Compliance frameworks

Framework hub

PCI DSS

PCI SSC · 4.0

Merchants or service providers that process, store, transmit, or impact cardholder data must meet PCI DSS requirements to safeguard cardholder data.

In scope — controls active

HLD Group maintains policies and controls mapped to this framework as part of our security and compliance programme. This hub describes programme alignment — not a third-party certification or attestation unless separately agreed in your contract.

Programme focus areas

  • Network segmentation
  • Cardholder data environment
  • ASV scanning

Policies meeting this framework

The following published policies and programme documents are mapped to PCI DSS. Status: published and under periodic review.

Assurance note

Programme alignment means HLD maintains controls, policies, and monitoring mapped to PCI DSS requirements appropriate to our services and risk profile. It does not by itself constitute certification, authorization, or a SOC/ISO audit report. Customers requiring formal attestations should contact [email protected].