Skip to content

Compliance

The programmes, and what each one requires

Mirage Gateway is being built toward formal payment-security and enterprise-trust validation. This page states where each programme actually stands, so that a buyer or partner can evaluate it against evidence rather than against a badge.

Pre-certification — design phase

Where each stands

PCI DSS v4.0.1
Programme in progress — scope design. The validation route is confirmed with a QSA, not assumed.
SOC 2
Planned. An examination report, not a certification, and not described as one here.
ISO/IEC 27001:2022
Planned. Broader than the payment-card scope, covering the management system.
Held today
None of the three. Stated plainly further down this page.

Programmes

In the order they matter for payment infrastructure.

PCI DSS v4.0.1

PCI Security Standards Council

Payment Card Industry Data Security Standard, service provider

Programme in progress — scope design

The first compliance target, covering the Mirage Gateway services and systems that would store, process or transmit payment account data, or affect the security of systems that do. The validation route — SAQ D for Service Providers versus a QSA-led Report on Compliance — is not ours to assume. It depends on the service model, volumes and what the compliance-accepting entity requires, and it is confirmed with a Qualified Security Assessor before launch, not decided in advance.

What it requires

  • QSA scoping engagement
  • Cardholder data flow diagrams
  • Formal CDE scope statement and system inventory
  • Gap assessment and remediation
  • Penetration testing and, where applicable, ASV scanning
  • Service Provider Attestation of Compliance naming the assessed services

SOC 2

AICPA Trust Services Criteria

System and Organization Controls 2

Planned — readiness programme not started

An independent examination report over control design and, in Type II, operating effectiveness. It is not a certification and is not described as one here. Security is the foundational criterion; Availability and Confidentiality matter to anyone depending on a payment API, and Processing Integrity is strategically relevant to payment workflows.

What it requires

  • System boundary definition
  • Control matrix
  • Readiness assessment and remediation
  • Type I examination
  • Type II examination after an operating period

ISO/IEC 27001:2022

International Organization for Standardization

Information security management system

Planned — programme not started

An organisation-level information security management framework, broader than the payment-card scope of PCI DSS. Valuable for enterprise procurement, and capable of eventually covering shared Mirage Global Technologies security governance rather than Mirage Gateway alone.

What it requires

  • ISMS scope definition
  • Risk methodology and risk register
  • Statement of Applicability
  • Policy and control library
  • Internal audit and management review
  • Certification audit by an accredited body

Current position, stated plainly

So that nobody has to infer it, and so that a claim made anywhere else can be checked against this page.

None of the programmes above is complete. Mirage Gateway does not hold PCI DSS validation, a SOC 2 report or ISO/IEC 27001 certification, is not a payment facilitator, acquirer or money transmitter, and is not yet available to external merchants.

  • PCI DSS validation or Attestation of Compliance
  • SOC 2 Type I or Type II report
  • ISO/IEC 27001 certification
  • Payment facilitator, acquirer or money transmitter status
  • A production payment gateway available to external merchants

When a programme completes, it will be stated with its assessed scope and date. If any Mirage document or proposal says otherwise before then, this page is the one that is correct.

On the word certificate

A distinction worth making early, because it decides what evidence a partner can actually accept.

There is no generic payment-security certificate that makes a service provider compliant. Validation is evidenced through the card industry’s own forms — an Attestation of Compliance, supported by the applicable self-assessment questionnaire or a Report on Compliance — and the attestation has to name the services it actually covers.

This matters more than it sounds. A parent company holding a validation that does not cover a particular payment service tells a partner nothing useful about that service. Mirage Gateway’s validation, when it exists, will name its scope and date, because a claim without those is not verifiable.