EST. 2012 CODEGO GROUP LTD · MALTA BANKING AS A SERVICE LOCAL IBAN · 15 COUNTRIES SEPA · SEPA INSTANT · SWIFT · 21 CCY PCI DSS CERTIFIED 2025 API FIRST · WEBHOOKS 79 COUNTRIES DEPOSITS MULTI-CURRENCY · 12+ FIAT $1.1BN PROCESSED 2025 EST. 2012 CODEGO GROUP LTD · MALTA BANKING AS A SERVICE LOCAL IBAN · 15 COUNTRIES SEPA · SEPA INSTANT · SWIFT · 21 CCY PCI DSS CERTIFIED 2025 API FIRST · WEBHOOKS 79 COUNTRIES DEPOSITS MULTI-CURRENCY · 12+ FIAT $1.1BN PROCESSED 2025
Codego · Compliance · est. 2012 PCI DSS · Level 1 ● Certified by Adsigo · 2025
PCI

PCI DSS Level 1.
The highest standard for protecting cardholder data.

Codego Group LTD is certified PCI DSS Level 1, the highest level of the Payment Card Industry Data Security Standard. The certification was issued in 2025 following an independent assessment by Adsigo and covers the Codego platform environment in which payment card data is stored, processed and transmitted.

01
Certification

Certification

Codego Group LTD holds PCI DSS Level 1 certification. The assessment was carried out by Adsigo, an independent security assessor, and the certificate was issued in 2025.

PCI DSS (Payment Card Industry Data Security Standard) is the security standard maintained by the PCI Security Standards Council, founded by the major card networks. It applies to every organisation that stores, processes or transmits payment card data. Level 1 is the highest level: it applies to service providers handling the largest volumes of card transactions and requires the most rigorous validation.

02
What Level 1 requires

What Level 1 requires

Validation at Level 1 is not a self-assessment. It requires:

(a) an annual assessment by a Qualified Security Assessor (QSA), documented in a Report on Compliance (ROC) and an Attestation of Compliance (AOC);
(b) quarterly external vulnerability scans performed by an Approved Scanning Vendor (ASV);
(c) regular penetration testing of the cardholder data environment;
(d) ongoing compliance with every PCI DSS requirement between one assessment and the next.

03
What the standard covers

What the standard covers

PCI DSS sets requirements across the whole lifecycle of cardholder data:

Secure network. Firewalls, network segmentation and hardened system configurations.
Protection of cardholder data. Encryption of card data at rest and in transit, and no storage of sensitive authentication data after authorisation.
Vulnerability management. Protection against malware, secure development and timely patching.
Access control. Access to card data restricted on a need-to-know basis, with unique user identification and strong authentication.
Monitoring and testing. Logging and monitoring of all access to systems and card data, and regular security testing.
Information security policy. A maintained security policy, staff awareness and an incident response plan.

04
What it means for partners

What it means for partners

Partners launching card programmes on Codego build on infrastructure that is already PCI DSS Level 1 certified for the services Codego provides. This reduces the scope of their own compliance effort from day one. Each partner remains responsible for the PCI DSS obligations that apply to its own systems, applications and processes.

05
Request compliance documentation

Request compliance documentation

Partners, prospective partners and auditors may request the PCI DSS compliance documentation, including the Attestation of Compliance, by writing to:

Email: banking@codegotech.com
Subject line: PCI DSS documentation request

Please include your company name and the purpose of the request.