Your QSA finds the gaps. We build the AWS infrastructure that closes them.
Segmentation, encryption, logging, access control — engineered on AWS to pass your PCI DSS assessment, not just to look good in a spreadsheet. Fixed price. Senior engineers only. Payment processors have passed annual PCI certification on environments we built and operate.
AWS Managed Service Provider (audited) · Advanced Tier Services Partner · 12+ years building PCI environments · Zero client security breaches
You're here because one of these just happened
- Your first Level 1 merchant or a bank partner asked for your AOC, and you don’t have one.
- Your QSA handed you a gap assessment with forty findings, and your team ships product, not compliance infrastructure.
- Your last assessment squeaked by, and the auditor made it clear next year won’t.
- PCI DSS 4.0’s future-dated requirements are now mandatory, and your controls were built for 3.2.1.
- You’re segmenting cardholder data by hope and a diagram from 2021.
Every one of these is an infrastructure problem. We’ve been solving them on AWS since before PCI DSS 3.0 existed.
The infrastructure side of every requirement your assessor tests
Scope reduction & segmentation
The cheapest PCI control is a smaller CDE. We isolate cardholder data flows into their own VPCs and accounts, cut the number of in-scope systems, and document the boundaries your QSA will actually accept.
Network security & encryption
Security groups without 0.0.0.0/0, WAF, TLS everywhere, KMS-managed encryption at rest, key rotation that happens without a human remembering to do it.
Logging & monitoring (Req. 10)
Centralized, tamper-evident logs with retention your assessor can verify — CloudTrail, GuardDuty, SIEM integration. We run Wazuh in production for a payment processor today.
Access control (Req. 7–8)
Least-privilege IAM, MFA enforcement, no shared credentials, session recording for administrative access. Evidence generated as a by-product, not as a fire drill.
Vulnerability management & hardening
Patched AMIs, container image scanning in CI/CD, configuration baselines enforced by code — drift gets corrected, not discovered during the assessment.
Evidence, on demand
Everything is Terraform. When your QSA asks how a control is enforced, the answer is a file, not a meeting.
Fixed price. Explicit scope. No surprises in month three.
1. Scoping call — 30 minutes
You describe your cardholder data flows and your assessment timeline. You leave with a first read on your scope and the biggest gaps, whether we work together or not.
2. Gap review against your assessment
We map your AWS environment against the requirements your QSA will test — or against the findings they already gave you.
3. Fixed-price remediation
Explicit list of what gets built and fixed, priced after discovery. Miss a milestone — you don't pay for that phase.
4. Assessment support
We sit in the room (or the call) when your assessor asks how controls are enforced, and we answer in their language.
5. Keep it compliant (optional)
PCI is annual. Under our audited MSP practice we operate the environment year-round — monitoring, patching, access reviews — so next year's assessment is a formality, not a project.
Payment infrastructure that passes, year after year
CentroBill — payment processing, USA
Migrated from on-premises to AWS and operated since. Passes annual PCI DSS certification on infrastructure we built and run. Case study →
Payzoff — payment platform, UK
Fault-tolerant PCI DSS environment built from scratch. 150+ payment methods, 200+ countries. Case study →
Zero security breaches across every client environment we have ever operated.
Why us, not a compliance consultancy
We build, they advise
Compliance consultants produce documents. Auditors produce findings. Somebody still has to engineer the segmentation, the logging, the key management. That somebody is us.
We don't audit you — so there's no conflict
We're not a QSA and don't want to be. Your assessor stays independent; we're the remediation team they can point at without violating that independence.
Audited ourselves
AWS independently reviewed our operations, security, and incident management before granting the MSP designation. We know what it's like to sit on your side of an audit.
Senior engineers, founder-led
The people on the call are the people doing the work. No account managers, no juniors on your production CDE.
QSAs: a remediation partner your independence rules allow
You can’t fix what you find. We can. IT-Magic works as the engineering counterpart to assessors: your client gets the gaps closed on AWS by a fixed-price team with a track record of annual recertifications, and you keep your independence intact. If you’d like a standing remediation partner for AWS environments, write to [email protected].
FAQ
Are you a QSA? Can you certify us?
No, and that’s the point. Certification requires an independent Qualified Security Assessor. We build and operate the infrastructure your QSA assesses. Auditor independence rules mean your assessor can’t remediate their own findings — that’s the work we do.
We already have a gap assessment. Can you just fix the findings?
Yes. A findings list from your QSA is the ideal starting point — we price remediation against it directly, fixed price after a scoping review.
How long does remediation take?
Depends on scope, but the biggest lever is usually scope reduction: shrinking the CDE often removes more findings than fixing them one by one. Typical engagements run weeks, not quarters. You’ll get a timeline with the fixed-price quote.
Do you work with PCI DSS 4.0 / 4.0.1?
Yes. The future-dated requirements of v4.0 are now mandatory, and most of them — authenticated scanning, expanded MFA, e-commerce script controls — land on infrastructure. That’s the migration work we do daily.
Can you keep us compliant after the assessment?
Yes — that’s our core business. As an audited AWS MSP we operate PCI environments year-round: monitoring, patching, access reviews, log retention. Clients on this model treat annual recertification as routine.
We're not on AWS yet. Can you migrate us?
Yes. CentroBill came to us on-premises. We migrate into a PCI-ready AWS architecture from day one, so you’re not paying for compliance twice.
Thirty minutes, one engineer, your data flows
Bring your cardholder data flow diagram — or just describe it. You’ll leave the call knowing your real PCI scope, your biggest gaps, and what fixing them costs. The read is yours either way.