Compliance Control
Compliance Control is a Russian-headquartered cybersecurity consulting firm that provides PCI certification, Bank of Russia regulatory assessments, penetration testing, and managed security services to banks, fintechs, payment systems, and retailers across Russia, CIS, and EMEA.
- Company typePrivate
- Founded2012
- HeadquartersVolokolamsk, Russia
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Compliance Control does
Compliance Control is a Russian-headquartered cybersecurity consulting firm founded in 2012, operating as part of the Compliance Control & Rakasta international consulting group. The company provides certification and assessment services across the full PCI standard family (PCI DSS QSA, PCI PIN Security, PCI 3DS, PCI Card Production, PCI SSF), SWIFT CSP, ISO 27001, GDPR, and Russian regulatory regimes including Bank of Russia regulations (716-P, 851-P, 742-P, 757-P, 779-P, 802-P, 821-P, 833-P), GOST R 57580.1-2017, and Federal Law 152 on personal data. It also delivers security testing services (penetration testing, web and mobile application security, social engineering, source code analysis, OUD4/EAL4+ assessments) and Secure SDLC consulting projects. Notable proprietary components include a cloud-based pentesting lab on RCloud by 3data infrastructure, a Research Center publishing vulnerability research (including the EvilPrinter NTLM coercion mechanism and MongoBleed CVE-2025-14847 analysis), and the Compliance App platform for CISO-led regulatory task management.
The business is built on regulatory credentials that create a high barrier to entry: Compliance Control is the first Russian-speaking VISA PIN Security Assessor globally (since February 2014), an Approved Scanning Vendor certified by PCI SSC, an SWIFT CSP Assessor, an FSTEC-licensed technical protection provider, and is listed on the NSPK (National Payment Card System) Qualified Auditors Register. Revenue is generated primarily through project-based professional services engagements with B2B clients, supplemented by subscription-based MSSP services (delivered under the Rakasta brand, with the first international contract signed in Georgia in February 2026) and emerging SaaS revenue from the Compliance App platform. The company runs a sales-led, event-driven go-to-market targeting banks, fintech firms, payment systems, retailers, and government entities in Russia, CIS (Kazakhstan, Uzbekistan, Tajikistan, Kyrgyzstan, Georgia), EMEA, and MENA, supported by the annual 'Fintech in Security' conference series held across multiple countries and participation in 700+ tenders annually.
Scale signals include 1,200+ cumulative clients worldwide, 1,000+ PCI DSS certification projects completed, 700-900+ projects and 500+ pentests delivered in 2025, a TOP-3 VISA PCI auditor ranking in the CEMEA region, and 44.6% YoY KPI growth in 2025. The company has 11-50 employees, operates from Volokolamsk (headquarters) and Moscow, with regional presence in Tashkent (IT Park Uzbekistan resident since 2022), Almaty, Dushanbe, and Tbilisi. Compliance Control is a privately held Russian LLC with no disclosed external institutional funding, no parent company, and no public listing.
Compliance Control firmographics
Firmographics- Name
- Compliance Control
- Legal name
- Общество с ограниченной ответственностью "Комплаинс Контрол"
- Website
- https://compliance-control.ru
- Company type
- Private
- Founded year
- 2012
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Compliance Control is a Russian-headquartered cybersecurity consulting firm that provides PCI certification, Bank of Russia regulatory assessments, penetration testing, and managed security services to banks, fintechs, payment systems, and retailers across Russia, CIS, and EMEA.
- Ownership category
- akta.pro rank
Compliance Control industry classification
Industry- Product category
- Cybersecurity Compliance Consulting
- NAICS
- Security Systems Services (except Locksmiths) (561621)
- akta.pro primary industry
- POS Certification, Testing & Compliance (EMVCo, PCI PTS/PCI DSS) (FSAMADAL)
- akta.pro secondary industries
- Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX) (BPAKADAC), Compliance, Risk & Audit Management (SOC 2/ISO/PCI) (HDABANAK)
Keywords
Where Compliance Control is headquartered
LocationHeadquarters
- HQ city
- Volokolamsk
- HQ country
- Russia
- HQ region
- Europe
Offices6 records
Markets served
Compliance Control business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Cybersecurity Consulting and Certification: Core revenue stream from providing consulting and certification services for compliance with PCI DSS, PCI PIN Security, PCI SSF, PCI 3DS, PCI Card Production, SWIFT CSP, ISO 27001, GDPR, Russian Bank of Russia regulations (716-P, 851-P, 742-P, 757-P, 779-P, 802-P, 821-P, 833-P), GOST R 57580.1-2017, Federal Law 152, and Bank of Russia regulations for financial institutions. Services include gap assessments, remediation roadmaps, documentation development, audit support, and compliance maintenance.
- Security Testing (Penetration Testing, Vulnerability Analysis, AppSec): Revenue from conducting penetration tests, web application security testing, DBO system testing, mobile application security assessments, social engineering assessments, source code analysis, OUD4 (EAL4+) assessments, and ASV scanning. Methods follow OSSTMM and PTES standards. Over 500 pentests and more than 100 projects per year are conducted.
- MSSP (Managed Security Service Provider) Services: Ongoing managed security services delivered via subscription model, including vulnerability management, incident monitoring, and perimeter control. First international MSSP contract signed in Georgia in February 2026.
- Secure SDLC Implementation Services: Consulting engagements for building secure software development lifecycle processes, including maturity audits, roadmap development, and implementation support. Projects start from 1,050,000 RUB.
- OUD4 Assessment Services: Compliance assessment services for applications requiring Evaluation Assurance Level 4 (EAL4) under GOST R ISO/IEC 15408-3-2013. Projects priced from 800,000 RUB.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| One time/ perpetual license | Multi-year contract | Secure SDLC Implementation — Fixed project price |
| One time/ perpetual license | Multi-year contract | OUD4 Assessment — Fixed project price |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels7 records
Compliance Control product offering
Product offeringCore offering
Compliance Control provides information security audit and consulting services for organizations handling payment card data and financial transactions, with specialization in PCI DSS, PCI PIN Security, PCI SSF, PCI 3DS, and PCI Card Production standards. The firm delivers penetration testing, ASV scanning, SWIFT CSP and ISO 27001 compliance assessments, and supports alignment with Russian Federation regulations including Bank of Russia standards. Its proprietary Compliance App platform enables ongoing compliance management and evidence collection across these frameworks.
Product overview
Compliance Control is a cybersecurity consulting company founded in 2012, operating as part of the international consulting group Compliance Control & Rakasta. The company offers a comprehensive portfolio of information security services rather than a unified software platform. Core offerings include penetration testing services (infrastructure, web applications, mobile apps, DBO systems, social engineering, and source code analysis), PCI compliance certification services (PCI DSS QSA, PCI PIN Security, PCI SSF, PCI 3DS, PCI Card Production), and Russian regulatory compliance consulting (Bank of Russia standards including ГОСТ Р 57580.1-2017, Federal Law No. 152, and various ЦБ Положения). The company also provides Secure SDLC implementation services, ASV scanning as a PCI SSC-certified vendor, OUD 4 conformity assessments, and comprehensive personal data protection services. A notable platform offering is Compliance App, which helps CISO and compliance managers coordinate regulatory requirements and internal compliance tasks. The company maintains an active research center publishing vulnerability research and participates in international cybersecurity competitions through its CTF team Pwn3dP0ss3. Geographic footprint spans Russia, CIS countries (Kazakhstan, Uzbekistan, Tajikistan, Kyrgyzstan, Georgia), EMEA, and MENA regions.
Differentiator
Problem solved
Functional benefit
Brands
- Compliance App: A platform designed to help CISO and compliance managers manage regulatory and internal requirements tasks, coordinate employee and department work, and engage auditors in the work process.
Products and services
- Information Security Audit Comprehensive audit of an organization's information security controls, policies, and procedures, delivered to banks, payment processors, and financial institutions.
- PCI DSS Compliance Assessment Formal assessment against the Payment Card Industry Data Security Standard, including gap analysis, remediation support, and Report on Compliance (ROC) preparation for merchants, processors, and service providers handling cardholder data.
- PCI Family Standards Assessment Assessments covering PCI PIN Security, PCI Software Security Framework (SSF), PCI 3-D Secure (3DS), and PCI Card Production standards for organizations across the payment ecosystem.
- SWIFT CSP Compliance Compliance assessment and attestation support for the SWIFT Customer Security Programme, targeted at banks and financial institutions operating SWIFT infrastructure.
- ISO 27001 Implementation End-to-end consulting service for designing, implementing, and certifying an Information Security Management System (ISMS) aligned with ISO/IEC 27001.
- Russian Regulatory Compliance Consulting Advisory and assessment services for Russian Federation information security regulations, including Bank of Russia standards on information security (e.g., GOST R 57580, 152-FZ on personal data, 187-FZ on critical information infrastructure, 21-FZ on national payment system).
- Penetration Testing Manual and automated penetration testing of networks, applications, and infrastructure to identify exploitable vulnerabilities, including pre-PCI DSS testing and ad-hoc security assessments.
- ASV Scanning External vulnerability scanning performed under PCI SSC Approved Scanning Vendor (ASV) methodology to satisfy PCI DSS Requirement 11.3.2 quarterly scan requirements.
- Compliance App Proprietary SaaS platform for ongoing compliance program management, evidence collection, control mapping, and reporting across PCI DSS, ISO 27001, SWIFT CSP, and Russian regulatory frameworks.
Quantifiable outcome
- 44.6% year-over-year growth in key performance indicators in 2025
- +7 more outcomes
Companies that use Compliance Control
Customer profileNamed customers11 records
Segments6 records
Ideal customer profiles2 records
Compliance Control technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature10 records
Compliance Control partnerships and signals
Strategic signalPartnerships
Eleven partnerships are on record, tiered strategic, core and minor.
- Fido-Biznes Academy (FBA)strategicPartnership agreement signed in June 2026 between Compliance Control & Rakasta and Fido-Biznes Academy, an educational platform of one of the largest developers and suppliers of information systems in Uzbekistan. The partnership developed educational programs adapted to Uzbekistan's regulatory requirements and current market trends, covering PCI DSS compliance, Bank of Uzbekistan information security requirements, and MSSP services for financial sector professionals.
- IT Park UzbekistanstrategicCompliance Control & Rakasta is an official resident of IT Park Uzbekistan since 2022, operating from Tashkent. This residency enables the company to conduct business operations and collaborate with local banks and fintech companies in the Republic of Uzbekistan.
- RakastacoreRakasta is the core partner company within the Compliance Control & Rakasta consulting group. Together, the group operates as an international cybersecurity consulting firm with combined expertise in certification, penetration testing, and MSSP services. Rakasta serves as the brand under which MSSP and managed security services are delivered, and the group jointly organizes the annual 'Fintech in Security' conference across multiple countries.
- RCloud by 3datacoreRCloud by 3data provides cloud infrastructure for Compliance Control's pentesting laboratory environment. The cloud-based laboratory enables over 50 successful cybersecurity research studies. RCloud provides VMware-based virtual environment, GPU-accelerated servers, and SLA-backed cloud infrastructure hosted in Moscow data centers. Compliance Control also certifies RCloud's platform under PCI DSS and conducts ASV scanning for the platform.
- PCI Security Standards Council (PCI SSC)coreCompliance Control holds QSA (Qualified Security Assessor), ASV (Approved Scanning Vendor), PCI 3DS Assessor, PCI Card Production SA, and PCI SSF Assessor accreditations from PCI SSC. These accreditations enable the company to conduct official PCI certification audits globally and represent the core of its compliance business.
- VISAcoreCompliance Control is a VISA-qualified PIN Security Assessor (PIN SA), first Russian-speaking company worldwide to achieve this qualification in February 2014. Also recognized as TOP-3 VISA PCI auditor in the CEMEA region. VISA qualification enables the company to conduct official PIN Security audits globally.
- BSI (British Standards Institution)minorBSI partner relationship for certification and standards collaboration, including ISO 27001 assessment capabilities and broader international standards work.
- SWIFT (Society for Worldwide Interbank Financial Telecommunication)coreCompliance Control holds SWIFT CSP Assessor status, enabling the company to conduct SWIFT Customer Security Programme assessments for SWIFT users globally.
- NSPK (National Payment Card System / НСПК)coreCompliance Control and its employees are officially listed in the Register of Qualified Auditors for Security of the National Payment Card System (NSPK), a mandatory credential for conducting audits in Russia's domestic payment card infrastructure.
- FinTech Association (Russia / Ассоциация ФинТех)strategicCompliance Control conducted joint research 'Security Resilience: Approaches to Assessing Information Security Maturity' with the FinTech Association, analyzing international IS frameworks for applicability in the Russian fintech sector. The company actively participates in FinTech Association events and working groups.
- SPACE (Kazakhstan CTF team)minorCollaborative CTF team partnership with Kazakhstan-based SPACE team for international cybersecurity competitions. Combined team SPACE x Pwn3dP0ss3 has consistently ranked in top 10 at Standoff competitions (2025 and 2026).
Scale indicators16 records
Recent moves7 records
Expansion highlights6 records
Compliance Control competitors and assessment
Company assessmentDirect peers
- SecurityMetrics: PCI-focused QSA and ASV firm providing PCI DSS audits, ASV scanning, and compliance services to merchants, payment processors, and financial institutions. Directly comparable QSA/ASV business mix, though focused on North American SMB merchants.
- Positive Technologies: Russian cybersecurity vendor and organizer of the Standoff cyber battle where Compliance Control's CTF team competes. Provides penetration testing, application security, and compliance tooling to Russian banks and critical infrastructure — the closest Russian-headquartered competitor in pentest and research depth.
- Coalfire: US-headquartered cybersecurity advisory firm with PCI QSA, ASV, and FedRAMP accreditations, providing compliance assessments and penetration testing across financial services. Directly comparable in QSA-led service model and CEMEA-adjacent coverage.
- Trustwave: Global PCI QSA, ASV, and managed security services provider delivering PCI DSS, penetration testing, and compliance consulting to banks, payment processors, and retailers. Most directly comparable global peer to Compliance Control given overlapping QSA/ASV/MSSP portfolio.
- Swordfish Security: Russian AppSec specialist offering Secure SDLC implementation, source code analysis, and penetration testing to financial institutions and fintechs. Directly comparable on the Secure SDLC and application security testing service line where Compliance Control sells from 1,050,000 RUB engagements.
Regional players
- Jet Infosystems: Russian IT and cybersecurity consultancy providing information security audits, compliance consulting, and penetration testing to banks and large enterprises. Comparable in Bank of Russia compliance and audit services, primarily focused on the Russian market.
- Informzashchita: One of the largest Russian cybersecurity consultancies, providing information security audits, Bank of Russia compliance consulting, and FSTEC-licensed services to banks and critical infrastructure. Comparable on Russian regulatory compliance work but primarily focused on the Russian domestic market.
- BI.ZONE: Russian cybersecurity company offering penetration testing, red teaming, threat intelligence, and managed security services to financial institutions across CIS. Comparable MSSP and pentest capabilities, with stronger enterprise brand recognition inside Russia.
- Angara Security: Russian MSSP and cybersecurity integrator offering managed security monitoring, vulnerability management, and compliance services to financial institutions. Comparable on the MSSP recurring-revenue model that Compliance Control is now building internationally.
Broad incumbents
- KPMG Cyber Security Services: Global Big 4 cybersecurity practice delivering PCI DSS, SWIFT CSP, ISO 27001, and regulatory compliance services to multinational banks and fintechs. Competes with Compliance Control on cross-border financial-sector compliance engagements, with deeper Western market reach but less Russian-regulatory depth.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Compliance Control social profiles
Digital presenceCompliance Control compliance and trust
Trust signalCompliance13 records
Compliance Control financial estimates
Financial estimateRevenue estimate
Valuation estimate
Compliance Control leadership team
Management profileNumber of profiles
Profiles2 records
Compliance Control funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Compliance Control M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Compliance Control
What does Compliance Control do?
Compliance Control provides information security audit and consulting services for organizations handling payment card data and financial transactions, with specialization in PCI DSS, PCI PIN Security, PCI SSF, PCI 3DS, and PCI Card Production standards. The firm delivers penetration testing, ASV scanning, SWIFT CSP and ISO 27001 compliance assessments, and supports alignment with Russian Federation regulations including Bank of Russia standards. Its proprietary Compliance App platform enables ongoing compliance management and evidence collection across these frameworks.
Is Compliance Control a public or private company?
Compliance Control is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Compliance Control founded?
Compliance Control was founded in 2012. It employs 11 to 50 people.
Where is Compliance Control based?
Compliance Control is headquartered in Volokolamsk, Russia, in the Europe region.
How does Compliance Control make money?
Five revenue lines are on record. Cybersecurity Consulting and Certification is the primary driver. The others are security Testing (Penetration Testing, Vulnerability Analysis, AppSec), MSSP (Managed Security Service Provider) Services, secure SDLC Implementation Services and OUD4 Assessment Services.
Who are Compliance Control's main competitors?
Direct peers on record are SecurityMetrics, Positive Technologies, Coalfire, Trustwave and Swordfish Security. Regional players are Jet Infosystems, Informzashchita, BI.ZONE and Angara Security. KPMG Cyber Security Services is listed as a broad incumbent.
Does Compliance Control have an API?
No public API is recorded for Compliance Control.
What industry is Compliance Control in?
Compliance Control's product category is Cybersecurity Compliance Consulting. Its primary akta.pro industry code is FSAMADAL, POS Certification, Testing & Compliance (EMVCo, PCI PTS/PCI DSS), with a secondary code of BPAKADAC, Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX). Its NAICS code is 561621.