See More RFPs

Payment Card Industry Data Security Standard Compliance Services

Overview


Cybersecurity & Data Privacy
New York, United StatesPosted: July 31st, 2026Deadline: August 26th, 2026

Settle Signals


Market intelligence for public sector sales teams

RFP Hunter shows what is open. Settle shows what is forming.

Settle pieces together buyer signals, budgets, contract activity, and the sources your team already monitors. See why an opportunity fits and what to do before the RFP posts.

Learn more about Settle

SUMMARY


A New York government authority seeks a PCI DSS compliance services provider for a three-year engagement. The work includes gap assessments, remediation guidance, merchant and payment gateway support, policy updates, training, vulnerability research, and ongoing advisory services.

DESCRIPTION


The government authority, located in New York, seeks a qualified vendor to provide Payment Card Industry Data Security Standard (PCI DSS) compliance services for a three-year contract period. The selected provider will assist the University in achieving and maintaining compliance with current PCI DSS requirements through policy and procedure updates, training, ongoing advisory support, and subject matter expertise.

Services will include conducting a PCI DSS gap analysis, assessing cardholder data environments, identifying vulnerabilities and compliance gaps, and providing remediation guidance. The vendor will also assist with establishing, maintaining, and managing merchant accounts, merchant IDs, and payment gateways; provide phone, email, and online support to merchants during normal business hours; and maintain electronic records of compliance activities, findings, and deliverables.

The provider may also be required to configure and maintain secure payment gateways integrated with processors, recommend secure solutions for card-present, online, and mobile payments, and prepare solution comparison reports addressing scope reduction, compliance benefits, operational fit, and cost considerations. The vendor will update policies, procedures, and training materials and create reusable templates to support future certification efforts. Questions must be submitted by August 10, 2026.

Similar RFPs


Frequently asked questions


When is the submission deadline?
Submissions are due August 26, 2026.
Who is a good fit for this opportunity?
  • PCI DSS-qualified cybersecurity and compliance consulting firm
  • Demonstrated experience assessing and remediating cardholder data environments
  • Expertise with merchant accounts, payment processors, and secure payment gateways
  • Capability to support card-present, online, and mobile payment environments
  • Experienced in policy development, training, documentation, and ongoing advisory support
  • Strong business-hours help desk and merchant support capabilities

Analysis generated by Settle AI from the source RFP.

RFP Hunter shows what is open. Settle shows what is forming.

Settle pieces together buyer signals, budgets, contract activity, and the sources your team already monitors. See why an opportunity fits and what to do before the RFP posts.

See how Settle works