Practical gap assessment, remediation and audit readiness for organisations that store, process or transmit cardholder data. Combined ISO 27001 + PCI DSS programmes available.
Searching for PCI DSS certification in Kenya or combined ISO and PCI DSS support? AACL Global helps organisations scope, implement and prepare for PCI DSS assessments with clear evidence and board-ready reporting. Delivery from Nairobi onsite or remote worldwide.
Scope is everything. We start by mapping cardholder data flows so you neither over-scope (wasted cost) nor under-scope (failed assessment). Remediation is prioritised by risk and assessment timeline.
What we deliver
Frequently asked questions
Who needs PCI DSS in Kenya?
Any organisation that stores, processes or transmits cardholder data — merchants, processors, fintechs, and service providers in the payment chain — typically needs to comply at the appropriate SAQ or ROC level.
Can PCI DSS and ISO 27001 be implemented together?
Yes. Many controls overlap. We design combined programmes so evidence and policies serve both frameworks without double work.
Do you perform the formal QSA assessment?
We provide gap assessment, remediation and readiness. Formal ROC assessment is performed by a PCI SSC-approved QSA; we prepare you so that engagement is efficient.
