Building an In-House PCI-DSS Environment for a Madrid-Based FinTech Company
Client Profile
A Madrid-based FinTech company providing payment processing services to online retailers across Spain and Portugal, operating under strict PCI-DSS compliance requirements.
Technologies Used
Business Challenge
Solution
Outcome
Process
Compliance Audit and Gap Analysis
Audited the client's existing outsourced PCI-DSS environment, identified cost inefficiencies, and mapped the gap between the current state and a self-managed compliant setup in AWS.
AWS Architecture Design
Designed a PCI-DSS compliant AWS architecture with isolated VPCs, encrypted storage, strict IAM policies, and network segmentation aligned to PCI-DSS requirements.
Infrastructure as Code Deployment
Provisioned the entire environment with Terraform — VPCs, security groups, databases, application services, and monitoring. Every component is version-controlled and reproducible.
Payment API Development
Built pre-configured application APIs for payment processing, replacing the vendor's restrictive SDK with a flexible, client-owned solution that supports custom merchant integrations.
Security and Compliance Configuration
Configured AWS Security Hub for continuous compliance monitoring, implemented automated alerting for policy violations, and established access logging and audit trails for all PCI-scoped systems.
Documentation and Audit Preparation
Guided the client through the PCI Self-Assessment Questionnaire and Attestation of Compliance. Prepared all evidence packages and documentation required by the Qualified Security Assessor.
Audit Execution and Certification
Managed communication with the QSA throughout the audit process, translating technical requirements into clear responses. The client received their Report on Compliance and began operating independently.
Ongoing Maintenance and Annual Renewals
Since 2018, we have maintained the environment, handled ongoing compliance processes, and prepared the client for each annual audit — six consecutive passes with zero critical findings.
Conclusion
Ready to Transform Your Infrastructure?
Book a free consultation with our team to discuss your DevOps and cloud engineering needs.