What it requires
PCI DSS sets 12 requirements grouped around six goals: secure networks, protecting cardholder data, vulnerability management, strong access control, monitoring and testing, and an information security policy. Version 4.0, which replaced 3.2.1 in 2024, added more flexible ways to meet controls and stricter rules on MFA, phishing protection and scripts on payment pages.
How compliance is shown
It depends on the volume of transactions. Large merchants and service providers need an annual assessment by a Qualified Security Assessor (QSA) and a Report on Compliance. Smaller merchants usually complete a Self Assessment Questionnaire (SAQ). Quarterly external vulnerability scans by an approved vendor are also required in most cases.
Reducing the scope
The less card data a company touches, the smaller the scope. Using a payment provider that handles the card entry, through a hosted page or a redirect, keeps most systems out of scope and simplifies compliance considerably.
Relation to other frameworks
PCI DSS is not a law but a contractual obligation. Many controls overlap with ISO 27001 and SOC 2, such as patch management, logging and penetration testing. The official documents are on the PCI SSC website.




