Blog

PCI DSS v4.0.1 FAQs: Requirements and Compliance

Written by Ajay Unni | Sep 22, 2026, 2:13:11 AM

What is PCI?

The Payment Card Industry Data Security Standard (PCI DSS) is a set of requirements designed to protect payment account data. It applies to entities that store, process or transmit cardholder data or sensitive authentication data, and to entities that can affect the security of the cardholder data environment.

What does PCI mean?

PCI means Payment Card Industry. PCI DSS stands for Payment Card Industry Data Security Standard.

What do PCI DSS security standards mean?

The PCI Data Security Standard represents a common set of industry tools and measurements to help ensure the safe handling of sensitive information. The Payment Card Industry Security Standards Council (PCI SSC) was launched in 2006 to manage the ongoing evolution of the Payment Card Industry (PCI) security standards with a focus on improving payment account security throughout the transaction process. The PCI DSS is administered and managed by the PCI SSC, an independent body that was created by the major payment card brands (Visa, Mastercard, American Express, Discover, and JCB).

What are the Payment Card Industry (PCI DSS) Requirements?

PCI DSS v4.0.1 is the current published version. Its 12 principal requirements are summarised below; use the full standard to determine the detailed controls that apply.

Build and Maintain a Secure Network and Systems

  • Requirement 1: Manage network security controls.
  • Requirement 2: Configure systems securely.

Protect Account Data

  • Requirement 3: Safeguard stored account data.
  • Requirement 4: Use strong encryption for cardholder data sent over open, public networks.

Maintain a Vulnerability Management Program

  • Requirement 5: Defend systems and networks against malicious software.
  • Requirement 6: Build and maintain secure software and systems.

Implement Strong Access Control Measures

  • Requirement 7: Limit access to systems and cardholder data according to business need.
  • Requirement 8: Identify users and authenticate their access to systems.
  • Requirement 9: Control physical access to cardholder data.

Regularly Monitor and Test Networks

  • Requirement 10: Record and monitor access to systems and cardholder data.
  • Requirement 11: Test the security of systems and networks regularly.

Maintain an Information Security Policy

  • Requirement 12: Maintain policies and programs that support information security.

Who manages PCI?

The Payment Card Industry Security Standards Council (PCI SSC) was launched in 2006 to manage the ongoing evolution of the Payment Card Industry (PCI) security standards with a focus on improving payment account security throughout the transaction process. The PCI DSS is administered and managed by the PCI SSC, an independent body that was created by the major payment card brands (Visa, Mastercard, American Express, Discover, and JCB).

What are the steps for PCI DSS compliance validation?

PCI DSS compliance is validated using the reporting documents required by the relevant payment brand or acquiring bank. PCI SSC does not recognise generic “compliance certificates” as substitutes for its official validation documents. A typical engagement includes:

  1. Agree the engagement, any NDA and the assessment scope.
  2. Perform a gap assessment against the applicable requirements.
  3. Prepare a remediation plan and address identified gaps.
  4. Complete the required assessment: a Report on Compliance (ROC), or an eligible Self-Assessment Questionnaire (SAQ), as applicable.
  5. Complete the relevant Attestation of Compliance (AOC), submit required evidence and maintain ongoing compliance.

What is PCI DSS Compliance? Does the PCI Security Standards Council enforce compliance?

PCI DSS compliance means meeting the applicable requirements of the standard. The PCI Security Standards Council develops and maintains the standard but does not enforce compliance programs. Payment brands and acquiring banks determine validation and enforcement requirements for their programs.

What is defined as ‘cardholder data’?

Cardholder data consists of, at minimum, the full primary account number (PAN). When present with the PAN, it can also include the cardholder name, expiration date and service code. An address or social security number alone is not cardholder data under this definition. Sensitive authentication data, such as card verification codes, full track data and PIN information, is a separate category subject to its own protections.

What is the definition of ‘merchant’?

For the purposes of the PCI DSS, a merchant is defined as any entity that accepts payment cards bearing the logos of a PCI SSC Participating Payment Brand as payment for goods and/or services. Note that a merchant that accepts payment cards as payment for goods and/or services can also be a service provider if the services sold result in storing, processing, or transmitting cardholder data on behalf of other merchants or service providers. For example, an ISP is a merchant that accepts payment cards for monthly billing, but also is a service provider if it hosts merchants as customers.

What constitutes a Service Provider?

A service provider is a business entity, other than a payment brand, that stores, processes or transmits cardholder data or sensitive authentication data on behalf of another entity. It also includes businesses whose services control or could affect the security of cardholder data, even if they do not directly handle that data.

Do organisations using third-party processors have to be PCI Compliant?

Yes. Merely using a third-party company does not exclude a company from PCI compliance. It may cut down on their risk exposure and consequently reduce the effort to validate compliance. However, it does not mean they can ignore PCI.

What constitutes a payment application?

The term payment application broadly describes software that stores, processes or transmits payment account data electronically. Whether a particular application is eligible for a PCI SSC software-validation program depends on that program’s scope and eligibility criteria; this is separate from the organisation’s PCI DSS obligations.

Are debit card transactions in scope for PCI?

Yes. PCI DSS applies to debit, credit and prepaid cards bearing the logo of a PCI SSC Participating Payment Brand; it is not limited to credit cards.

How to secure credit card Data by achieving PCI Compliance?

The Payment Card Industry Data Security Standard (PCI DSS) is a set of requirements designed to ensure that all companies that process, store or transmit payment account data maintain a secure environment and protect cardholder data. Compliance requires continuously meeting the applicable requirements; a successful assessment alone does not guarantee ongoing security.

What could happen to my organisation if we fail to implement or adhere to the PCI Data Security Standard?

Failure to comply or adhere to the PCI standard may result in fines, restrictions, or permanent expulsion from card acceptance programs. Specific consequences depend on the payment brand’s and acquiring bank’s rules and agreements.

What is PA-DSS?

PA-DSS stands for Payment Application Data Security Standard. It was retired on 28 October 2022 and superseded by the PCI Secure Software Standard and the PCI Secure Software Lifecycle (Secure SLC) Standard. It is no longer an active route for validating new payment applications.

What is an Approved Scanning Vendor (ASV)?

Approved Scanning Vendors (ASVs) are organisations approved by PCI SSC to perform external vulnerability scans of merchants’ and service providers’ internet-facing environments in accordance with the ASV program. A passing ASV scan addresses the applicable scanning requirements; it does not establish overall PCI DSS compliance.

Is Application Penetration testing part of Penetration Testing in PCI DSS?

Penetration testing should include network and application layer testing as well as controls and processes around the networks and applications, and should occur from both outside the network trying to come in (external testing) and from inside the network.

What is meant by “adequate network segmentation” in the PCI DSS?

Through PCI network segmentation the main aim is to reduce the scope (and therefore the complexity) of card-processing networks. Effective segmentation isolates the cardholder data environment from systems that are out of scope, so those systems cannot affect its security. If segmentation is used to reduce scope, its effectiveness must be tested. Limiting stored data and access remains useful, but does not by itself establish effective network segmentation.

How to secure payment Systems or account data?

Security of payment systems or account data is the responsibility of every business that participates in payment processing. PCI DSS provides a common security baseline, while payment brands and acquiring banks retain their own compliance-validation and enforcement programs.

Do I need vulnerability scanning to validate compliance?

Where PCI DSS Requirement 11.3.2 applies, external vulnerability scanning must be performed by a PCI SSC Approved Scanning Vendor, with evidence of passing scans at least once every three months. Internal vulnerability scans are separate requirements. Confirm the applicable requirements and Self-Assessment Questionnaire (SAQ), if eligible, with your acquiring bank or payment brand; outsourcing payment processing does not automatically remove scanning obligations.

How does PCI DSS penetration testing differ from vulnerability assessments, and who performs it?

Vulnerability assessment simply identifies and reports noted vulnerabilities, whereas a penetration test attempts to exploit the vulnerabilities to determine whether unauthorized access or other malicious activity is possible. Penetration testing should include network and application layer testing as well as controls and processes around the networks and applications, and should occur from both outside the network trying to come in (external testing) and from inside the network. The PCI DSS does not require that a QSA or ASV perform the penetration test-it may be performed by either a qualified internal resource or a qualified third party. The tester must also have organisational independence from the systems being tested.

What should I do if I’m compromised?

Activate your incident response plan and promptly notify your acquiring bank and internal security team. Follow the applicable payment-brand reporting and response requirements. For Visa-related incidents, consult Visa’s current What To Do If Compromised: Visa Supplemental Requirements (June 2026), obtained through your acquiring bank. The response must follow the requirements relevant to your organisation and incident.

What is the link for the Payment Card Industry Security Standards (PCI SSC) Website?

Visit the PCI Security Standards Council website for official standards, guidance and program information.