCI DSS compliance consultants sit

We scope, find the gaps, fix them with your team and build the evidence. Then an independent assessor validates the result. Most PCI DSS compliance consultants sit here, although not all of them admit it.

40–60%
Of first-year spend goes to readiness work rather than to the assessor.
12
Requirements in the standard. A scan touches roughly one of them.
51
New requirements that became mandatory on 31 March 2025.
3–6 mo
Typical remediation time, which is why late starts fail.
The checklist

What good PCI DSS compliance consultants actually do

Five behaviours separate PCI DSS compliance consultants worth hiring from ones worth avoiding. Moreover, none of them are difficult to test for.

Good PCI DSS compliance consultants ask before they quote

Scope drives cost, so a number offered before anyone understands how you take payments is a guess. Good PCI DSS compliance consultants ask first and price second.

They explain scope, not just price

The useful conversation is about which systems fall inside the boundary and how to make that boundary smaller. Because scope reduction is the cheapest saving available, it should come up early.

They know what changed in v4.0.1

Ask about requirements 6.4.3, 11.6.1 and 8.4.2. Anyone still describing the 2022 version has not worked on a current assessment.

They are specific about what they cannot do

A firm that volunteers its own limits before you ask is telling you something useful. That is far more reassuring than a list of things it claims to be able to do.

They partner with assessors instead of posing as one

Preparation and validation are separate jobs for a reason. So a readiness firm that works openly alongside independent QSAs is the normal, healthy arrangement.

Walk away

Red flags when comparing PCI DSS compliance consultants

Every one of these is common among PCI DSS compliance consultants, and every one should end the conversation. We are not naming competitors, but you will recognise the phrasing.

Red flag

PCI DSS compliance consultants who guarantee a pass

Nobody can promise this, because your assessor reaches an independent conclusion. Moreover, a guarantee like that encourages box-ticking rather than security.

Red flag

PCI DSS compliance consultants who offer to certify you

Certifying and validating are assessor functions. A readiness firm claiming to certify is either confused about the rules or hoping you are.

Red flag

An official-looking compliance badge

There is no official seal. The Council explicitly forbids marks like "PCI Certified", so a badge on a homepage is a warning rather than a credential.

Red flag

A fixed price before any scoping happens

Scope moves the price by several multiples. Therefore a firm quoting instantly either intends to change the number later or does not understand the work.

Red flag

They cannot explain the questionnaires

If a firm cannot tell you plainly how the shortest form differs from the longest, they should not be choosing one on your behalf.

Red flag

No mention of the March 2025 deadline

The new requirements have been mandatory since then. Silence about it usually means the firm is quoting from an old playbook.

No obligation

Ask us anything before you shortlist PCI DSS compliance consultants

Send five answers and a question. You get a written reply with a budget range, usually within one business day, and an honest view on whether you even need PCI DSS compliance consultants.

A written answer by email, not a calendar link.
No phone number requested, and no sales call.
If you only need an assessor, we will say so and step aside.
“I do not know” is a perfectly good answer to any of these.
Step 1 of 2
1. Have you been assessed before?

This tells us whether we are starting from scratch or tidying up.

2. How do you take card payments?

Three left. Still no phone number.

3. Roughly how many card transactions a year?
4. How many systems or sites touch card data?

A written reply within one business day. No sales calls, and your details are never shared.

The distinction

Why readiness beats assessment when choosing PCI DSS compliance consultants

Businesses rarely fail because they are insecure. Instead they fail because nobody prepared the evidence, and because the boundary was never agreed. That is what good PCI DSS compliance consultants exist to prevent.

An assessor arrives, tests what you have, and writes down what is missing. That is their job and they do it well. But they are not there to fix anything, and many will not even suggest how, since advising on a control and then judging it would compromise their independence.

So the gap between those two roles is where most failed assessments live. PCI DSS compliance consultants sit in that gap. We find the issues that would fail you, fix them on a timetable you control, and hand the assessor an environment that is already tidy.

Finding a gap early is cheap. Finding it during an assessment means a failure, a remediation window and a second engagement fee.
Scope reduction is the largest saving available. Because every system inside the boundary gets tested, shrinking that boundary lowers every later cost.
Evidence is the hidden cost. Most of a bad assessment week is spent hunting screenshots nobody collected in advance.
Our limits

What our PCI DSS compliance consultants do, and never claim

We publish this because PCI DSS compliance consultants worth hiring will tell you their limits before you ask.

What Winslow does and does not do
WorkWho does it
Scoping and scope reductionUs
Gap analysis against the current standardUs
Remediation, hands-on with your teamUs
Policies, procedures and the evidence packageUs
Helping you understand your own questionnaireUs, but you sign it
The formal assessment and the signed reportAn independent QSA, never us
The quarterly external scansAn approved scanning vendor, never us
Certifying or validating complianceAn independent QSA, never us
We are not a Qualified Security Assessor and do not describe ourselves as one.
We are not affiliated with or endorsed by the PCI Security Standards Council, and we use no official marks.
We cannot promise you will pass, and we would not trust any firm that did.
Fit

Who we help, and who should hire someone else

Turning away work we cannot do well is the cheapest reputation PCI DSS compliance consultants can buy. So here is the honest split.

Good fit

You need PCI DSS compliance consultants and a deadline

A letter arrived, a date was given, and nobody internally has owned this before. That is the most common reason businesses hire PCI DSS compliance consultants, so it is exactly what we are built for.

Good fit

You failed, or you nearly did

An assessor wrote findings and you need them closed properly before the re-test. We work through that list with your engineers rather than handing back a report.

Poor fit

You do not need PCI DSS compliance consultants at all

If your controls and evidence are genuinely in order, you do not need PCI DSS compliance consultants at all. Tell us that and we will introduce you straight to an assessor, at no charge.

Where we are

Where our PCI DSS compliance consultants are based

You contract with Winslow Compliance Partners wherever your engagement runs. Because work is coordinated across US and UK hours, a question raised in the morning is usually answered the same working day.

Boston

Massachusetts, United States

1 Beacon Street
Boston, Massachusetts
United States

Eastern Time  ·  US engagements

London

United Kingdom

169 Piccadilly
London W1J 9EH
United Kingdom

Greenwich Mean Time  ·  UK and EU engagements

Common questions

Questions about hiring PCI DSS compliance consultants

What is the difference between a consultant and a QSA?

A QSA is licensed to perform the formal assessment and sign the report your bank accepts. A consultant prepares you for it. So the assessor judges, and the consultant fixes. Independence rules keep those roles apart on purpose.

Do I need PCI DSS compliance consultants, or just a QSA?

If your controls, policies and evidence are genuinely in order, you may only need the assessor. However, most businesses discover gaps once someone looks properly, and closing those before the assessment is far cheaper than failing it.

How do I tell good PCI DSS compliance consultants from bad ones?

Ask the nine questions at the top of this page. A firm that answers them plainly, states its own limits, and refuses to guarantee a pass is behaving correctly. Vagueness on any of those points is the signal.

What should PCI DSS compliance consultants cost?

Gap analysis and readiness generally runs between $8,000 and $40,000 depending on scope, with remediation on top. Readiness work typically accounts for 40 to 60 percent of first-year spend. Anything under $5,000 for real remediation is not real work.

Can PCI DSS compliance consultants guarantee we pass?

No. Your assessor reaches an independent conclusion, so no consultant controls the outcome. Anyone promising a pass is either misinformed or selling you a box-ticking exercise.

We use Stripe, so do we need PCI DSS compliance consultants?

A hosted checkout shrinks the work considerably, although it does not remove it. Requirements 6.4.3 and 11.6.1, which cover the scripts on your payment page, remain yours. Many businesses on the shortest questionnaire are surprised by that.

Why is there no phone number on this site?

Because five written questions tell us more about your situation than a discovery call would, and it also respects your time. You get a written answer instead of a calendar invitation.

Not sure where to start? Ask us anything