PCI Compliance
Definition
PCI Compliance
PCI compliance is the mandatory security standard that any organization storing, processing, or transmitting cardholder data must meet. Set by the PCI Security Standards Council, the framework — known formally as PCI DSS — covers six control objectives, 12 core requirements, and roughly 400 sub-tests that keep card numbers, CVVs, and PINs out of criminal hands.
Every retailer, SaaS platform, call center, and outsourcing provider that touches a Visa, Mastercard, Amex, Discover, or JCB transaction sits inside PCI’s scope. Miss the mark and you’re exposed to fines from card brands, forensic audit costs, and reputational damage that lingers long after the breach headline fades.
The good news: PCI DSS v4.0.1 (published in June 2024) is prescriptive. You can read the requirements, map them to your stack, and hire (or outsource to) teams that already run inside the fence.
Key takeaways
- PCI DSS v4.0.1 is enforced globally by the PCI Security Standards Council; the future-dated requirements became mandatory on 31 March 2025.
- Merchants fall into four levels, from Level 1 (>6M card transactions per year) down to Level 4 (<20k e-commerce transactions).
- IBM’s 2024 Cost of a Data Breach report put the average retail breach at $3.48M, a number that dwarfs the cost of annual compliance.
- Non-compliance fines run from $5,000 to $100,000 per month, levied by acquiring banks and card brands.
- Certified BPO providers in the Philippines, India, and Colombia let merchants outsource card-handling processes without dragging their entire back office into PCI scope.
How it works
PCI compliance works by translating six control objectives into 12 numbered requirements that every in-scope entity must meet, then proving that meeting through annual assessments, quarterly ASV scans, and continuous monitoring.
The 12 requirements group under these six objectives:
- Build and maintain a secure network: install firewalls, kill vendor default passwords.
- Protect cardholder data: encrypt stored data, encrypt anything crossing public networks.
- Maintain a vulnerability management program: antivirus, secure code, timely patching.
- Implement strong access control: need-to-know access, unique IDs, physical restriction.
- Regularly monitor and test networks: log everything, run quarterly external scans, penetration test yearly.
- Maintain an information security policy: a documented, staff-trained policy that covers every worker who touches card data.
Assessment method depends on merchant level. Level 1 merchants file a Report on Compliance (ROC) signed by a Qualified Security Assessor (QSA). Levels 2–4 usually complete a Self-Assessment Questionnaire (SAQ) matched to how they accept payments. Everyone submits an Attestation of Compliance to their acquiring bank once a year.
Version 4.0.1 added targeted risk analyses, multi-factor authentication for all access into the cardholder data environment, and expanded requirements around scripts on payment pages — a direct response to the Magecart-style skimming attacks that hit British Airways and Ticketmaster.
Examples
Compliance looks different at each scale. These four snapshots show how retailers, platforms, and outsourced teams meet the same standard.
- Amazon (Level 1 merchant, 2024): Amazon Web Services publishes an annual PCI DSS Attestation of Compliance that downstream merchants inherit for infrastructure controls, letting AWS-hosted stores narrow their own audit scope.
- Stripe (payment processor, ongoing): Stripe operates as a PCI Level 1 Service Provider, so merchants using Stripe Elements or Checkout can attest via SAQ A, the shortest questionnaire in the family, roughly 22 controls versus SAQ D’s 300+.
- Concentrix (BPO, 2024): The global contact-center operator maintains PCI DSS certification across delivery sites in the Philippines, India, and Nicaragua so brands can outsource card-not-present order taking without expanding their own compliance footprint.
- British Airways (breach, 2018): A Magecart script on the airline’s payment page exfiltrated 380,000 card records; the UK ICO’s initial £183M fine was later reduced to £20M, and BA’s remediation is now cited as the textbook case for PCI DSS v4.0’s new script-integrity rules.
Related terms
PCI DSS overlaps with several adjacent frameworks. Learn how they interlock:
- Data security: the broader discipline PCI DSS applies to card data specifically.
- Cybersecurity: the umbrella practice; PCI is one sector-specific standard inside it.
- GDPR: EU privacy law that governs personal data (including card details) alongside PCI DSS.
- Business process outsourcing: the delivery model many merchants use to move card-handling into a certified provider.
- Call center: the operation most often in PCI scope inside a BPO contract.
- KYC (know your customer): a parallel compliance regime for identity verification, often audited beside PCI in financial services.
FAQ
Who has to be PCI compliant?
Any merchant, processor, acquirer, issuer, or service provider that stores, processes, or transmits cardholder data. It doesn’t matter if you take one card a year or one million — you’re in scope.
How much does PCI compliance cost?
Costs scale with merchant level. Level 4 merchants can self-assess for under $5,000 a year; a Level 1 retailer with a QSA-signed ROC, quarterly ASV scans, and penetration testing typically spends $70,000–$250,000 annually.
What happens if you fail PCI compliance?
Acquiring banks pass through fines of $5,000–$100,000 per month until you remediate. You can also lose your merchant account, face card-brand-driven forensic audits, and pay per-record damages under state or national data-protection laws if a breach occurs.
Can PCI compliance be outsourced?
Yes. Payment processors like Stripe or Adyen absorb most of the technical scope, and PCI-certified BPO providers can take over voice-order capture, chargeback handling, and dispute processing so cardholder data never touches your systems.
How often is PCI DSS updated?
The PCI SSC publishes major versions roughly every three to four years, with minor point releases in between. Version 4.0 landed in March 2022, 4.0.1 in June 2024, and the transition deadline for new requirements closed on 31 March 2025.
Ready to move card-handling work to a certified partner? Start with the Outsource Accelerator hubs directory to shortlist providers by country, function, and compliance credential.







Independent




