Payment Card Industry Data Security Standard (PCI DSS)
Definition
Payment Card Industry Data Security Standard (PCI DSS)
The Payment Card Industry Data Security Standard (PCI DSS) is a set of 12 rules any firm that stores, processes, or sends card data must meet. It protects card data, cuts fraud loss, and forces safe handling across the whole payment chain.
Any merchant, payment processor, gateway, or service provider handling a Visa, Mastercard, Amex, Discover, or JCB card falls under PCI DSS.
The Payment Card Industry Security Standards Council (PCI SSC) writes the rules; the card brands enforce them through acquiring banks.
Version 4.0.1 became mandatory on 31 March 2025 and layered 51 new controls onto the framework. The PCI Security Standards Council targeted multi-factor authentication, phishing resistance, and script tracking on payment pages.
Failure to comply carries real teeth. Beyond monthly card-brand fines, a confirmed breach triggers forensic investigation by a PFI, higher transaction fees for months, and public disclosure obligations under state and national breach laws.
Key takeaways
- 12 core requirements cover network, access, monitoring, and policy controls.
- Any entity storing, processing, or transmitting cardholder data must comply.
- Version 4.0.1 became mandatory on 31 March 2025.
- Non-compliance fines run $5,000 to $100,000 per month per card brand.
- Outsourced payment vendors must prove PCI DSS compliance in writing.
How it works
PCI DSS groups its 12 requirements into six control objectives — build a secure network, protect stored data, run vulnerability management, control access, log everything, and keep a written policy. Each requirement carries testing procedures and validation rules.
| Objective group | Requirements | Focus |
|---|---|---|
| Build and maintain a secure network | 1, 2 | Firewalls, no default passwords |
| Protect cardholder data | 3, 4 | Storage and transmission |
| Vulnerability management | 5, 6 | Antivirus and secure development |
| Strong access control | 7, 8, 9 | Least privilege, physical access |
| Regular monitoring and testing | 10, 11 | Logging and penetration tests |
| Information security policy | 12 | Documented policy program |
Validation depends on transaction volume. As NIST’s computer security glossary notes, PCI DSS is a tiered assessment: Level 1 merchants (over 6 million card transactions a year) need a full QSA audit, while smaller tiers self-assess via SAQs.
Compliance drift is real. Verizon’s 2022 Payment Security Report found that only 43.4% of assessed organizations fully sustained PCI DSS compliance in 2020, down from a 55.4% peak in 2016.
Examples
Every business that handles a Visa or Mastercard number sits inside PCI DSS scope — from a corner cafe running a card reader to a global airline. The examples below show how the standard bites across different outsourcing profiles and transaction volumes.
Target 2013 breach. Hackers stole 40 million card records after infiltrating an HVAC vendor. Target had been assessed PCI DSS compliant that September; investigators later found segmentation gaps a strict review should catch, and Target paid $18.5 million to settle.
British Airways 2018 skimming attack. A Magecart script harvested 400,000 payment card details from the airline’s checkout page. The ICO fined BA £20 million in 2020, the largest UK data protection fine at the time — and cited PCI DSS gaps in script control.
Outsourced BPO payment desks. Manila contact centers handling US card orders operate as service providers under PCI DSS. They typically hold Level 1 status, complete an annual QSA audit, and share an Attestation of Compliance (AoC) with clients on request.
Home Depot 2014 breach. Malware on self-checkout terminals exposed 56 million card details across US stores. The retailer had a PCI DSS assessment in progress; the breach accelerated its migration to point-to-point encryption and EMV chip readers.
Related terms
- Compliance: the umbrella practice PCI DSS sits inside.
- Data security: the broader discipline of protecting information assets.
- GDPR: the EU personal-data rule PCI DSS-scoped EU merchants also must meet.
- HIPAA: the US health-data equivalent with a similar assessor model.
- SOC 2: the AICPA trust framework often paired with PCI DSS for BPOs.
- ISO 27001: the global information security management standard.
- Risk management: the parent process for scoping PCI DSS controls.
FAQ
Who has to comply with PCI DSS?
Any organization that stores, processes, or transmits branded credit card data must comply. That covers merchants, processors, gateways, service providers, and outsourced BPO call centers taking card orders. Volume sets assessment level, not whether the rules apply.
How much does PCI DSS non-compliance cost?
Card brands can fine acquiring banks $5,000 to $100,000 per month, and banks pass those fines to the merchant. Breach costs run much higher; Target’s 2013 exposure eventually cost more than $200 million once fines, forensics, and civil litigation were tallied.
What changed in PCI DSS v4.0.1?
Version 4.0.1 kept the 12 core requirements but added 51 future-dated controls covering multi-factor authentication for all access, targeted risk analyses, phishing defenses, and continuous script tracking on payment pages. Full enforcement began 31 March 2025.
Is PCI DSS a law?
No; PCI DSS is a contractual standard the card brands enforce through acquiring banks, not a government law.
Ready to hire a PCI DSS-compliant partner? Browse vetted outsourcing providers on the OA directory and shortlist ones that publish a current AoC.







Independent




