PCI DSS Payment Security Compliance Training Course
| Course code | SD-FT-008 |
|---|---|
| Duration | 5 days |
| Level | Intermediate to Advanced |
| Category | Financial Technology |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Payment environments rarely fail compliance because teams have never read a PCI DSS requirement. They fail because cardholder-data flows are incompletely mapped, scope boundaries are assumed rather than evidenced, supplier responsibilities are unclear, and controls cannot be demonstrated to a QSA, acquirer, or internal audit team. This five-day PCI DSS Payment Security Compliance Training Course equips finance, technology, risk, and security professionals to translate PCI DSS v4.0.1 into a defensible operating model for payment acceptance, processing, storage, and outsourced services.
Participants work through the PCI DSS assessment method from scoping through evidence review, gap analysis, remediation planning, and validation. They learn to identify account data and system components in scope; determine appropriate SAQ, ROC, and Attestation of Compliance routes; test controls against PCI DSS requirements; assess compensating controls and customized approaches; manage third-party service-provider dependencies; and prepare evidence for annual validation. The course addresses core technical and operational areas including network segmentation, access control, vulnerability management, logging, secure software practices, incident response, and continuous compliance.
Instructor-led briefings are paired with payment-environment case studies, evidence-review labs, scoping workshops, and group assessment exercises. Participants analyse a realistic merchant and service-provider scenario, make scope decisions, evaluate sample artefacts, record findings, and defend remediation priorities. They leave with a practical PCI DSS assessment pack: a cardholder-data environment scope map, responsibility matrix, requirement-to-evidence matrix, gap register, and risk-ranked remediation roadmap that can be adapted for their organisation.
The course is designed for experienced professionals who contribute to payment security, PCI compliance, internal audit, IT operations, product delivery, vendor governance, or financial-control functions. It is particularly valuable where payment systems, cloud services, e-commerce platforms, and external processors create complex ownership and evidence challenges.
Course objectives
By the end of this course, participants will be able to:
- Map cardholder-data flows and define the PCI DSS cardholder-data environment scope
- Select the appropriate PCI SSC validation route using SAQ, ROC, and AOC criteria
- Assess PCI DSS v4.0.1 requirements against policies, configurations, logs, and control evidence
- Build a requirement-to-evidence matrix for an internal PCI DSS readiness assessment
- Evaluate network segmentation evidence and document its impact on PCI DSS scope
- Produce a PCI DSS gap register with risk ratings, control owners, and remediation dates
- Assess third-party service-provider responsibilities using a PCI accountability matrix
- Create a risk-ranked remediation roadmap and annual PCI DSS compliance calendar
Benefits of attending
For you
- Gain the ability to lead or contribute credibly to PCI DSS scoping and readiness assessments
- Build evidence-based audit skills for reviewing payment-security controls rather than relying on policy statements
- Strengthen credibility with QSAs, acquirers, internal audit teams, and payment-service providers
- Develop a reusable approach for translating PCI DSS findings into owned remediation actions
- Prepare for expanded responsibilities in payment security, GRC, technology risk, or PCI compliance management
For your organisation
- Reduce the risk of omitted systems and uncontrolled suppliers remaining within the cardholder-data environment
- Improve the quality and traceability of evidence presented during SAQ, ROC, and internal audit activities
- Create clearer accountability between merchants, service providers, security teams, and operational control owners
- Prioritise PCI DSS remediation by risk, requirement dependency, and validation deadlines
- Embed PCI DSS considerations into payment changes, cloud adoption, vendor onboarding, and business-as-usual control testing
Target competencies
Who should attend
- PCI Compliance Managers — who coordinate assessment evidence, remediation activity, and annual validation
- Information Security Managers — who must operate and evidence technical controls across payment environments
- Internal Auditors — who test payment-security controls and report assurance findings
- IT Infrastructure and Network Managers — who own segmentation, access, logging, and vulnerability-management controls
- Payment Operations and FinTech Product Managers — who need to design payment changes without expanding unmanaged PCI scope
- Third-Party Risk and Vendor Managers — who must establish and monitor service-provider PCI responsibilities
Requirements and prerequisites
Participants should have working experience in information security, IT operations, internal audit, payment operations, risk, or compliance. They should understand basic network concepts such as firewalls, VLANs, segmentation, authentication, privileged access, encryption, vulnerability scanning, and log review. Familiarity with payment terms including PAN, cardholder data environment, merchant, acquirer, processor, and service provider is helpful. Participants should be able to read a policy, system diagram, audit finding, or spreadsheet-based control register. Prior QSA experience, coding ability, penetration-testing expertise, or previous PCI DSS certification is not required.
Training methodology
The programme combines instructor-led PCI DSS interpretation with structured assessment practice. Participants work in small teams on a realistic payment environment containing e-commerce components, cloud-hosted services, network segments, payment gateways, and outsourced providers. Exercises use sample diagrams, policies, scan outputs, access reviews, incident records, and supplier attestations to distinguish acceptable evidence from unsupported claims. Daily workshops build one linked assessment pack, culminating in a group presentation of scope decisions, key gaps, remediation priorities, and an implementation plan for the participant’s own environment.
Course outline
Day 1: PCI DSS foundations, payment flows, and scope
- PCI DSS v4.0.1 structure, intent, and assessment lifecycle
- Roles of merchants, acquirers, processors, QSAs, and service providers
- Account data definitions: PAN, SAD, cardholder data, and authentication data
- Cardholder-data environment identification and system-component inventory
- Payment-channel mapping for e-commerce, MOTO, retail, and mobile acceptance
- Scope reduction through tokenisation, outsourcing, and validated segmentation
- SAQ, ROC, and Attestation of Compliance selection criteria
Workshop: Participants create a cardholder-data flow diagram and initial PCI DSS scope statement for a multi-channel merchant scenario.
Day 2: Testing technical PCI DSS controls
- Network security controls and firewall rule-set evidence
- Secure configurations, hardening standards, and configuration-change records
- Protection of stored account data through masking, truncation, and cryptography
- Key-management lifecycle evidence for encryption keys and custodians
- Identity and access management, least privilege, and privileged-account reviews
- Multi-factor authentication coverage and authentication-event evidence
- Malware protection, vulnerability scanning, patching, and penetration-testing evidence
Workshop: Participants review a technical evidence pack, test selected requirements, and record supported findings in an evidence matrix.
Day 3: Operational controls, secure delivery, and monitoring
- Secure software development requirements and software-change governance
- Web application protection, payment-page scripts, and e-commerce integrity controls
- Logging, time synchronisation, retention, and security-event review procedures
- Security operations monitoring and alert escalation workflows
- Incident response planning, payment-brand notification, and forensic readiness
- Security awareness training and role-specific PCI DSS responsibilities
- Information-security policy governance and annual control review
Workshop: Participants assess a payment-page change and incident scenario, producing findings, evidence requests, and corrective actions.
Day 4: Assessment evidence, third parties, and remediation
- PCI DSS testing procedures and sampling rationale
- Designing requirement-to-evidence matrices and evidence-request lists
- Distinguishing control design, operating effectiveness, and unsupported assertions
- Third-party service-provider due diligence and responsibility allocation
- Reviewing AOCs, service descriptions, shared-responsibility models, and contractual commitments
- Compensating controls and customized approaches under PCI DSS v4.0.1
- Gap-register construction, risk scoring, ownership, and remediation dependencies
Workshop: Participants build a supplier responsibility matrix and risk-ranked gap register from a service-provider evidence case.
Day 5: Validation readiness and compliance operating model
- Preparing for QSA interviews, evidence walkthroughs, and validation milestones
- ROC and SAQ completion quality checks
- Attestation of Compliance review and executive sign-off considerations
- PCI DSS transition timelines and future-dated requirement planning
- Continuous compliance control testing and annual compliance calendars
- PCI metrics for remediation governance and management reporting
- Integrating PCI DSS into change management, cloud onboarding, and vendor lifecycle processes
Workshop: Participants present a final PCI DSS assessment pack containing scope, evidence priorities, gaps, remediation roadmap, and 90-day action plan.
Tools & standards covered
PCI DSS v4.0.1, PCI SSC Self-Assessment Questionnaire (SAQ), PCI SSC Attestation of Compliance (AOC), NIST SP 800-115
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
-
21 – 25 Sep 2026Book
Live Online · USD 1,500 -
05 – 09 Oct 2026Book
Live Online · USD 1,500 -
12 – 16 Oct 2026Book
Live Online · USD 1,500 -
19 – 23 Oct 2026Book
Kigali · USD 3,500 -
19 – 23 Oct 2026Book
Mombasa · USD 3,200 -
19 – 23 Oct 2026Book
Live Online · USD 1,500 -
19 – 23 Oct 2026Book
Dubai · USD 4,500 -
09 – 13 Nov 2026Book
Dar es Salaam · USD 3,500
49 more dates — ask us.
Group of 5+?
Request in-house delivery or group rates →Related courses in Financial Technology
Mobile Money Operations for Microfinance Institutions Training Course
Microfinance institutions increasingly use mobile money to collect loan instalments, disburse loans, pay agents, receive savings deposits an…
Digital Lending Analytics for Credit Risk Managers Training Course
Digital lenders make credit decisions from application data, transaction histories, device signals, bureau files and behavioural events—ofte…
Financial Technology Applications in Insurance Training Course
Insurance firms are under pressure to shorten quote-to-bind cycles, reduce claims leakage, strengthen fraud controls, and serve policyholder…
Advanced Financial Technology Architecture and Payments Training Course
Payment platforms are expected to deliver real-time availability, resilient transaction processing, accurate reconciliation and controlled a…