What is PCI DSS?
Also known as: Payment Card Industry Data Security Standard
PCI DSS is the mandatory security standard for any organization that stores, processes, or transmits credit card data, enforced by the payment card brands.
The Payment Card Industry Data Security Standard (PCI DSS) is a set of security requirements created by the major card brands (Visa, Mastercard, American Express, Discover, JCB) to protect cardholder data. It is managed by the PCI Security Standards Council. Compliance is mandatory for any entity that stores, processes, or transmits credit or debit card information. The current version as of 2025 is PCI DSS v4.0.1, which became effective on April 1, 2024, replacing v3.2.1.
The standard contains 12 core requirements grouped into six control objectives: build and maintain a secure network, protect cardholder data, maintain a vulnerability management program, implement strong access control measures, regularly monitor and test networks, and maintain an information security policy. Each requirement has specific sub-requirements and testing procedures. Validation methods vary by transaction volume. Merchants processing over 6 million card transactions per year must have an annual on-site assessment by a Qualified Security Assessor (QSA). Smaller merchants can self-assess using a Self-Assessment Questionnaire (SAQ). Network scans by an Approved Scanning Vendor (ASV) are required for all merchants handling card data.
PCI DSS sits alongside other security frameworks like ISO 27001 and NIST SP 800-53 but is uniquely prescriptive about cardholder data environments. Non-compliance exposes organizations to fines from acquiring banks, increased transaction fees, and potential loss of card-processing privileges. A breach while non-compliant can trigger penalties of up to $500,000 per incident plus liability for fraud costs. The standard applies to any system component in the cardholder data environment (CDE), including networks, servers, applications, and third-party service providers that process card data.
Key facts
- PCI DSS v4.0.1 is the current version, effective April 2024.
- 12 core requirements organized under 6 control objectives.
- Compliance validation ranges from annual SAQ to on-site QSA assessment based on transaction volume.
- Merchants processing over 6 million card transactions annually require an on-site QSA audit.
- Approved Scanning Vendor (ASV) network scans are mandatory for all merchants handling card data.
- Non-compliance fines from acquiring banks can reach $500,000 per breach incident.
How it works in practice
Related terms
References
More in Standards & Compliance
BCP 14
BCP 14 defines the normative meaning of MUST, SHOULD, MAY, and related keywords used in RFCs to specify requirement levels in Internet standards.
BCP 38
BCP 38 (RFC 2827) is a Best Current Practice that defines ingress filtering to prevent packets with spoofed source IP addresses from leaving a network.
GDPR
The General Data Protection Regulation (GDPR) is an EU law that governs the processing of personal data and applies to any organization worldwide that handles data of EU residents.
HIPAA
HIPAA is a 1996 US federal law that sets national standards for protecting sensitive patient health information from disclosure without consent or knowledge.
IANA
IANA is the function that coordinates global IP address allocation, manages the DNS root zone, and assigns protocol numbers used in Internet standards, ensuring unique identifiers across the network.
ICANN
ICANN is a nonprofit organization that coordinates the Domain Name System (DNS) root zone, accredits registrars, and oversees the Internet Assigned Numbers Authority (IANA) functions for global unique identifiers.
IETF
The Internet Engineering Task Force (IETF) is an open international community of network designers, operators, vendors, and researchers that develops voluntary internet standards, primarily through working groups and the RFC document series.
ISO 27001
ISO 27001 is an international standard specifying requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS).
ITU-T
ITU-T is the United Nations agency that sets global telecommunications standards, including X.509 certificates and G-series video codecs.
Regional Internet Registry
A Regional Internet Registry (RIR) is an organization that manages the allocation and registration of Internet number resources (IP addresses and Autonomous System Numbers) within a specific geographic region.