Skip to content
09/14StandardOut of scope

PCI DSS

The security standard for handling payment-card data.

What it is

Maintained by the PCI Security Standards Council, PCI DSS is a framework for safely storing, processing, and transmitting cardholder data. Validation ranges from a Self-Assessment Questionnaire (SAQ) for smaller merchants to a Report on Compliance (ROC) by a QSA for large volumes.

Certifiable?

Validated compliance (SAQ or QSA-signed ROC), enforced by card brands/acquirers.

Where it's used

Any organization that touches cardholder data, worldwide.

Effort level

Scales with card volume and how much you can descope (e.g., via a payment processor).

Typical trigger

You start accepting or processing card payments.

Related frameworks

Overlaps with CIS/ISO on the technical controls, but is payment-specific.

Why it matters

PCI DSS protects payment-card data throughout its lifecycle. Compliance isn't optional if you process cards — the card brands enforce it, and breaches carry severe financial penalties, liability, and loss of the ability to process payments.

When is it needed?

As soon as your systems store, process, or transmit cardholder data. Even if you use a payment processor, you likely have some PCI DSS obligations depending on your integration method.

Use cases

  • E-commerce platforms processing payments
  • Payment service providers and gateways
  • Retail and hospitality point-of-sale environments
  • SaaS platforms with payment features
  • Any business handling card-present or card-not-present transactions

Who asks for it?

  • Card brands (Visa, Mastercard, Amex, Discover)
  • Acquiring banks and payment processors
  • Merchant service providers
  • Qualified Security Assessors (QSAs)
  • Customers trusting you with their card data

Benefits

  • Protects against payment-data breaches and associated liability
  • Required to maintain the ability to process card payments
  • Well-defined scope reduction techniques (tokenization, P2PE)
  • SAQ options for smaller merchants reduce assessment burden
  • Mature ecosystem of tools, assessors, and guidance
  • Clear, prescriptive requirements with testing procedures

Legal requirements

Mandated contractually by card brands through merchant agreements. While not a government law, failure to comply results in fines, increased transaction fees, and potential loss of card-processing privileges.

Key control areas

Build and maintain a secure network (firewalls, no defaults)
Protect cardholder data (encryption, key management)
Maintain a vulnerability management program
Implement strong access control measures
Regularly monitor and test networks
Maintain an information security policy

Want to see how Compscan maps your environment to PCI DSS?