{"id":66561,"date":"2026-06-03T08:51:31","date_gmt":"2026-06-03T06:51:31","guid":{"rendered":"https:\/\/www.usd.de\/?p=66561"},"modified":"2026-06-03T08:51:33","modified_gmt":"2026-06-03T06:51:33","slug":"s-public-services-pci-dss-compliance-extended-scope","status":"publish","type":"post","link":"https:\/\/www.usd.de\/en\/s-public-services-pci-dss-compliance-extended-scope\/","title":{"rendered":"PCI DSS v4.0.1 with an Expanded Scope: S-Public Services GmbH Works with usd AG on Structured Audit Management"},"content":{"rendered":"\n<p>Digital payment processes in the public administration environment&nbsp;require a particularly&nbsp;high level&nbsp;of security and traceability. Sensitive payment data must be protected, and regulatory requirements must be reliably integrated into existing process and system landscapes.&nbsp;<\/p>\n\n\n\n<p>S-Public Services GmbH also&nbsp;operates&nbsp;in this regulatory environment. As the&nbsp;Sparkassen-Finanzgruppe\u2019s&nbsp;center of competence for e-government, it serves demanding clients such as federal authorities and municipal administrations. Secure payment processes that meet the highest regulatory standards are therefore&nbsp;business-critical.&nbsp;<\/p>\n\n\n\n<p>As regulatory complexity increases, especially due to new requirements for service providers, the&nbsp;demands&nbsp;on&nbsp;the audit process also&nbsp;rise. For its annual <a href=\"https:\/\/www.usd.de\/en\/pci-payment-security\/pci-audit\/\">PCI DSS audit<\/a> with expanded requirements, S-Public Services GmbH was looking for a partner that would not only assess regulatory requirements but also classify them methodically, prioritize them, and translate them into sustainable audit processes. Since 2024, usd AG has been supporting S-Public Services GmbH throughout its PCI DSS certification process. The focus is not on meeting individual requirements in isolation, but on ensuring a manageable, transparent implementation in&nbsp;day-to-day operations.<\/p>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Expanded PCI DSS Scope Due to New Requirements<\/h2>\n\n\n\n<p>As the PCI DSS requirements for service providers changed, the scope for S-Public Services GmbH expanded significantly compared with the previous year. This required a clear delineation of new requirements, a systematic classification within the existing certification scope, and realistic prioritization. Together with usd AG, the assessment scope was analyzed systematically, segmented in a practical way, and translated into a robust roadmap.<\/p>\n\n\n\n<p>The goal was not to consider the expanded set of requirements in isolation, but to embed it consistently into existing processes, systems, and responsibilities.<\/p>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Structured Preparation and Close Collaboration<\/h2>\n\n\n\n<p>To address the expanded assessment scope with confidence, S-Public Services and usd relied on structured preparation with clearly defined roles, responsibilities, and coordination formats. In joint workshops, the new service provider requirements were classified, existing processes were reviewed, and concrete implementation steps were prioritized. A particular focus was placed on integrating new processes and systems cleanly into the existing landscape without disrupting ongoing operations. usd AG\u2019s ability to connect regulatory requirements with operational reality proved to be a decisive success factor.<\/p>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\">\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>What mattered most was not one individual measure, but the joint approach. The close coordination, clearly defined responsibilities, and structured preparation enabled us to classify new requirements in a controlled way and implement them step by step.<\/p>\n\n\n\n<div style=\"height:8px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p><em>Per Philipp Schneider, Senior Consultant and QSA, usd AG<\/em><\/p>\n<\/blockquote>\n\n\n\n<div style=\"height:1px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:33.33%\">\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"1024\" src=\"https:\/\/www.usd.de\/wp-content\/uploads\/Per-Philipp-Schneider_rund-1-1024x1024.png\" alt=\"\" class=\"wp-image-66556\" style=\"width:160px\" \/><\/figure>\n<\/div>\n<\/div>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">The Result: Successful PCI DSS Certification with an Expanded Scope<\/h2>\n\n\n\n<p>Despite the significantly expanded assessment scope, certification under PCI DSS v4.0.1 was completed successfully. At the same time, a clearly traceable, audit-ready security architecture was established that can also accommodate future regulatory expansions in a transparent way.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>The collaboration was constructive and goal\u2011oriented from the very beginning. Strong technical expertise, short decision-making paths, and a consistently collaborative approach shaped the entire audit process.<\/p>\n\n\n\n<p>What deserves special mention is that the audit was not perceived as a purely formal review, but as a constructive dialogue among peers. The auditors\u2019 ability to translate the complexity of the 12 PCI DSS requirements into clear, actionable measures provides us with significant added value.<\/p>\n\n\n\n<p>This strengthens the security architecture in a sustainable way and directly benefits S-Public Services\u2019 clients, who expect the highest level of sensitivity when it comes to payment security.<\/p>\n\n\n\n<div style=\"height:8px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p><em>Eva-Christiane Lerche, Senior Produktmanagerin E-Payment, S-Public Services GmbH<\/em><\/p>\n<\/blockquote>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p><strong><u>About S-Public Services GmbH<\/u><\/strong><\/p>\n\n\n\n<p>S-Public Services GmbH is the&nbsp;Sparkassen-Finanzgruppe\u2019s&nbsp;competence center for e-government and a point of contact for the public sector as well as municipal organizations and companies. With specialized plug-and-play solutions for payment services and digital administrative processes, S-Public Services supports the digital transformation of a wide range of citizen services. It offers&nbsp;numerous&nbsp;options for digital payments, efficient booking processes, and application services\u2014from simple solutions to complete application workflows with interfaces to specialized administrative systems. In addition, it supports public administrations with modern e-government and citizen services, including online appointment scheduling, visitor flow management, and digital application procedures, as well as a comprehensive catalog of more than 500 form applications. Its clients include cities, municipalities, and data centers. S-Public Services is part of the DSV Group,&nbsp;the&nbsp;Sparkassen-Finanzgruppe\u2019s&nbsp;central service provider.&nbsp;Learn&nbsp;more&nbsp;at&nbsp;<a href=\"https:\/\/www.s-publicservices.de\/\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/www.s-publicservices.de\/<\/a>&nbsp;<\/p>\n\n\n\n<p><a id=\"_msocom_1\"><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Digital payment processes in the public administration environment&nbsp;require a particularly&nbsp;high level&nbsp;of security and traceability. Sensitive payment data must be protected, and regulatory requirements must be reliably integrated into existing process and system landscapes.&nbsp; S-Public Services GmbH also&nbsp;operates&nbsp;in this regulatory environment. As the&nbsp;Sparkassen-Finanzgruppe\u2019s&nbsp;center of competence for e-government, it serves demanding clients such as federal authorities and [&hellip;]<\/p>\n","protected":false},"author":112,"featured_media":66554,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"off","_et_pb_old_content":"","_et_gb_content_width":"","inline_featured_image":false,"footnotes":""},"categories":[462,373,394],"tags":[434,6471,496,440,15135,9410],"class_list":["post-66561","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-customer-stories-en","category-news-en","category-pci-en","tag-pci-en","tag-pci-audit-en","tag-pci-compliance-en","tag-pci-dss-en","tag-pci-dss-in-public-sector","tag-pci-dss-v4-0-1-en"],"_links":{"self":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/posts\/66561","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/users\/112"}],"replies":[{"embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/comments?post=66561"}],"version-history":[{"count":5,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/posts\/66561\/revisions"}],"predecessor-version":[{"id":66591,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/posts\/66561\/revisions\/66591"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/media\/66554"}],"wp:attachment":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/media?parent=66561"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/categories?post=66561"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/tags?post=66561"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}