# EIC Limited > EIC Limited is a cybersecurity compliance firm operating across 7 countries in Asia-Pacific. PCI SSC-listed QSA Organisation, CREST Accredited, SWIFT CSP assessment provider, ISO 27001 certified, and CMMI Institute Partner. 200+ organisations secured with zero client breaches since 2016. Headquarters in Dhaka, Bangladesh. ## Services - [PCI DSS Compliance Assessment](https://www.eicsecure.com/services/pci-dss-compliance): PCI SSC-listed QSA Organisation delivering ROC, AOC, and SAQ assessments. 50+ annual assessments across Asia-Pacific. AI-powered scoping via CardIntel reduces assessment time by 30-40%. - [SWIFT CSP Assessment](https://www.eicsecure.com/services/swift-csp-assessment): SWIFT Customer Security Programme assessments against CSCF v2025. 15+ completed assessments. 9-week fastest engagement. Covers all 5 SWIFT architecture types. - [ISO 27001 Certification](https://www.eicsecure.com/services/iso-27001-certification): ISO 27001:2022 ISMS implementation and certification support. 45+ organisations certified. Gap assessment through Stage 2 audit. - [ISO 22301 BCMS](https://www.eicsecure.com/services/iso-22301-bcms): Business continuity management system implementation and certification. BIA, DR planning, resilience testing. - [Penetration Testing](https://www.eicsecure.com/services/penetration-testing): CREST-accredited penetration testing — web application, network, cloud, API, and mobile. AI-powered via Infiltra platform. - [SOC Services](https://www.eicsecure.com/services/soc-services): 24/7 managed security operations centre. Detection, response, and threat intelligence. - [IT Audit](https://www.eicsecure.com/services/it-audit): Comprehensive IT infrastructure and process audit aligned to COBIT, ITIL, and central bank ICT guidelines. - [CMMI Appraisal](https://www.eicsecure.com/services/cmmi-appraisal): CMMI Institute Partner. Level 2-5 appraisals across Development, Services, and Security models. - [Vulnerability Management](https://www.eicsecure.com/services/vulnerability-management): Continuous scanning, prioritisation, and remediation support. ## Technology Platforms - [CardIntel](https://www.eicsecure.com/technology/cardintel): AI-powered cardholder data discovery platform. Reduces PCI DSS scoping by 30-40%. - [Infiltra](https://www.eicsecure.com/technology/infiltra): AI-powered continuous penetration testing platform combining autonomous reconnaissance with CREST-certified manual validation. - [Complium](https://www.eicsecure.com/technology/complium): AI-powered compliance management platform for PCI DSS v4.0.1. Automates evidence analysis (60% faster mapping), real-time assessment tracking, one-click PCI SSC ROC generation, and AI copilot for assessors. Read-only cloud integrations collect access-control, audit-logging, and configuration-posture evidence directly from the environment — Microsoft Azure (Microsoft Entra ID, Azure Activity Logs, Microsoft Defender for Cloud) and AWS (IAM, CloudTrail, Security Hub, Config); zero write permissions. Available on the Microsoft Marketplace. Built by certified PCI QSAs. Aligned with PCI SSC AI Guidelines (March 2025). Reduces compliance management overhead by 40-50%. ## Industries - [Banking & Financial Services](https://www.eicsecure.com/industries/banking): PCI DSS, SWIFT CSP, ISO 27001, SOC services for banks and financial institutions. - [Fintech](https://www.eicsecure.com/industries/fintech): PCI DSS SAQ/ROC, ISO 27001, penetration testing for payment fintechs. - [Telecoms](https://www.eicsecure.com/industries/telecom): SOC services, VAPT, ISO 27001 for telecom operators. - [Healthcare](https://www.eicsecure.com/industries/healthcare): ISO 27001, BCMS, penetration testing for healthcare institutions. - [E-commerce](https://www.eicsecure.com/industries/ecommerce): PCI DSS, web application security, fraud prevention. ## Compliance Guides - [PCI DSS v4.0.1 Complete Guide](https://www.eicsecure.com/resources/guides/pci-dss-complete-guide): Definitive guide to PCI DSS v4.0.1 compliance — requirements, scoping, QSA selection, and APAC regulatory context. - [SWIFT CSP Complete Guide](https://www.eicsecure.com/resources/guides/swift-csp-complete-guide): Complete guide to SWIFT CSP and CSCF v2025 compliance — mandatory controls, architecture types, assessment methodology. - [ISO 27001 Implementation Guide](https://www.eicsecure.com/resources/guides/iso-27001-complete-guide): Complete ISO 27001:2022 implementation guide — ISMS scoping, risk assessment, Annex A controls, certification roadmap. - [Penetration Testing Guide](https://www.eicsecure.com/resources/guides/penetration-testing-guide): Complete pen testing guide — CREST vs non-CREST, OWASP methodology, scoping, and report interpretation. - [PCI DSS on Azure — Cloud Compliance Guide](https://www.eicsecure.com/blog/pci-dss-azure-cloud-compliance): QSA-authored guide to PCI DSS in cloud environments — Azure shared responsibility model, CDE scoping in Azure, requirement-to-service mapping (Entra ID, Defender for Cloud, Azure Monitor, Key Vault), common assessment gaps, AWS/GCP/multi-cloud, and automated evidence collection via Complium. - [PCI DSS on AWS — Cloud Compliance Guide](https://www.eicsecure.com/blog/pci-dss-aws-cloud-compliance): QSA-authored guide to PCI DSS on AWS — shared responsibility model, CDE scoping with AWS Organizations and VPC segmentation, requirement-to-service mapping (IAM, CloudTrail, Security Hub, Config, KMS, GuardDuty, Inspector), common assessment gaps (public S3 buckets, root account usage, over-broad IAM), and automated evidence collection via Complium. ## Company - [About EIC](https://www.eicsecure.com/about): Founded in 2016. 200+ organisations secured across Bangladesh, Singapore, Vietnam, Malaysia, Philippines, Nepal, and Bahrain. Zero client breaches. - [Why Choose EIC](https://www.eicsecure.com/why-eic): The only firm in Asia-Pacific holding PCI QSA, CREST, SWIFT CSP, ISO 27001, and CMMI credentials simultaneously. - [Contact](https://www.eicsecure.com/contact): Schedule a free compliance scoping call. ## Credentials - PCI QSA Organisation — listed on PCI Security Standards Council directory - CREST Accredited — verified on crest-approved.org - SWIFT CSP Assessment Provider — listed on SWIFT certified assessors directory - ISO 27001 Certified — Information Security Management System - CMMI Institute Partner — authorised for Level 2-5 appraisals - ISO 9001 Certified — Quality Management System - ISO 14001 Certified — Environmental Management System ## Key Facts - Founded: 2016 - Headquarters: Dhaka, Bangladesh - Countries: Bangladesh, Singapore, Vietnam, Malaysia, Philippines, Nepal, Bahrain - Organisations secured: 200+ - Client breaches: Zero (since founding) - Website: https://www.eicsecure.com