Stripe
A Level 1 service provider RoC across four card brands.
We supported the annual Report on Compliance for a global payments platform operating across four regions, coordinating with internal QSA teams and external attestation vendors.
- Sector
- Payments infrastructure
- Framework
- PCI DSS 4.0 · Report on Compliance
- Year
- 2024
- Signed by
- Partner
§ 01 — Scope
What we tested.
- 01Card data environment segmentation review
- 02Cryptographic key lifecycle testing
- 03Change management sampling across 14 in-scope services
- 04Vendor governance and fourth-party inventory
§ 02 — Findings
01
Two documentation gaps in the annual segmentation validation, closed before issuance.
02
Recommendation to consolidate three overlapping HSM key ceremonies.
§ 03 — Outcome
RoC issued on schedule with zero compensating controls. Follow-on advisory scoped for the following observation window.
§ 04 — Next