Any Rochester-area business accepting credit card payments — from a dental practice to an auto dealership to a small retailer — has obligations under the Payment Card Industry Data Security Standard (PCI DSS). Hurricane Technologies handles PCI compliance work for clients across the Greater Rochester area.
What PCI compliance involves
PCI compliance is a combination of technical controls, documented policies, and ongoing validation. Our service covers:
- Determining your PCI "level" based on transaction volume (most SMBs are Level 4)
- Completing the appropriate Self-Assessment Questionnaire (SAQ)
- Quarterly external vulnerability scans by an Approved Scanning Vendor (ASV)
- Network segmentation to reduce PCI scope
- Cardholder data flow documentation
- Incident response procedures specific to cardholder data
Industries where PCI matters most
PCI compliance is non-optional for any business processing credit cards. We see the most active PCI work in dental practices, healthcare, and financial services firms.
Related services
PCI compliance is part of our broader IT compliance service and pairs naturally with NIST framework work.