• 4,000 firms
  • Independent
  • Trusted
Save up to 70% on staff

Home » Glossary » PCI Compliance

PCI Compliance

Definition

PCI Compliance

Payment Card Industry (PCI) compliance is the security standard firms that store, send, or handle card data must meet. The PCI Security Standards Council writes it, and card brands enforce it through your bank. Scope starts at your first card sale.

The formal name is the Payment Card Industry Data Security Standard, better known as PCI DSS. Version 4.0.1 landed in June 2024. It sorts six control objectives into 12 requirements and roughly 400 sub-tests.

Every retailer, software platform, call center, and outsourcing provider that touches a Visa, Mastercard, Amex, Discover, or JCB payment sits in scope. Miss the mark and you pay in fines, forensic audits, and lost trust.

The upside is that PCI DSS reads like a checklist rather than a philosophy — you can map each requirement to your stack, then hire or outsource to teams that already work inside the fence.

Key takeaways

  • PCI DSS v4.0.1 is enforced worldwide by the PCI Security Standards Council, and the future-dated requirements became mandatory on 31 March 2025.
  • Merchants sit in four levels, from Level 1 at more than 6 million card transactions a year down to Level 4 at under 20,000 e-commerce transactions.
  • IBM’s 2024 Cost of a Data Breach report put the average retail breach at $3.48 million, a figure that dwarfs the cost of staying compliant.
  • Non-compliance fines run from $5,000 to $100,000 a month, levied by acquiring banks and passed down from the card brands.
  • Certified providers in the Philippines, India, and Colombia let merchants move card handling offshore without dragging the whole back office into scope.

How it works

PCI compliance works by turning six control objectives into 12 numbered requirements, then proving you meet them. Proof comes through an annual assessment, quarterly scans by an Approved Scanning Vendor, and monitoring that runs every day of the year.

  • Build a secure network: install firewalls and kill vendor default passwords.
  • Protect cardholder data: encrypt what you store and anything crossing public networks.
  • Manage vulnerabilities: antivirus, secure code, and patching on a clock.
  • Control access: need-to-know permissions, unique IDs, and physical restriction.
  • Monitor and test: log everything, scan quarterly, run a penetration test each year.
  • Keep a security policy: documented, trained, and binding on everyone near card data.

Assessment depth tracks merchant level — the table below shows what each tier files and who signs it off.

Merchant levelAnnual card transactionsValidation pathSigned off by
Level 1Over 6 millionReport on Compliance plus quarterly ASV scansQualified Security Assessor
Level 21 million to 6 millionSelf-Assessment Questionnaire plus ASV scansInternal assessor or QSA
Level 320,000 to 1 million e-commerceSelf-Assessment Questionnaire plus ASV scansMerchant officer
Level 4Under 20,000 e-commerceSelf-Assessment QuestionnaireMerchant officer

Everyone files an Attestation of Compliance with their acquiring bank once a year. The blank forms and reporting templates sit in the Council’s document library, matched to how you take payments.

Version 4.0.1 added targeted risk analyses, multi-factor authentication for every route into the cardholder data environment, and script integrity rules for payment pages.

Those script rules answer the Magecart style skimming that hit British Airways and Ticketmaster. The PCI DSS v4.0.1 standard published by the PCI Security Standards Council sets out every control in full.

Version 4.0 arrived in March 2022, 4.0.1 followed in June 2024, and the transition deadline for future-dated requirements closed on 31 March 2025. Anything marked best practice before that date is now mandatory.

Scope shrinks when card data does. Tokenizing the number at capture, routing calls through a hosted payment page, or pushing the transaction to a certified processor pulls whole systems out of the assessment.

Card data rarely travels alone. Firms that also handle health records run PCI DSS beside the Health Insurance Portability and Accountability Act (HIPAA), and most feed alerts into a security operations center.

Examples

Compliance looks different at every scale. A cloud host, a payment processor, an outsourced contact center, and a breached airline all sit under the same standard, yet each proves it a different way. Here are four.

Amazon Web Services (Level 1, 2024). AWS publishes an annual PCI DSS Attestation of Compliance that hosted merchants inherit for infrastructure controls, which narrows a store’s own audit to its application layer.

Stripe (Level 1 service provider). Merchants using Stripe Elements or Checkout can attest with SAQ A, the shortest questionnaire in the family at roughly 22 controls against SAQ D’s 300 plus.

Concentrix (business process outsourcing, 2024). The contact center operator holds PCI DSS certification across delivery sites in the Philippines, India, and Nicaragua, so brands can outsource phone order taking without widening their own compliance footprint.

British Airways (breach, 2018). A Magecart script on the airline’s payment page took 380,000 card records. The UK Information Commissioner’s Office cut its initial £183 million fine to £20 million — and the case now anchors the script integrity rules.

The money argument settles it — IBM’s 2024 Cost of a Data Breach report put the average retail breach at $3.48 million, while a Level 4 merchant self-assesses for under $5,000 a year.

Related terms

PCI DSS does not sit alone. It overlaps with broader security practice, with privacy law, and with the outsourcing models merchants use to keep card data off their own systems. These six terms are the ones you will meet first.

FAQ

Who has to be PCI compliant?

Any merchant, processor, acquirer, issuer, or service provider that stores, processes, or transmits cardholder data. One card a year or one million, you are in scope either way.

How much does PCI compliance cost?

Cost tracks merchant level. A Level 4 merchant can self-assess for under $5,000 a year. A Level 1 retailer paying for a QSA-signed Report on Compliance, quarterly ASV scans, and penetration testing usually spends $70,000 to $250,000.

What happens if you fail PCI compliance?

Acquiring banks pass through fines of $5,000 to $100,000 a month until you remediate. You can also lose the merchant account and face a card brand forensic audit. A breach on top of that brings per-record damages under data protection law.

Can PCI compliance be outsourced?

Yes. Processors such as Stripe or Adyen absorb most of the technical scope, and certified BPO providers can take over voice order capture, chargeback handling, and dispute processing. Cardholder data then never lands in your own systems.

How often is PCI DSS updated?

The Council ships a major version every three to four years, with point releases in between.

Ready to move card handling to a certified partner? Start with the Outsource Accelerator hubs directory to shortlist providers by country and credential.

Companies you might be interested in

Get Inside Outsourcing

An insider's view on why remote and offshore staffing is radically changing the future of work.

Order now

Start your
journey today

  • Independent
  • Secure
  • Transparent

About OA

Outsource Accelerator is the trusted source of independent information, advisory and expert implementation of Business Process Outsourcing (BPO).

The #1 outsourcing authority

Outsource Accelerator offers the world’s leading aggregator marketplace for outsourcing. It specifically provides the conduit between world-leading outsourcing suppliers and the businesses – clients – across the globe.

The Outsource Accelerator website has over 5,000 articles, 450+ podcast episodes, and a comprehensive directory with 4,700+ BPO companies… all designed to make it easier for clients to learn about – and engage with – outsourcing.

About Derek Gallimore

Derek Gallimore has been in business for 20 years, outsourcing for over eight years, and has been living in Manila (the heart of global outsourcing) since 2014. Derek is the founder and CEO of Outsource Accelerator, and is regarded as a leading expert on all things outsourcing.

“Excellent service for outsourcing advice and expertise for my business.”

Learn more
Banner Image
Get 3 Free Quotes Verified Outsourcing Suppliers
4,000 firms.Just 2 minutes to complete.
SAVE UP TO
70% ON STAFF COSTS
Learn more

Connect with over 4,000 outsourcing services providers.

Banner Image

Transform your business with skilled offshore talent.

  • 4,000 firms
  • Simple
  • Transparent
Banner Image