PCI DSS Payment Security Compliance Training Course

5 days Financial Technology Certificate on completion
Course codeSD-FT-008
Duration5 days
LevelIntermediate to Advanced
CategoryFinancial Technology
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Payment environments rarely fail compliance because teams have never read a PCI DSS requirement. They fail because cardholder-data flows are incompletely mapped, scope boundaries are assumed rather than evidenced, supplier responsibilities are unclear, and controls cannot be demonstrated to a QSA, acquirer, or internal audit team. This five-day PCI DSS Payment Security Compliance Training Course equips finance, technology, risk, and security professionals to translate PCI DSS v4.0.1 into a defensible operating model for payment acceptance, processing, storage, and outsourced services.

Participants work through the PCI DSS assessment method from scoping through evidence review, gap analysis, remediation planning, and validation. They learn to identify account data and system components in scope; determine appropriate SAQ, ROC, and Attestation of Compliance routes; test controls against PCI DSS requirements; assess compensating controls and customized approaches; manage third-party service-provider dependencies; and prepare evidence for annual validation. The course addresses core technical and operational areas including network segmentation, access control, vulnerability management, logging, secure software practices, incident response, and continuous compliance.

Instructor-led briefings are paired with payment-environment case studies, evidence-review labs, scoping workshops, and group assessment exercises. Participants analyse a realistic merchant and service-provider scenario, make scope decisions, evaluate sample artefacts, record findings, and defend remediation priorities. They leave with a practical PCI DSS assessment pack: a cardholder-data environment scope map, responsibility matrix, requirement-to-evidence matrix, gap register, and risk-ranked remediation roadmap that can be adapted for their organisation.

The course is designed for experienced professionals who contribute to payment security, PCI compliance, internal audit, IT operations, product delivery, vendor governance, or financial-control functions. It is particularly valuable where payment systems, cloud services, e-commerce platforms, and external processors create complex ownership and evidence challenges.

Course objectives

By the end of this course, participants will be able to:

  • Map cardholder-data flows and define the PCI DSS cardholder-data environment scope
  • Select the appropriate PCI SSC validation route using SAQ, ROC, and AOC criteria
  • Assess PCI DSS v4.0.1 requirements against policies, configurations, logs, and control evidence
  • Build a requirement-to-evidence matrix for an internal PCI DSS readiness assessment
  • Evaluate network segmentation evidence and document its impact on PCI DSS scope
  • Produce a PCI DSS gap register with risk ratings, control owners, and remediation dates
  • Assess third-party service-provider responsibilities using a PCI accountability matrix
  • Create a risk-ranked remediation roadmap and annual PCI DSS compliance calendar

Benefits of attending

For you

  • Gain the ability to lead or contribute credibly to PCI DSS scoping and readiness assessments
  • Build evidence-based audit skills for reviewing payment-security controls rather than relying on policy statements
  • Strengthen credibility with QSAs, acquirers, internal audit teams, and payment-service providers
  • Develop a reusable approach for translating PCI DSS findings into owned remediation actions
  • Prepare for expanded responsibilities in payment security, GRC, technology risk, or PCI compliance management

For your organisation

  • Reduce the risk of omitted systems and uncontrolled suppliers remaining within the cardholder-data environment
  • Improve the quality and traceability of evidence presented during SAQ, ROC, and internal audit activities
  • Create clearer accountability between merchants, service providers, security teams, and operational control owners
  • Prioritise PCI DSS remediation by risk, requirement dependency, and validation deadlines
  • Embed PCI DSS considerations into payment changes, cloud adoption, vendor onboarding, and business-as-usual control testing

Target competencies

PCI DSS scopingControl evidence testingPayment data mappingGap remediation planningThird-party accountabilityValidation preparation

Who should attend

  • PCI Compliance Managers — who coordinate assessment evidence, remediation activity, and annual validation
  • Information Security Managers — who must operate and evidence technical controls across payment environments
  • Internal Auditors — who test payment-security controls and report assurance findings
  • IT Infrastructure and Network Managers — who own segmentation, access, logging, and vulnerability-management controls
  • Payment Operations and FinTech Product Managers — who need to design payment changes without expanding unmanaged PCI scope
  • Third-Party Risk and Vendor Managers — who must establish and monitor service-provider PCI responsibilities

Requirements and prerequisites

Participants should have working experience in information security, IT operations, internal audit, payment operations, risk, or compliance. They should understand basic network concepts such as firewalls, VLANs, segmentation, authentication, privileged access, encryption, vulnerability scanning, and log review. Familiarity with payment terms including PAN, cardholder data environment, merchant, acquirer, processor, and service provider is helpful. Participants should be able to read a policy, system diagram, audit finding, or spreadsheet-based control register. Prior QSA experience, coding ability, penetration-testing expertise, or previous PCI DSS certification is not required.

Training methodology

The programme combines instructor-led PCI DSS interpretation with structured assessment practice. Participants work in small teams on a realistic payment environment containing e-commerce components, cloud-hosted services, network segments, payment gateways, and outsourced providers. Exercises use sample diagrams, policies, scan outputs, access reviews, incident records, and supplier attestations to distinguish acceptable evidence from unsupported claims. Daily workshops build one linked assessment pack, culminating in a group presentation of scope decisions, key gaps, remediation priorities, and an implementation plan for the participant’s own environment.

Course outline

Day 1: PCI DSS foundations, payment flows, and scope

  • PCI DSS v4.0.1 structure, intent, and assessment lifecycle
  • Roles of merchants, acquirers, processors, QSAs, and service providers
  • Account data definitions: PAN, SAD, cardholder data, and authentication data
  • Cardholder-data environment identification and system-component inventory
  • Payment-channel mapping for e-commerce, MOTO, retail, and mobile acceptance
  • Scope reduction through tokenisation, outsourcing, and validated segmentation
  • SAQ, ROC, and Attestation of Compliance selection criteria

Workshop: Participants create a cardholder-data flow diagram and initial PCI DSS scope statement for a multi-channel merchant scenario.

Day 2: Testing technical PCI DSS controls

  • Network security controls and firewall rule-set evidence
  • Secure configurations, hardening standards, and configuration-change records
  • Protection of stored account data through masking, truncation, and cryptography
  • Key-management lifecycle evidence for encryption keys and custodians
  • Identity and access management, least privilege, and privileged-account reviews
  • Multi-factor authentication coverage and authentication-event evidence
  • Malware protection, vulnerability scanning, patching, and penetration-testing evidence

Workshop: Participants review a technical evidence pack, test selected requirements, and record supported findings in an evidence matrix.

Day 3: Operational controls, secure delivery, and monitoring

  • Secure software development requirements and software-change governance
  • Web application protection, payment-page scripts, and e-commerce integrity controls
  • Logging, time synchronisation, retention, and security-event review procedures
  • Security operations monitoring and alert escalation workflows
  • Incident response planning, payment-brand notification, and forensic readiness
  • Security awareness training and role-specific PCI DSS responsibilities
  • Information-security policy governance and annual control review

Workshop: Participants assess a payment-page change and incident scenario, producing findings, evidence requests, and corrective actions.

Day 4: Assessment evidence, third parties, and remediation

  • PCI DSS testing procedures and sampling rationale
  • Designing requirement-to-evidence matrices and evidence-request lists
  • Distinguishing control design, operating effectiveness, and unsupported assertions
  • Third-party service-provider due diligence and responsibility allocation
  • Reviewing AOCs, service descriptions, shared-responsibility models, and contractual commitments
  • Compensating controls and customized approaches under PCI DSS v4.0.1
  • Gap-register construction, risk scoring, ownership, and remediation dependencies

Workshop: Participants build a supplier responsibility matrix and risk-ranked gap register from a service-provider evidence case.

Day 5: Validation readiness and compliance operating model

  • Preparing for QSA interviews, evidence walkthroughs, and validation milestones
  • ROC and SAQ completion quality checks
  • Attestation of Compliance review and executive sign-off considerations
  • PCI DSS transition timelines and future-dated requirement planning
  • Continuous compliance control testing and annual compliance calendars
  • PCI metrics for remediation governance and management reporting
  • Integrating PCI DSS into change management, cloud onboarding, and vendor lifecycle processes

Workshop: Participants present a final PCI DSS assessment pack containing scope, evidence priorities, gaps, remediation roadmap, and 90-day action plan.

Tools & standards covered

PCI DSS v4.0.1, PCI SSC Self-Assessment Questionnaire (SAQ), PCI SSC Attestation of Compliance (AOC), NIST SP 800-115

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

No prior PCI assessment experience is required, but this is an intermediate-to-advanced course rather than an introduction to IT or payment systems. Participants should understand basic security controls, network concepts, and the role their organisation plays in accepting or processing card payments.

A laptop is recommended for working with the course templates, diagrams, and evidence-review exercises. Access to live organisational systems is neither needed nor requested; all assessment materials are provided in a controlled training scenario.

It suits professionals with responsibility for PCI compliance, information security, internal audit, infrastructure, payment operations, product delivery, or supplier assurance. It is also appropriate for managers who need to challenge scope, evidence quality, and remediation plans before external validation.

This course uses the PCI DSS assessment method and focuses specifically on payment-account data, validation routes, PCI evidence, SAQs, AOCs, QSAs, and service-provider responsibilities. General security frameworks are referenced only where they support a PCI DSS requirement or operating control.

The scope map, evidence matrix, gap register, accountability matrix, and remediation roadmap can be adapted directly to an internal readiness review or annual PCI programme. Participants also learn how to frame evidence requests and remediation discussions with system owners and external providers.

You leave with a completed PCI DSS assessment pack based on the course case study, including a cardholder-data scope map, requirement-to-evidence matrix, gap register, supplier responsibility matrix, and 90-day remediation plan. A certificate of completion is issued after the course.

Upcoming sessions

  • 21 – 25 Sep 2026
    Live Online · USD 1,500
    Book
  • 05 – 09 Oct 2026
    Live Online · USD 1,500
    Book
  • 12 – 16 Oct 2026
    Live Online · USD 1,500
    Book
  • 19 – 23 Oct 2026
    Kigali · USD 3,500
    Book
  • 19 – 23 Oct 2026
    Mombasa · USD 3,200
    Book
  • 19 – 23 Oct 2026
    Live Online · USD 1,500
    Book
  • 19 – 23 Oct 2026
    Dubai · USD 4,500
    Book
  • 09 – 13 Nov 2026
    Dar es Salaam · USD 3,500
    Book

49 more dates — ask us.


Group of 5+?

Request in-house delivery or group rates →

Related courses in Financial Technology

5 Days Certificate

Mobile Money Operations for Microfinance Institutions Training Course

Microfinance institutions increasingly use mobile money to collect loan instalments, disburse loans, pay agents, receive savings deposits an…

5 Days Certificate

Digital Lending Analytics for Credit Risk Managers Training Course

Digital lenders make credit decisions from application data, transaction histories, device signals, bureau files and behavioural events—ofte…

5 Days Certificate

Financial Technology Applications in Insurance Training Course

Insurance firms are under pressure to shorten quote-to-bind cycles, reduce claims leakage, strengthen fraud controls, and serve policyholder…

5 Days Certificate

Advanced Financial Technology Architecture and Payments Training Course

Payment platforms are expected to deliver real-time availability, resilient transaction processing, accurate reconciliation and controlled a…