PCI DSS
The security standard for handling payment-card data.
What it is
Maintained by the PCI Security Standards Council, PCI DSS is a framework for safely storing, processing, and transmitting cardholder data. Validation ranges from a Self-Assessment Questionnaire (SAQ) for smaller merchants to a Report on Compliance (ROC) by a QSA for large volumes.
Certifiable?
Validated compliance (SAQ or QSA-signed ROC), enforced by card brands/acquirers.
Where it's used
Any organization that touches cardholder data, worldwide.
Effort level
Scales with card volume and how much you can descope (e.g., via a payment processor).
Typical trigger
You start accepting or processing card payments.
Related frameworks
Overlaps with CIS/ISO on the technical controls, but is payment-specific.
Why it matters
PCI DSS protects payment-card data throughout its lifecycle. Compliance isn't optional if you process cards — the card brands enforce it, and breaches carry severe financial penalties, liability, and loss of the ability to process payments.
When is it needed?
As soon as your systems store, process, or transmit cardholder data. Even if you use a payment processor, you likely have some PCI DSS obligations depending on your integration method.
Use cases
- E-commerce platforms processing payments
- Payment service providers and gateways
- Retail and hospitality point-of-sale environments
- SaaS platforms with payment features
- Any business handling card-present or card-not-present transactions
Who asks for it?
- Card brands (Visa, Mastercard, Amex, Discover)
- Acquiring banks and payment processors
- Merchant service providers
- Qualified Security Assessors (QSAs)
- Customers trusting you with their card data
Benefits
- Protects against payment-data breaches and associated liability
- Required to maintain the ability to process card payments
- Well-defined scope reduction techniques (tokenization, P2PE)
- SAQ options for smaller merchants reduce assessment burden
- Mature ecosystem of tools, assessors, and guidance
- Clear, prescriptive requirements with testing procedures
Legal requirements
Mandated contractually by card brands through merchant agreements. While not a government law, failure to comply results in fines, increased transaction fees, and potential loss of card-processing privileges.
Key control areas
Want to see how Compscan maps your environment to PCI DSS?