Codego Group LTD is certified PCI DSS Level 1, the highest level of the Payment Card Industry Data Security Standard. The certification was issued in 2025 following an independent assessment by Adsigo and covers the Codego platform environment in which payment card data is stored, processed and transmitted.
Codego Group LTD holds PCI DSS Level 1 certification. The assessment was carried out by Adsigo, an independent security assessor, and the certificate was issued in 2025.
PCI DSS (Payment Card Industry Data Security Standard) is the security standard maintained by the PCI Security Standards Council, founded by the major card networks. It applies to every organisation that stores, processes or transmits payment card data. Level 1 is the highest level: it applies to service providers handling the largest volumes of card transactions and requires the most rigorous validation.
Validation at Level 1 is not a self-assessment. It requires:
(a) an annual assessment by a Qualified Security Assessor (QSA), documented in a Report on Compliance (ROC) and an Attestation of Compliance (AOC);
(b) quarterly external vulnerability scans performed by an Approved Scanning Vendor (ASV);
(c) regular penetration testing of the cardholder data environment;
(d) ongoing compliance with every PCI DSS requirement between one assessment and the next.
PCI DSS sets requirements across the whole lifecycle of cardholder data:
Secure network. Firewalls, network segmentation and hardened system configurations.
Protection of cardholder data. Encryption of card data at rest and in transit, and no storage of sensitive authentication data after authorisation.
Vulnerability management. Protection against malware, secure development and timely patching.
Access control. Access to card data restricted on a need-to-know basis, with unique user identification and strong authentication.
Monitoring and testing. Logging and monitoring of all access to systems and card data, and regular security testing.
Information security policy. A maintained security policy, staff awareness and an incident response plan.
Partners launching card programmes on Codego build on infrastructure that is already PCI DSS Level 1 certified for the services Codego provides. This reduces the scope of their own compliance effort from day one. Each partner remains responsible for the PCI DSS obligations that apply to its own systems, applications and processes.
Partners, prospective partners and auditors may request the PCI DSS compliance documentation, including the Attestation of Compliance, by writing to:
Email: banking@codegotech.com
Subject line: PCI DSS documentation request
Please include your company name and the purpose of the request.