Behind the audit

A behind-the-scenes view of a PCI DSS 4.0 audit of Verisec 10XPay Payment Cryptography as a Service, conducted with Foregenix, and what it takes to demonstrate compliance in practice.

Achieving PCI DSS compliance in a cloud-based payment environment is a structured, resource-intensive process that extends far beyond formal requirements. At Verisec, that process involves close collaboration between internal teams and external assessors, with a clear focus on proving that security works in practice, not just on paper.

Inside the audit process

A PCI DSS assessment follows a structured sequence of activities, beginning with scope definition and progressing through gap analysis, evidence collection and remediation.

Initial workshops and remote discussions are used to understand and map the service environment. From there, assessors examine technical, operational, and organisational controls.

A critical aspect of the process is demonstrating that controls are active and effective within daily operations.

The assessment culminates with a final in-person assessment and a detailed report that can result in hundreds of pages of evidence, analysis, and findings.

Evidence and transparency in practice

At the centre of every PCI DSS assessment is verifiable evidence.

Compliance must be demonstrated across multiple domains, technologies, governance structures, and organisational roles.

For Verisec, this involves live demonstrations, documentation reviews, and detailed explanations of how systems operate under normal conditions. This provides clear, verifiable proof that controls exist, operate effectively, and are consistently maintained.

This ensures that compliance is not based on isolated controls, but on a complete and consistent operational model.

The goal is not simply to show that individual controls exist, but to demonstrate a complete and coherent security framework that operates effectively across the entire organisation.

Managing complexity in a cloud payment environment

The 10XPay PCaaS introduces additional complexity due to its distributed architecture and multiple service components. Operating across several locations and sub-services requires the audit to consider a wide range of technical and organisational factors simultaneously.

Verisec’s role is to present this complexity in a structured way that allows for accurate evaluation. This includes translating complex internal architectures and operational processes into a format that aligns with PCI DSS requirements, while preserving the integrity of the underlying design. The ability to bridge this gap is essential for a successful assessment.

Beyond minimum compliance

PCI DSS is one of the most widely recognised security standards in the payment industry. However, it is designed to establish a baseline level of security rather than define the upper limit of what organisations should do.

In practice, Verisec applies stricter internal standards to meet the expectations of financial institutions and payment providers. This means that the audit becomes part of a broader security strategy, rather than a standalone compliance exercise. The objective is not simply to pass an audit, but to maintain long-term resilience, strengthen trust, and continuously improve security posture.

Customer impact

For organisations using 10XPay, the benefits extend beyond the audit itself.

By consuming payment cryptography as a managed service, customers can reduce the complexity of their own compliance activities. Elements such as infrastructure validation, cryptographic controls and key management can be handled within Verisec’s environment rather than by the customer.

This can help reduce audit scope, lower operational overhead, and minimise the internal resources required to support compliance initiatives.

Most importantly, it enables customers to focus on their core business while relying on a validated and externally assessed platform. The result is both efficiency and increased confidence in security controls.

Trust built on verification

The result of the audit is binary – compliance is either achieved or it is not – but the process behind it is extensive and multi-layered.

Multiple layers of internal review, external validation, evidence gathering, and quality assurance are required before an Attestation of Compliance (AoC) can be issued.

This reflects a focus on producing results that are not only compliant, but credible and defensible in real-world scenarios, providing customers, partners, and stakeholders with confidence that security controls have been independently verified and thoroughly assessed.

Looking ahead

The assessment of Verisec 10XPay demonstrates how compliance, when approached systematically, can support both security and operational efficiency.

By maintaining close collaboration with experienced assessors, continuously refining internal processes, and investing in robust security controls, Verisec ensures its services remain aligned with evolving industry expectations.

This approach positions audits not as isolated events, but as an important part of maintaining trust in an increasingly complex digital payments landscape.

This article is based on interviews with Dan Farr (as the audit assessor from Foregenix) and Dimitri Binazzi (Chief Security and Compliance Officer of Verisec) in October 2024. Verisec 10XPay Payment Cryptography as a Service has PCI DSS v4.0.1 Attestation of Compliance since August 2025.

What is PCI DSS 4.0?

PCI DSS (Payment Card Industry Data Security Standard) is the global security standard designed to protect cardholder data and reduce payment fraud. Version 4.0 places greater emphasis on continuous security, customised approaches to compliance, and demonstrating that controls are operating effectively over time rather than only at the point of assessment.

PCI standards are developed and maintained by the PCI Security Standards Council (PCI SSC).

What is Verisec 10XPay?

Verisec 10XPay Payment Cryptography as a Service (PCaaS) provides payment cryptography infrastructure for financial institutions, payment providers and processors.

The platform enables organisations to manage critical cryptographic functions, including key management, transaction security and payment processing controls, without the operational burden of maintaining traditional on-premises payment HSM environments.

About Foregenix

Foregenix is a specialist cybersecurity and compliance consultancy providing PCI assessments, penetration testing, risk management and security advisory services to organisations worldwide.

About Verisec

Verisec provides digital trust and security solutions that help organisations protect identities, secure transactions and meet regulatory requirements. Through solutions such as Verisec 10XPay, the company enables secure, scalable and compliant payment infrastructure for modern financial ecosystems.

Categories

  • All
  • News
  • Press Releases