Panacea Infosec
Panacea Infosec is a New Delhi-headquartered PCI QSA and ISO 27001 certification body delivering cybersecurity consulting, compliance auditing and managed security services to 1,300+ clients across 50+ countries, acquired by SGS in January 2026.
- Company typePrivate
- Founded2012
- HeadquartersNew Delhi, India
- Headcount51–100
- GTM typeB2B
- OfferingServices
What Panacea Infosec does
Panacea Infosec is a New Delhi-headquartered information security consulting and managed security services firm founded in 2012, operating across 50+ countries with offices in Gurugram, Noida and Pune and a team of 90+ cybersecurity professionals. The firm is accredited by the PCI Security Standards Council as a Qualified Security Assessor (QSA) and across PCI ASV, PCI 3DS, PCI QPA, PCI SSF and PCI P2PE programs, is an accredited ISO 27001 certification body, and is CERT-In empanelled for Indian government security audits. It delivers PCI DSS and ISO 27001 certification, cybersecurity consulting, security assessments, managed security services and training to banking, payment gateway, telecom, BPO, healthcare, insurance, e-commerce and government clients, complemented by three proprietary products: pCDS (cardholder data scanner), pSAQ (SAQ workflow automation) and pCMD (multi-standard compliance dashboard).
The company generates revenue primarily through project-based professional services engagements priced per scope, supplemented by its proprietary compliance software products. Distribution is direct via the company website and referrals from the PCI SSC GEAR community, with no reseller or marketplace intermediation. Its go-to-market is sales-led enterprise and mid-market engagement, supported by content marketing (blog, case studies), PCI SSC GEAR participation, and earned media from Deloitte Tech Fast 50 India (2020) and Economic Times Fastest Growing MSME (2021) recognition. As of January 2026, Panacea Infosec was acquired by SGS (SIX: SGSN) and operates as part of SGS's Digital Trust segment.
Panacea Infosec firmographics
Firmographics- Name
- Panacea Infosec
- Legal name
- Panacea InfoSec Private Limited
- Website
- https://panaceainfosec.com
- Company type
- Private
- Founded year
- 2012
- Operating status
- Acquired
- Headcount range
- 51–100 employees
- Short description
- Panacea Infosec is a New Delhi-headquartered PCI QSA and ISO 27001 certification body delivering cybersecurity consulting, compliance auditing and managed security services to 1,300+ clients across 50+ countries, acquired by SGS in January 2026.
- Ownership category
- akta.pro rank
Panacea Infosec industry classification
Industry- Product category
- Cybersecurity Consulting
- NAICS
- Computer Systems Design and Related Services (54151), Other Computer Related Services (541519), Other Scientific and Technical Consulting Services (54169)
- SIC
- Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Security Governance, Risk & Compliance (GRC) Advisory (BPAKADAG)
- akta.pro secondary industries
- Cybersecurity & Identity Consulting (BPAHAEAG), Security Information & Event Management (SIEM), SOAR & SOC Platforms (HLACAJAE), IT Governance, Risk & Compliance (IT GRC) Platforms (HDAEALAK)
Keywords
Where Panacea Infosec is headquartered
LocationHeadquarters
- HQ city
- New Delhi
- HQ country
- India
- HQ region
- Asia
Offices4 records
Markets served
Panacea Infosec business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Cybersecurity Consulting and Compliance Services: Panacea Infosec generates revenue primarily through professional services engagements including PCI DSS QSA audits, ISO 27001 certifications, security assessments, penetration testing, managed security services, and cybersecurity training. Revenue is project-based and engagement-based, with services delivered by certified QSAs and security professionals. Clients include payment gateways, banks, financial institutions, telecom companies, BPOs, and e-commerce merchants across 50+ countries.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Professional consulting and auditing services are priced on a per-engagement basis. |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels5 records
Panacea Infosec product offering
Product offeringCore offering
Panacea Infosec is an information security consulting firm specializing in PCI DSS Qualified Security Assessor (QSA) audits, ISO 27001 ISMS certifications, penetration testing, managed security services, and cybersecurity consulting for banks, payment gateways, telecom operators, and government organizations across 50+ countries. The firm also sells three proprietary security products—pCDS (card data scanner), pSAQ (SAQ manager), and pCMD (compliance management dashboard)—to automate payment security and compliance workflows.
Product overview
Panacea Infosec offers a portfolio of three in-house security products designed to support PCI DSS compliance and information security operations: pCDS (Panacea Card Data Scanner) for identifying cardholder data within environments; pSAQ (Panacea SAQ Manager) for automating PCI Self-Assessment Questionnaire processes; and pCMD (Panacea Compliance Management Dashboard) for pre-audit evidence collection and compliance management. These products are complemented by a range of professional services including Managed Security Services (log review/SIEM, cyber forensics, file integrity review, malware analysis), Training services (PCI DSS Implementation, ISO 27001), IT Security Assessment (network penetration testing, web application security testing, mobile application security testing, wireless security testing, secure code review), Cybersecurity Consulting (ISO 27001, ISO 22301, RBI PSS, HIPAA, GLBA, SOX, PCI SAQ, PCI 3DS, vendor security audits), and Compliance Certification services (PCI DSS, ISO 27001).
Differentiator
Problem solved
Functional benefit
Products and services
- Compliance Certification
Quantifiable outcome
- Achieved nationwide PCI DSS certification for a leading Indian banking institution within 6 months, making it the first bank in India to achieve nationwide certification for both acquiring and issuance services.
- +5 more outcomes
Companies that use Panacea Infosec
Customer profileNamed customers9 records
Segments10 records
Ideal customer profiles4 records
Panacea Infosec technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
Panacea Infosec partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- SGSflagshipSGS, the world's leading testing, inspection and certification company, acquired Panacea Infosec in January 2026. The acquisition brings over 90 cybersecurity professionals and expertise in payment security solutions supporting PCI/DSS standards to SGS. Panacea Infosec now operates as part of SGS's Digital Trust segment. SGS is targeting at least CHF 200 million in additional revenue from its Digital Trust segment by 2027 compared to 2023.
Scale indicators7 records
Recent moves5 records
Expansion highlights6 records
Panacea Infosec competitors and assessment
Company assessmentDirect peers
- SISA: SISA is an India-headquartered cybersecurity firm and PCI QSA focused on payment security assessments, PCI DSS compliance, and forensic services. It is the most direct geographic and functional peer to Panacea Infosec, serving banks, payment processors, and merchants across Asia and the Middle East.
- Coalfire: Coalfire is a US-based cybersecurity advisory and PCI QSA firm specializing in PCI DSS, HITRUST, ISO 27001, FedRAMP, and cloud security assessments. It competes directly with Panacea on enterprise PCI mandates and shares a similar professional-services-plus-tools model.
- Foregenix: Foregenix is a UK/South Africa-based cybersecurity consultancy with deep PCI DSS specialization and its own proprietary card-data discovery tools (similar to Panacea's pCDS). Closely comparable in niche focus on payment security, mid-market client base, and geographic mix across EMEA and emerging markets.
- SecurityMetrics: SecurityMetrics is a US-headquartered PCI QSA and cybersecurity firm providing PCI DSS audits, ASV scans, and managed security services. Comparable to Panacea on the merchant-and-processor PCI assessment offering and the blended services-plus-SaaS model.
- ControlCase: ControlCase is a global compliance and cybersecurity services firm specializing in PCI DSS, SOC, ISO 27001, and HITRUST assessments, with proprietary GRC software (similar positioning to Panacea's pCMD). Directly comparable on multi-standard audit-and-platform delivery to BFSI and payment clients.
- A-LIGN: A-LIGN is a US-based cybersecurity and compliance firm specializing in SOC 2, ISO 27001, PCI DSS, HITRUST, and FedRAMP audits. Comparable to Panacea in delivering accredited third-party assurance with a professional-services-plus-technology model targeting enterprise and SaaS clients.
- Schellman & Co: Schellman is a US-based specialty compliance and cybersecurity assessment firm offering SOC, ISO 27001, PCI DSS, HITRUST, and FedRAMP attestation services. Comparable to Panacea on accredited third-party assurance positioning and premium mid-market client mix.
- Trustwave: Trustwave is a global cybersecurity firm providing PCI DSS QSA services, managed security services, database security, and threat intelligence. Directly comparable to Panacea on PCI QSA assessments combined with a managed security services portfolio.
- Tevora: Tevora is a US-based cybersecurity consulting firm providing PCI DSS, SOC, ISO 27001, penetration testing, and managed security services. Comparable to Panacea on the blend of compliance attestation and offensive security testing for enterprise clients.
Broad incumbents
- KPMG Cyber Security Services: KPMG's global cybersecurity practice offers PCI DSS QSA, ISO 27001, SOC reporting, and broader advisory and risk services to multinational clients. As a Big 4 incumbent it competes with Panacea on enterprise mandates and is also closely linked through Panacea's board advisor (ex-KPMG Senior Advisor Rajesh Varma).
Market position
Strengths4 records
Weaknesses5 records
Competitive moat4 records
Key risks5 records
Key highlights7 records
Customer concentration
Panacea Infosec social profiles
Digital presencePanacea Infosec compliance and trust
Trust signalCompliance4 records
Panacea Infosec financial estimates
Financial estimateRevenue estimate
Valuation estimate
Panacea Infosec leadership team
Management profileNumber of profiles
Profiles10 records
Panacea Infosec funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Panacea Infosec M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Panacea Infosec
What does Panacea Infosec do?
Panacea Infosec is an information security consulting firm specializing in PCI DSS Qualified Security Assessor (QSA) audits, ISO 27001 ISMS certifications, penetration testing, managed security services, and cybersecurity consulting for banks, payment gateways, telecom operators, and government organizations across 50+ countries. The firm also sells three proprietary security products—pCDS (card data scanner), pSAQ (SAQ manager), and pCMD (compliance management dashboard)—to automate payment security and compliance workflows.
Is Panacea Infosec a public or private company?
Panacea Infosec is a private company. It is classified as corporate owned and is currently acquired.
When was Panacea Infosec founded?
Panacea Infosec was founded in 2012. It employs 51 to 100 people.
Where is Panacea Infosec based?
Panacea Infosec is headquartered in New Delhi, India, in the Asia region.
How does Panacea Infosec make money?
One revenue line is on record: cybersecurity Consulting and Compliance Services.
Who are Panacea Infosec's main competitors?
Direct peers on record are SISA, Coalfire, Foregenix, SecurityMetrics, ControlCase, A-LIGN, Schellman & Co, Trustwave and Tevora. KPMG Cyber Security Services is listed as a broad incumbent.
Does Panacea Infosec have an API?
No public API is recorded for Panacea Infosec.
What industry is Panacea Infosec in?
Panacea Infosec's product category is Cybersecurity Consulting. Its primary akta.pro industry code is BPAKADAG, Security Governance, Risk & Compliance (GRC) Advisory, with a secondary code of BPAHAEAG, Cybersecurity & Identity Consulting. Its NAICS code is 54151 and its SIC code is 7373.