GlossaryCompliance operations

PCI DSS

Short answer

PCI DSS (Payment Card Industry Data Security Standard) is the security standard that any organisation that stores, processes or transmits payment card data must follow. It is set by the PCI Security Standards Council, founded by the major card brands, and enforced through contracts with banks and payment providers.

What it requires

PCI DSS sets 12 requirements grouped around six goals: secure networks, protecting cardholder data, vulnerability management, strong access control, monitoring and testing, and an information security policy. Version 4.0, which replaced 3.2.1 in 2024, added more flexible ways to meet controls and stricter rules on MFA, phishing protection and scripts on payment pages.

How compliance is shown

It depends on the volume of transactions. Large merchants and service providers need an annual assessment by a Qualified Security Assessor (QSA) and a Report on Compliance. Smaller merchants usually complete a Self Assessment Questionnaire (SAQ). Quarterly external vulnerability scans by an approved vendor are also required in most cases.

Reducing the scope

The less card data a company touches, the smaller the scope. Using a payment provider that handles the card entry, through a hosted page or a redirect, keeps most systems out of scope and simplifies compliance considerably.

Relation to other frameworks

PCI DSS is not a law but a contractual obligation. Many controls overlap with ISO 27001 and SOC 2, such as patch management, logging and penetration testing. The official documents are on the PCI SSC website.

Related terms

Keep reading on this topic

Running security as a repeatable process: policy management, risk registers, evidence upkeep, supplier assessment and audit readiness between cycles.

Go to the topic hub