ReadSafety.com
Payment Security StandardPCI Security Standards Council (PCI SSC)Last reviewed: August 2026

PCI DSS

PCI DSS is the security standard that any organization handling credit card data must follow to protect cardholder information from theft and fraud.

What You'll Learn

  • What PCI DSS is and who created it
  • Who must comply with PCI DSS
  • The 12 requirements overview
  • Cardholder data environment (CDE)
  • Compliance levels and validation methods
  • Self-Assessment Questionnaires (SAQ) vs on-site audits
  • Consequences of non-compliance

First: What Is This?

PCI DSS (Payment Card Industry Data Security Standard) is a set of security requirements designed to protect cardholder data wherever it is processed, stored, or transmitted. It is published by the PCI Security Standards Council (PCI SSC), which was founded by Visa, Mastercard, American Express, Discover, and JCB.

Any organization that accepts, processes, stores, or transmits credit card information must comply with PCI DSS. This includes merchants (shops, restaurants, e-commerce sites), payment processors, banks, and service providers. The standard exists because credit card fraud costs billions annually, and stolen card data can be used for unauthorized purchases worldwide.

Who Does It Apply To?

Merchants accepting card payments (any size)
Payment processors and gateways
Banks and financial institutions issuing or acquiring cards
Service providers with access to cardholder data
E-commerce sites using fully outsourced payment (reduced scope but still applicable)
Companies storing only truncated card numbers
Organizations that never handle card data in any form
Cash-only businesses
Cryptocurrency-only payment systems

Is It Mandatory?

PCI DSS is not a law - it is a contractual requirement. When a merchant signs an agreement to accept credit cards, they agree to comply with PCI DSS. Non-compliance can result in fines from card brands ($5,000-$100,000/month), increased transaction fees, and ultimately losing the ability to accept card payments. Some jurisdictions (Nevada, Minnesota, Washington) have also enacted PCI-related laws.

The 12 Requirements (Overview)

Professional

PCI DSS v4.0 organizes requirements into 6 goals and 12 requirements: Build and Maintain a Secure Network (1. Install and maintain network security controls, 2. Apply secure configurations), Protect Account Data (3. Protect stored account data, 4. Protect data in transit with strong cryptography), Maintain a Vulnerability Management Program (5. Protect from malicious software, 6. Develop secure systems), Implement Strong Access Control (7. Restrict access by business need, 8. Identify users and authenticate, 9. Restrict physical access), Regularly Monitor and Test (10. Log and monitor access, 11. Test security regularly), Maintain a Policy (12. Support information security with organizational policies).

In Plain English

PCI DSS has 12 main rules organized into 6 common-sense goals: (1-2) Build a secure network with firewalls and proper settings. (3-4) Protect card data when stored and when sent over networks. (5-6) Keep systems updated and free from viruses. (7-8-9) Only let authorized people access card data. (10-11) Watch what happens and test your security regularly. (12) Have written security policies that everyone follows.

🧠Explain Like I'm 10

Imagine you have a secret diary (card data). The 12 rules are: (1-2) Lock your room and close the windows. (3-4) Keep the diary in a safe and use a secret code when sending pages to friends. (5-6) Check for bugs and keep your lock updated. (7-8-9) Only give the key to people who absolutely need it, make them prove who they are, and do not let strangers in your room. (10-11) Set up a camera and test your lock regularly. (12) Write down all the rules so everyone remembers them.

Practical Example

An e-commerce company processes 500,000 card transactions per year (Level 2 merchant). They must: segment their network so card data systems are isolated, encrypt card numbers in their database (AES-256), use TLS 1.2+ for all card data transmission, run quarterly vulnerability scans by an Approved Scanning Vendor (ASV), complete an annual Self-Assessment Questionnaire (SAQ D), and maintain an incident response plan.

Why Does This Rule Exist?

Before PCI DSS (pre-2004), each card brand had its own security program with different requirements. Merchants had to comply with multiple overlapping standards. PCI DSS unified these into one standard. It exists because data breaches at merchants and processors were (and still are) the primary source of stolen card data used for fraud.

Common Mistake

Thinking PCI DSS compliance means you are secure. PCI DSS is a minimum baseline - a floor, not a ceiling. Many breached organizations were PCI DSS compliant at their last assessment. Compliance is a point-in-time validation; security requires continuous vigilance. Also, compliance does not protect against all attack vectors - only those related to cardholder data.

Frequently Asked Questions

What are the PCI DSS compliance levels?

For merchants: Level 1 (>6 million transactions/year) requires annual on-site audit by a QSA. Level 2 (1-6 million) requires annual SAQ and quarterly ASV scans. Level 3 (20,000-1 million e-commerce) requires annual SAQ. Level 4 (<20,000 e-commerce or <1 million other) requires annual SAQ. Exact thresholds vary by card brand.

What is a QSA?

A Qualified Security Assessor (QSA) is a company certified by the PCI SSC to perform on-site PCI DSS assessments. QSA individuals must pass an exam and maintain certification annually. Only QSAs can issue a Report on Compliance (ROC) for Level 1 merchants and service providers.

What happens if card data is breached?

Consequences include: fines from card brands ($5,000-$500,000+ depending on severity), forensic investigation costs ($50,000-$500,000+), card reissuance costs charged back to the breached entity, potential lawsuits from affected cardholders, reputational damage, and possible loss of the ability to accept card payments.

Related Guides

Issuing organization: PCI Security Standards Council (PCI SSC)
Current version: PCI DSS v4.0.1 (June 2024)
Effective date: March 31, 2024 (v4.0 mandatory); March 31, 2025 (future-dated requirements)
Last reviewed: August 2026
Back to Finance