The Payment Card Industry Data Security Standard (PCI DSS) is a set of requirements designed to protect payment account data. It applies to entities that store, process or transmit cardholder data or sensitive authentication data, and to entities that can affect the security of the cardholder data environment.
PCI means Payment Card Industry. PCI DSS stands for Payment Card Industry Data Security Standard.
The PCI Data Security Standard represents a common set of industry tools and measurements to help ensure the safe handling of sensitive information. The Payment Card Industry Security Standards Council (PCI SSC) was launched in 2006 to manage the ongoing evolution of the Payment Card Industry (PCI) security standards with a focus on improving payment account security throughout the transaction process. The PCI DSS is administered and managed by the PCI SSC, an independent body that was created by the major payment card brands (Visa, Mastercard, American Express, Discover, and JCB).
PCI DSS v4.0.1 is the current published version. Its 12 principal requirements are summarised below; use the full standard to determine the detailed controls that apply.
The Payment Card Industry Security Standards Council (PCI SSC) was launched in 2006 to manage the ongoing evolution of the Payment Card Industry (PCI) security standards with a focus on improving payment account security throughout the transaction process. The PCI DSS is administered and managed by the PCI SSC, an independent body that was created by the major payment card brands (Visa, Mastercard, American Express, Discover, and JCB).
PCI DSS compliance is validated using the reporting documents required by the relevant payment brand or acquiring bank. PCI SSC does not recognise generic “compliance certificates” as substitutes for its official validation documents. A typical engagement includes:
PCI DSS compliance means meeting the applicable requirements of the standard. The PCI Security Standards Council develops and maintains the standard but does not enforce compliance programs. Payment brands and acquiring banks determine validation and enforcement requirements for their programs.
Cardholder data consists of, at minimum, the full primary account number (PAN). When present with the PAN, it can also include the cardholder name, expiration date and service code. An address or social security number alone is not cardholder data under this definition. Sensitive authentication data, such as card verification codes, full track data and PIN information, is a separate category subject to its own protections.
For the purposes of the PCI DSS, a merchant is defined as any entity that accepts payment cards bearing the logos of a PCI SSC Participating Payment Brand as payment for goods and/or services. Note that a merchant that accepts payment cards as payment for goods and/or services can also be a service provider if the services sold result in storing, processing, or transmitting cardholder data on behalf of other merchants or service providers. For example, an ISP is a merchant that accepts payment cards for monthly billing, but also is a service provider if it hosts merchants as customers.
A service provider is a business entity, other than a payment brand, that stores, processes or transmits cardholder data or sensitive authentication data on behalf of another entity. It also includes businesses whose services control or could affect the security of cardholder data, even if they do not directly handle that data.
Yes. Merely using a third-party company does not exclude a company from PCI compliance. It may cut down on their risk exposure and consequently reduce the effort to validate compliance. However, it does not mean they can ignore PCI.
The term payment application broadly describes software that stores, processes or transmits payment account data electronically. Whether a particular application is eligible for a PCI SSC software-validation program depends on that program’s scope and eligibility criteria; this is separate from the organisation’s PCI DSS obligations.
Yes. PCI DSS applies to debit, credit and prepaid cards bearing the logo of a PCI SSC Participating Payment Brand; it is not limited to credit cards.
The Payment Card Industry Data Security Standard (PCI DSS) is a set of requirements designed to ensure that all companies that process, store or transmit payment account data maintain a secure environment and protect cardholder data. Compliance requires continuously meeting the applicable requirements; a successful assessment alone does not guarantee ongoing security.
Failure to comply or adhere to the PCI standard may result in fines, restrictions, or permanent expulsion from card acceptance programs. Specific consequences depend on the payment brand’s and acquiring bank’s rules and agreements.
PA-DSS stands for Payment Application Data Security Standard. It was retired on 28 October 2022 and superseded by the PCI Secure Software Standard and the PCI Secure Software Lifecycle (Secure SLC) Standard. It is no longer an active route for validating new payment applications.
Approved Scanning Vendors (ASVs) are organisations approved by PCI SSC to perform external vulnerability scans of merchants’ and service providers’ internet-facing environments in accordance with the ASV program. A passing ASV scan addresses the applicable scanning requirements; it does not establish overall PCI DSS compliance.
Penetration testing should include network and application layer testing as well as controls and processes around the networks and applications, and should occur from both outside the network trying to come in (external testing) and from inside the network.
Through PCI network segmentation the main aim is to reduce the scope (and therefore the complexity) of card-processing networks. Effective segmentation isolates the cardholder data environment from systems that are out of scope, so those systems cannot affect its security. If segmentation is used to reduce scope, its effectiveness must be tested. Limiting stored data and access remains useful, but does not by itself establish effective network segmentation.
Security of payment systems or account data is the responsibility of every business that participates in payment processing. PCI DSS provides a common security baseline, while payment brands and acquiring banks retain their own compliance-validation and enforcement programs.
Where PCI DSS Requirement 11.3.2 applies, external vulnerability scanning must be performed by a PCI SSC Approved Scanning Vendor, with evidence of passing scans at least once every three months. Internal vulnerability scans are separate requirements. Confirm the applicable requirements and Self-Assessment Questionnaire (SAQ), if eligible, with your acquiring bank or payment brand; outsourcing payment processing does not automatically remove scanning obligations.
Vulnerability assessment simply identifies and reports noted vulnerabilities, whereas a penetration test attempts to exploit the vulnerabilities to determine whether unauthorized access or other malicious activity is possible. Penetration testing should include network and application layer testing as well as controls and processes around the networks and applications, and should occur from both outside the network trying to come in (external testing) and from inside the network. The PCI DSS does not require that a QSA or ASV perform the penetration test-it may be performed by either a qualified internal resource or a qualified third party. The tester must also have organisational independence from the systems being tested.
Activate your incident response plan and promptly notify your acquiring bank and internal security team. Follow the applicable payment-brand reporting and response requirements. For Visa-related incidents, consult Visa’s current What To Do If Compromised: Visa Supplemental Requirements (June 2026), obtained through your acquiring bank. The response must follow the requirements relevant to your organisation and incident.
Visit the PCI Security Standards Council website for official standards, guidance and program information.