Onyx Blog

Insights on security and compliance

Practical, no-nonsense guidance on PCI, ISO 27001, GDPR, penetration testing, and building an audit-ready security posture.

PCI Compliance Cost: What Drives the Price

PCI compliance cost depends on your merchant level and how you handle cardholder data: validation, scanning, penetration testing, remediation, and ongoing effort. How to budget and reduce the cost of PCI compliance.

ISO 27001 Certification Cost: What Drives the Total

ISO 27001 certification cost has three parts: the certification body fee plus surveillance, ISMS implementation, and internal time. What drives each, how to reduce costs, and how to budget.

SOC 2 Audit Cost: What You Will Actually Pay

SOC 2 audit cost explained: the CPA auditor fee plus readiness work. What drives each, the key factors that move the number for Type 1 and Type 2 audits, and how to keep compliance costs down.

PCI DSS Level 1: What It Takes

PCI DSS Level 1 is the highest merchant compliance level, validated by an annual QSA-led Report on Compliance plus quarterly ASV scans and penetration testing at least annually and after significant changes. What it takes to meet Level 1 requirements.

SOC 2 Readiness Assessment: What to Expect

A SOC 2 readiness assessment scopes criteria, assesses security controls, identifies gaps, and produces a remediation plan before the audit. What to expect and why it saves money.

The ISO 27001 Certification Process, Step by Step

The ISO 27001 certification process step by step: scope, gap analyses, risk assessment, Statement of Applicability, controls, internal audit, the two-stage certification audit, and surveillance.

PCI DSS SAQ Types Explained: Which One Applies to You?

PCI DSS SAQ types explained: SAQ A, A-EP, B, B-IP, C, C-VT, P2PE, and D. How to complete the right Self-Assessment Questionnaire based on how you take payments, and how to qualify for a simpler one.

SOC 2 for SaaS Companies: The Practical Guide

SOC 2 compliance for SaaS: Trust Services Criteria, cloud security controls auditors look at, and how to achieve SOC 2 with Type 1 then Type 2. A practical guide.

What Is an Approved Scanning Vendor (ASV)?

An Approved Scanning Vendor (ASV) is a PCI SSC-approved organisation that performs the external vulnerability scanning PCI DSS requires, at least quarterly. What a PCI ASV is, why you need one, and how ASV scans work.