Scoping is where cost is won or lost
PCI DSS applies to systems that store, process or transmit cardholder data, and to connected systems that can affect the security of the cardholder data environment (CDE). In Kenya, many organisations over-scope by treating the entire corporate network as in-scope, or under-scope by ignoring connected systems and third parties.
A clear network and data-flow diagram, segmentation where justified, and a documented applicability decision are the foundation of a manageable programme. Scope mistakes show up later as assessment delays or findings.
What drives PCI DSS cost in Kenya
Cost is driven by scope size, number of locations, whether you are a merchant or service provider, the assessment type (SAQ vs QSA assessment), and how much remediation is required before assessment. Tooling, penetration testing and compensating controls also add to the total.
Combining PCI DSS with an existing or planned ISO 27001 programme reduces duplication: risk assessment, access control, logging, vendor management and security awareness can serve both if designed deliberately.
A practical path for Kenyan organisations
Map card data flows and define the CDE. Close obvious gaps (default passwords, missing MFA on admin access, unencrypted transmission). Align policies and evidence with the current PCI DSS version. Engage a QSA or complete the correct SAQ path for your channel type.
Do not treat the ROC or SAQ as a one-off project. Maintaining evidence and change control between assessments is what keeps certification sustainable.
How AACL supports PCI DSS in Kenya
We help organisations scope the CDE, run gap assessments, remediate controls, and prepare for QSA assessment or SAQ completion. Programmes can stand alone or integrate with ISO 27001 and broader security retainers. Onsite in Nairobi and Kenya, or remote worldwide.
To discuss this subject with our practitioners, write to info@aacl.co.ke.
