Case study: Vytal and Securious

Vytal PCI compliance case study

Securious has been working with Vytal to provide PCI DSS assurance for their UK operations, aligning with Vytal’s global controls and documentation and producing the attestations their partners require.

About Vytal

Vytal is a reuse platform that helps cafés, universities and venues cut single-use waste. Customers borrow reusable cups and food containers, return them within a set window, and avoid disposables altogether. The service supports large and small operators, making it easier for them to offer convenient, returnable packaging and reduce environmental impact at scale.

About Securious

Securious is the South West’s leading Payment Card Industry Qualified Security Assessor and cyber security company. We help clients with Governance, Risk and Compliance (PCI DSS, ISO 27001, PCI 3DS, Cyber Essentials and Cyber Essentials Plus); we offer a Managed Detection and Response service (helping clients stay secure with live 24/7 monitoring and visibility of their environments, threat detection and automated alerts, which are overseen by our analysts), and penetration testing services.

The objective

Vytal wanted clear, recognised PCI DSS assurance for the UK that would stand up to partner due-diligence and reflect how the service actually operates. Because the platform both provides services to merchants and receives specific payments itself, Vytal needed attestations that covered both contexts – service provider and merchant – without reinventing documentation already used globally.

The challenge

Behind the scenes, Vytal’s service brings together multiple components and providers. PCI responsibilities are shared between Vytal and third parties, and the platform has two assurance contexts to consider: service provider and merchant. The challenge was to define PCI scope and responsibility boundaries precisely across app, in-venue payment and cloud layers, present this in a form stakeholders could rely on, and package existing global documentation into stable evidence suitable for assessment and future audits – all while keeping the process efficient for a small UK team.

The solution

Securious worked with Vytal to map PCI scope and responsibility boundaries so it was clear what sat with Vytal and what was inherited from providers. We then structured existing materials into fixed evidence packs that aligned with PCI expectations and could be reused for renewals. To speed acceptance, we joined stakeholder sessions to explain the approach and answer assurance questions. With scope, evidence and roles agreed, we completed the assessment for the UK entity and produced two Attestations of Compliance: one as a service provider and one as a merchant. 

The results

Vytal now has PCI DSS attestations in both required contexts for the UK, supported by reusable evidence and a clear responsibility model. Partner due-diligence is faster, renewals are simpler, and UK assurance stays aligned with how the platform operates globally.

Darren, QSA at Securious, comments:

“Vytal wanted assurance that matched the reality of their service, not a tick-box exercise. We concentrated on the foundations that make PCI work in practice: a clear scope, unambiguous responsibility boundaries, and evidence that stands up to scrutiny and can be reused. The UK team were organised and decisive, which meant we could keep momentum, handle assurance questions from partners quickly, and move from scoping to two clean AOCs without drama. It’s a great example of how clarity and pace go hand in hand.”

Adam Trethewy, Vytal UK Expansion Manager, comments:

“Our goal was simple: provide partners with confidence that our service meets PCI expectations, expressed clearly and consistently with our global approach. Securious helped us articulate who does what, shape our documentation into something stakeholders could rely on, and deliver the two attestations we needed with minimal friction. They were responsive, pragmatic and easy to work with throughout – exactly what we were looking for in a PCI partner.”

Learn more about Vytal at their website

If you are interested in PCI DSS Compliance, click here to read more or get in touch using the contact form below