PCI Compliance
Definition
PCI Compliance
Payment Card Industry (PCI) compliance is the security standard firms that store, send, or handle card data must meet. The PCI Security Standards Council writes it, and card brands enforce it through your bank. Scope starts at your first card sale.
The formal name is the Payment Card Industry Data Security Standard, better known as PCI DSS. Version 4.0.1 landed in June 2024. It sorts six control objectives into 12 requirements and roughly 400 sub-tests.
Every retailer, software platform, call center, and outsourcing provider that touches a Visa, Mastercard, Amex, Discover, or JCB payment sits in scope. Miss the mark and you pay in fines, forensic audits, and lost trust.
The upside is that PCI DSS reads like a checklist rather than a philosophy — you can map each requirement to your stack, then hire or outsource to teams that already work inside the fence.
Key takeaways
- PCI DSS v4.0.1 is enforced worldwide by the PCI Security Standards Council, and the future-dated requirements became mandatory on 31 March 2025.
- Merchants sit in four levels, from Level 1 at more than 6 million card transactions a year down to Level 4 at under 20,000 e-commerce transactions.
- IBM’s 2024 Cost of a Data Breach report put the average retail breach at $3.48 million, a figure that dwarfs the cost of staying compliant.
- Non-compliance fines run from $5,000 to $100,000 a month, levied by acquiring banks and passed down from the card brands.
- Certified providers in the Philippines, India, and Colombia let merchants move card handling offshore without dragging the whole back office into scope.
How it works
PCI compliance works by turning six control objectives into 12 numbered requirements, then proving you meet them. Proof comes through an annual assessment, quarterly scans by an Approved Scanning Vendor, and monitoring that runs every day of the year.
- Build a secure network: install firewalls and kill vendor default passwords.
- Protect cardholder data: encrypt what you store and anything crossing public networks.
- Manage vulnerabilities: antivirus, secure code, and patching on a clock.
- Control access: need-to-know permissions, unique IDs, and physical restriction.
- Monitor and test: log everything, scan quarterly, run a penetration test each year.
- Keep a security policy: documented, trained, and binding on everyone near card data.
Assessment depth tracks merchant level — the table below shows what each tier files and who signs it off.
| Merchant level | Annual card transactions | Validation path | Signed off by |
|---|---|---|---|
| Level 1 | Over 6 million | Report on Compliance plus quarterly ASV scans | Qualified Security Assessor |
| Level 2 | 1 million to 6 million | Self-Assessment Questionnaire plus ASV scans | Internal assessor or QSA |
| Level 3 | 20,000 to 1 million e-commerce | Self-Assessment Questionnaire plus ASV scans | Merchant officer |
| Level 4 | Under 20,000 e-commerce | Self-Assessment Questionnaire | Merchant officer |
Everyone files an Attestation of Compliance with their acquiring bank once a year. The blank forms and reporting templates sit in the Council’s document library, matched to how you take payments.
Version 4.0.1 added targeted risk analyses, multi-factor authentication for every route into the cardholder data environment, and script integrity rules for payment pages.
Those script rules answer the Magecart style skimming that hit British Airways and Ticketmaster. The PCI DSS v4.0.1 standard published by the PCI Security Standards Council sets out every control in full.
Version 4.0 arrived in March 2022, 4.0.1 followed in June 2024, and the transition deadline for future-dated requirements closed on 31 March 2025. Anything marked best practice before that date is now mandatory.
Scope shrinks when card data does. Tokenizing the number at capture, routing calls through a hosted payment page, or pushing the transaction to a certified processor pulls whole systems out of the assessment.
Card data rarely travels alone. Firms that also handle health records run PCI DSS beside the Health Insurance Portability and Accountability Act (HIPAA), and most feed alerts into a security operations center.
Examples
Compliance looks different at every scale. A cloud host, a payment processor, an outsourced contact center, and a breached airline all sit under the same standard, yet each proves it a different way. Here are four.
Amazon Web Services (Level 1, 2024). AWS publishes an annual PCI DSS Attestation of Compliance that hosted merchants inherit for infrastructure controls, which narrows a store’s own audit to its application layer.
Stripe (Level 1 service provider). Merchants using Stripe Elements or Checkout can attest with SAQ A, the shortest questionnaire in the family at roughly 22 controls against SAQ D’s 300 plus.
Concentrix (business process outsourcing, 2024). The contact center operator holds PCI DSS certification across delivery sites in the Philippines, India, and Nicaragua, so brands can outsource phone order taking without widening their own compliance footprint.
British Airways (breach, 2018). A Magecart script on the airline’s payment page took 380,000 card records. The UK Information Commissioner’s Office cut its initial £183 million fine to £20 million — and the case now anchors the script integrity rules.
The money argument settles it — IBM’s 2024 Cost of a Data Breach report put the average retail breach at $3.48 million, while a Level 4 merchant self-assesses for under $5,000 a year.
Related terms
PCI DSS does not sit alone. It overlaps with broader security practice, with privacy law, and with the outsourcing models merchants use to keep card data off their own systems. These six terms are the ones you will meet first.
- Data Security: the broader discipline that PCI DSS applies to card data specifically.
- Cybersecurity: the umbrella practice that holds PCI DSS as one sector standard among many.
- General Data Protection Regulation (GDPR): the European privacy law that governs personal data, card details included.
- Business Process Outsourcing: the delivery model merchants use to move card handling into a certified provider.
- Call Center: the operation most often pulled into PCI scope inside a BPO contract.
- Know Your Customer (KYC): the parallel identity check regime that financial firms audit beside PCI DSS.
FAQ
Who has to be PCI compliant?
Any merchant, processor, acquirer, issuer, or service provider that stores, processes, or transmits cardholder data. One card a year or one million, you are in scope either way.
How much does PCI compliance cost?
Cost tracks merchant level. A Level 4 merchant can self-assess for under $5,000 a year. A Level 1 retailer paying for a QSA-signed Report on Compliance, quarterly ASV scans, and penetration testing usually spends $70,000 to $250,000.
What happens if you fail PCI compliance?
Acquiring banks pass through fines of $5,000 to $100,000 a month until you remediate. You can also lose the merchant account and face a card brand forensic audit. A breach on top of that brings per-record damages under data protection law.
Can PCI compliance be outsourced?
Yes. Processors such as Stripe or Adyen absorb most of the technical scope, and certified BPO providers can take over voice order capture, chargeback handling, and dispute processing. Cardholder data then never lands in your own systems.
How often is PCI DSS updated?
The Council ships a major version every three to four years, with point releases in between.
Ready to move card handling to a certified partner? Start with the Outsource Accelerator hubs directory to shortlist providers by country and credential.







Independent




