Compliance

PCI DSS on AWS, built to pass the audit

We design and build cardholder-data environments on AWS that meet PCI DSS requirements, from segmentation and encryption to logging and evidence, and prepare you for your Qualified Security Assessor. The same approach covers SOC 2, ISO 27001 and HIPAA readiness.

What's included

Controls built in, evidence ready

Scoping & segmentation

The cardholder data environment kept as small as possible and isolated by account and network boundaries, which shrinks the audit scope.

Encryption & keys

KMS-managed keys, encryption at rest and in transit, and key policies that separate who can use data from who can manage it.

Logging & monitoring

Organization-wide CloudTrail, centralized tamper-resistant logs with PCI-grade retention, GuardDuty and alerting.

Continuous control checks

AWS Security Hub's PCI DSS standard and AWS Config conformance packs flag drift as it happens, not at audit time.

Evidence & audit support

Policies, diagrams and a shared-responsibility matrix prepared, AWS Artifact reports collected, and your QSA's questions answered.

SOC 2, ISO 27001, HIPAA

The same control set mapped to other frameworks, so one environment serves several audits.

Funding

How compliance work gets funded

Compliance work is scoped and priced up front. Two things can lower the cost.

AWS programs

  • Migration Acceleration Program (MAP)

    When the compliant environment is built as the target of a migration, it falls under the migration's funding.

Averium

Where the work lowers your AWS bill, part of Averium's fee is recovered from those savings instead of being invoiced upfront. The split is fixed in the statement of work before anything starts.

Only an AWS Partner can request AWS funding. We prepare and submit the application; AWS makes the final award. How AWS funding works

How it works

From first call to done

  1. 1

    Gap assessment

    Current environment checked against PCI DSS v4.0.1 requirements.

  2. 2

    Design

    Scope, segmentation and control design agreed with you and your QSA.

  3. 3

    Build

    Controls implemented as code, with continuous checks enabled.

  4. 4

    Audit readiness

    Evidence pack prepared and audit questions supported.

Why Averium

AWS Partner. Certified engineers. Paid from results.

The team that builds it also runs the FinOps platform that keeps it cost-efficient afterwards.

  • Built to PCI DSS v4.0.1, the current version of the standard
  • Controls as code, so the environment stays compliant after the audit
  • Security Hub and Config checks catch drift between audits
  • Engineers certified as AWS Solutions Architect and DevOps Engineer Professional

Averium is not a Qualified Security Assessor and does not issue PCI DSS certification. AWS is validated as a PCI DSS Level 1 Service Provider for its in-scope services; your compliance depends on how you build on top of them. That part is what we do.

FAQ

Common questions

Can you make us PCI DSS Level 1?+

Your merchant or service provider level is set by your annual transaction volume, and Level 1 requires an assessment by a QSA. We build the environment and prepare the evidence so that assessment goes smoothly; the assessor issues the Report on Compliance.

Isn't AWS already PCI DSS compliant?+

AWS is a validated PCI DSS Level 1 Service Provider for the infrastructure and services in scope. That covers AWS's side of the shared-responsibility model. Network design, access control, logging, encryption and your applications are your side, and that's where most audit findings come from.

Which version of PCI DSS do you build to?+

PCI DSS v4.0.1, including the requirements that became mandatory in March 2025.

Do you also help with SOC 2 or ISO 27001?+

Yes. Most AWS controls overlap across frameworks, so we map one control set to SOC 2, ISO 27001 or HIPAA and prepare the technical evidence for each.

Start with a free estimate.