What You Need to Know About a PCI DSS Readiness Assessment
Payment Card Assessments | Audit Readiness | PCI DSS
Published: May 25, 2022
Last Updated: Jan 8, 2026
Many organizations preparing for PCI DSS compliance wonder whether they should get a readiness assessment or just skip directly to full validation. Matt Crane, Director of Schellman’s PCI Practice, explains what a PCI DSS readiness assessment is and the value it brings.
What Is a PCI DSS Readiness Assessment?
A PCI DSS readiness assessment is an evaluation of your organization’s current systems, configurations, and controls relative to the applicable PCI DSS requirements. It is designed to:
- Assess your current environment against the standard
- Identify gaps or areas your team needs to address
- Confirm what controls are already in place
Who Benefits from a Readiness Assessment?
Readiness assessments are especially useful for:
- New clients who have never undergone PCI DSS validation
- Organizations transitioning from an older version of the standard (e.g., PCI DSS 3.2.1 to 4.0)
By completing a readiness assessment, your organization gains insight into how prepared you are for full validation, which reduces surprises and improves efficiency during the official assessment.
How a Readiness Assessment Works
- Scope Review
- Assess which PCI DSS requirements are applicable to your organization
- Identify potential shortcuts or reduced validation methods (e.g., using a Self-Assessment Questionnaire for certain merchants)
- Environment and Controls Evaluation
- Examine system configurations, security controls, and processes that are already in place
- Compare current practices to the applicable PCI DSS requirements
- Gap Identification and Reporting
- Highlight areas where your environment does not yet meet the standard
- Provide an informational overview of how requirements are typically addressed, without offering advisory or consulting recommendations
This process allows organizations to understand their strengths and weaknesses and prepare internally to address gaps before the formal validation process begins.
Moving Forward with Your PCI DSS Journey
A readiness assessment evaluates and verifies your current controls, but addressing any gaps remains the responsibility of your team. A well-timed readiness assessment helps ensure a smoother, more informed path toward full PCI DSS compliance.
By clarifying where your organization stands, readiness assessments allow teams to plan more effectively and enter the full PCI DSS validation process with confidence. Organizations interested in a PCI DSS readiness assessment can reach out to discuss objectives and determine their best approach.
About Matt Crane
Matt Crane is a Director at Schellman, where he excels in project management and client relations while overseeing assessments against various PCI Standards. With a primary focus on PCI DSS Compliance for organizations spanning diverse industries, Matt leverages a decade of expertise in information security services. Prior to joining Schellman in July 2017, Matt held key positions in both the private and public sectors, specializing in PCI and NIST assessments, as well as intelligence analysis. His extensive background includes leading PCI engagements, performing risk assessments, and general consulting services for merchants and service providers across multiple industry verticals. With an exceptional track record and a profound understanding of the industry, Matt Crane is a valuable asset to Schellman, ensuring clients receive unparalleled guidance in achieving their compliance goals. Matt holds a BBA in Information Security and Assurance as well as several industry certifications including CISSP, CISA, CRISC, QSA,