Milestone CMS Is Now PCI DSS 4.0.1 Certified

We’re happy to share that Milestone has earned PCI DSS 4.0.1 certification, confirmed through an independent assessment by Aegisra Assurance LLP. For our CMS customers, this is more than a badge. It means the platform behind your website, booking pages, and payment-connected workflows has been checked against one of the most demanding security standards in the industry. 

Why this matters for CMS customers

Your CMS does far more than publish pages. It powers booking engines, guest-facing forms, and the workflows that sit right next to payment. Anywhere card data can travel, security must hold up. 

That is exactly what PCI DSS is built for. It is the global standard for protecting payment card information, and it sets clear, verifiable rules for how systems that touch that data should be secured. More and more, customers and procurement teams ask for proof of it before they will trust a platform. This certification is proof, validated by an outside assessor rather than something we simply claim about ourselves. 

The assessment at a glance

  • Standard: PCI DSS Version 4.0.1
  • Scope: SAQ-A-EP

What the assessment covered

The review looked at six core areas of security, all of which support the environment your CMS runs in. 

Secure networks. Firewalls, segmentation, CDN protections, and hardened configurations that keep unauthorized traffic out from the network layer up. 

Data protection. Strong encryption and secure handling for sensitive data, whether it is stored or moving between systems. 

Vulnerability management. Regular patching, updates, and system hardening that shrink the window attackers have to work with. 

Access control. Role-based permissions, authentication, and physical safeguards so only the right people reach sensitive systems. 

Network monitoring. Continuous logging and testing to catch and respond to unusual activity early. 

Security policy. A company-wide security program that shapes how the whole team works, from onboarding to daily practice. 

What you get from it

For CMS customers, the certification gives you: 

  • Confidence that the platform hosting your site meets an independently verified security standard.
  • Less risk around any payment-adjacent or guest data workflows connected to your CMS.
  • Documentation you can hand straight to your own security and procurement reviews.

Security is ongoing, not one and done

Threats change, and so do the controls needed to stay ahead of them. This certification reflects where we stand today, and it comes with a commitment to keep investing in the monitoring, governance, and testing that keep your platform protected over time. 

If you need security documentation for a vendor review, or you would like to know more about how we approach security, reach out to the Milestone team anytime. 

Timothy Talreja

Recent Posts

US Search Awards 2026: Milestone Shortlisted in Three Categories

We’re excited to announce that Milestone, Inc. has been shortlisted in three categories at the 2026…

3 days ago

Building the Knowledge Foundation for AI Discovery: From Schema to Entities

For more than two decades, being found meant earning a place on the results page.…

7 days ago

NLWeb: The first step toward AI-ready Knowledge Layer

AI is creating a new front door to the web. Every major shift on the web…

1 week ago

Webinar: 5 Must-Haves for Hotel Websites in the AI Era and Product Roadmap

AI is changing how travelers discover, evaluate, and book hotels, and the hotel website must…

2 weeks ago

Webinar Recap: The Hotelier’s Guide to Search, AI Visibility, and Budgeting for 2027

Milestone experts Brad Nelson, Mike Supple, and Khara Mangiduyos walked through how AI is fundamentally…

3 weeks ago

Webinar Recap: The AI Visibility Flywheel – How Brands Get Featured in AI Search

In this session, Milestone experts Benu Aggarwal, Bill Hunt, and Ritika Chugh discussed how AI…

4 weeks ago