PCI DSS Certification in 90 Days for a Mumbai Payment Aggregator

Case Study | Fintech & Payments | Mumbai

PCI DSS Certification in 90 Days for a Mumbai Payment Aggregator

How MDIT Services helped a licensed payment aggregator achieve PCI DSS v4.0 certification within a regulator-imposed 90-day deadline — enabling RBI licence renewal and preventing business disruption.

  • 87 days to full PCI DSS v4.0 certification
  • 0 critical findings carried forward to final Report on Compliance
  • 100% compliance achieved across all 12 PCI DSS requirements
  • RBI licence renewed on schedule

The Client and the Challenge

The client is a Mumbai-based licensed payment aggregator processing in excess of ₹500 crore in annual transaction volume for merchants across e-commerce, hospitality, and education sectors. As a payment aggregator operating under RBI’s Payment Aggregator Guidelines, the company is required to maintain a valid PCI DSS certification as a condition of its licence.

During a routine RBI inspection, the company’s existing PCI DSS certification was flagged as lapsing. The RBI issued a formal directive: achieve PCI DSS v4.0 certification within 90 days or face suspension of the payment aggregator licence — a suspension that would have immediately halted all transaction processing for hundreds of merchant clients and caused severe financial and reputational damage.

The situation was further complicated by the fact that the company’s previous compliance vendor had failed to deliver certification and had withdrawn from the engagement, leaving the company without a compliance partner and with an incomplete gap assessment. With the clock running, the company engaged MDIT Services on an emergency basis.

Problem Areas Identified

MDIT’s emergency gap assessment, conducted in Week 1, identified four critical areas of non-compliance that had caused the previous certification attempt to fail:

  1. Cardholder Data Environment (CDE) not segmented: The network had not been properly segmented to isolate systems that store, process, or transmit cardholder data (CHD) from those that do not. This meant the entire network was technically in scope for PCI DSS — making compliance dramatically more complex and expensive.
  2. Weak cryptography (TLS 1.0 still active): Legacy TLS 1.0 and TLS 1.1 protocols were still enabled on several servers in the CDE. PCI DSS v4.0 requires that organisations use only strong cryptography (TLS 1.2 or higher) for transmission of cardholder data. The continued presence of deprecated protocols was a direct violation of PCI DSS Requirement 4.
  3. Missing ASV scan: PCI DSS Requirement 11.3 mandates quarterly external vulnerability scanning by an Approved Scanning Vendor (ASV). The company had not completed any ASV scans in the preceding 12 months, meaning there was no scanning history to present to the QSA.
  4. Inadequate penetration test: PCI DSS Requirement 11.4 requires an annual penetration test conducted by a qualified internal or external tester. The company’s previous penetration test was neither scoped correctly (it did not cover segmentation verification as required by PCI DSS v4.0) nor conducted by a suitably qualified tester.

MDIT’s Approach — Emergency PCI DSS Certification Programme

Given the 90-day constraint, MDIT designed and executed an accelerated PCI DSS certification programme with parallel workstreams running simultaneously across all four problem areas.

Week 1: Emergency Gap Assessment and CDE Scoping

MDIT’s PCI DSS specialists conducted a rapid but comprehensive gap assessment across all 12 PCI DSS v4.0 requirements. In parallel, the team worked with the client’s network and infrastructure team to define a defensible and minimal CDE scope using network segmentation — isolating card data systems behind dedicated network controls and firewall rules. A correctly scoped CDE reduced the number of systems in scope from over 200 to 31, dramatically simplifying the compliance effort.

Weeks 2–4: Technical Remediation

MDIT provided detailed technical remediation guidance and hands-on support for the two most time-critical issues:

  • TLS Upgrade: Identified all servers, load balancers, and APIs with TLS 1.0/1.1 enabled. Coordinated the upgrade to TLS 1.2/1.3 across all CDE components, including testing to confirm no business functionality was broken. All legacy TLS disabled and verified within 14 days.
  • Firewall and segmentation hardening: Implemented network segmentation controls, updated firewall rulesets, deployed intrusion detection on CDE segment boundaries, and verified segmentation using penetration testing techniques.

Weeks 3–6: ASV Scanning and Penetration Testing

MDIT coordinated ASV-approved external vulnerability scanning using a PCI SSC Approved Scanning Vendor partner. Two quarterly ASV scans were compressed into a remediate-and-rescan cycle to produce a clean scan report within the certification timeline.

MDIT conducted the PCI DSS-compliant penetration test in parallel — covering external network, internal network, CDE segmentation verification (as required by PCI DSS v4.0 Requirement 11.4.5), and application-layer testing of the payment portal. All findings were remediated and a clean re-test report produced.

Weeks 5–10: Policy and Documentation, QSA Coordination

A complete PCI DSS policy suite — covering all required policies, procedures, standards, and evidence artefacts — was developed and implemented. MDIT coordinated closely with the appointed Qualified Security Assessor (QSA) throughout, addressing assessor queries in real time to avoid delays in the assessment process.

Week 11–13: QSA Assessment and Report on Compliance

The formal QSA assessment was conducted in Week 11. Due to the thoroughness of MDIT’s preparation, the assessment completed without any significant findings that required reassessment. The Report on Compliance (ROC) was issued at the end of Week 13 — Day 87 of the engagement.

Results

The payment aggregator achieved PCI DSS v4.0 certification on Day 87 — three days ahead of the RBI deadline. The RBI licence renewal was completed on schedule, and transaction processing for all merchant clients continued without interruption.

The Report on Compliance contained zero critical findings carried forward — all identified non-conformities were remediated and verified during the assessment process. The QSA confirmed full compliance across all 12 PCI DSS requirements.

Following certification, the company engaged MDIT on an ongoing basis to manage their annual PCI DSS compliance cycle, including quarterly ASV scanning, continuous monitoring of the CDE, and preparation for annual re-certification.

“We were in a genuinely critical situation — our previous vendor had failed us and the RBI deadline was immovable. MDIT’s team took over immediately, worked in parallel across every problem area, and delivered certification three days early. I don’t think any other team could have moved that fast without cutting corners — and MDIT cut none.”

— Chief Technology Officer, Mumbai Payment Aggregator (name withheld for confidentiality)

Need Urgent PCI DSS Certification?

Whether you are facing a regulator deadline, a failed certification attempt, or starting your PCI DSS journey for the first time, MDIT’s PCI DSS team delivers results on schedule.

Contact MDIT for PCI DSS Certification  | 
Call: +91 8130 479 555

MDIT Services — CERT-In Empanelled Cybersecurity Company | New Delhi, India

View all case studies

Related MDIT Services

Discuss a Similar PCI DSS Engagement →

Free Consult