• 4,000 firms
  • Independent
  • Trusted
Save up to 70% on staff

Home » Glossary » Payment Card Industry Data Security Standard (PCI DSS)

Payment Card Industry Data Security Standard (PCI DSS)

Definition

Payment Card Industry Data Security Standard (PCI DSS)

The Payment Card Industry Data Security Standard (PCI DSS) is a set of 12 rules any firm that stores, processes, or sends card data must meet. It protects card data, cuts fraud loss, and forces safe handling across the whole payment chain.

Any merchant, payment processor, gateway, or service provider handling a Visa, Mastercard, Amex, Discover, or JCB card falls under PCI DSS.

The Payment Card Industry Security Standards Council (PCI SSC) writes the rules; the card brands enforce them through acquiring banks.

Version 4.0.1 became mandatory on 31 March 2025 and layered 51 new controls onto the framework. The PCI Security Standards Council targeted multi-factor authentication, phishing resistance, and script tracking on payment pages.

Failure to comply carries real teeth. Beyond monthly card-brand fines, a confirmed breach triggers forensic investigation by a PFI, higher transaction fees for months, and public disclosure obligations under state and national breach laws.

Key takeaways

  • 12 core requirements cover network, access, monitoring, and policy controls.
  • Any entity storing, processing, or transmitting cardholder data must comply.
  • Version 4.0.1 became mandatory on 31 March 2025.
  • Non-compliance fines run $5,000 to $100,000 per month per card brand.
  • Outsourced payment vendors must prove PCI DSS compliance in writing.

How it works

PCI DSS groups its 12 requirements into six control objectives — build a secure network, protect stored data, run vulnerability management, control access, log everything, and keep a written policy. Each requirement carries testing procedures and validation rules.

Objective groupRequirementsFocus
Build and maintain a secure network1, 2Firewalls, no default passwords
Protect cardholder data3, 4Storage and transmission
Vulnerability management5, 6Antivirus and secure development
Strong access control7, 8, 9Least privilege, physical access
Regular monitoring and testing10, 11Logging and penetration tests
Information security policy12Documented policy program

Validation depends on transaction volume. As NIST’s computer security glossary notes, PCI DSS is a tiered assessment: Level 1 merchants (over 6 million card transactions a year) need a full QSA audit, while smaller tiers self-assess via SAQs.

Compliance drift is real. Verizon’s 2022 Payment Security Report found that only 43.4% of assessed organizations fully sustained PCI DSS compliance in 2020, down from a 55.4% peak in 2016.

Examples

Every business that handles a Visa or Mastercard number sits inside PCI DSS scope — from a corner cafe running a card reader to a global airline. The examples below show how the standard bites across different outsourcing profiles and transaction volumes.

Target 2013 breach. Hackers stole 40 million card records after infiltrating an HVAC vendor. Target had been assessed PCI DSS compliant that September; investigators later found segmentation gaps a strict review should catch, and Target paid $18.5 million to settle.

British Airways 2018 skimming attack. A Magecart script harvested 400,000 payment card details from the airline’s checkout page. The ICO fined BA £20 million in 2020, the largest UK data protection fine at the time — and cited PCI DSS gaps in script control.

Outsourced BPO payment desks. Manila contact centers handling US card orders operate as service providers under PCI DSS. They typically hold Level 1 status, complete an annual QSA audit, and share an Attestation of Compliance (AoC) with clients on request.

Home Depot 2014 breach. Malware on self-checkout terminals exposed 56 million card details across US stores. The retailer had a PCI DSS assessment in progress; the breach accelerated its migration to point-to-point encryption and EMV chip readers.

Related terms

  • Compliance: the umbrella practice PCI DSS sits inside.
  • Data security: the broader discipline of protecting information assets.
  • GDPR: the EU personal-data rule PCI DSS-scoped EU merchants also must meet.
  • HIPAA: the US health-data equivalent with a similar assessor model.
  • SOC 2: the AICPA trust framework often paired with PCI DSS for BPOs.
  • ISO 27001: the global information security management standard.
  • Risk management: the parent process for scoping PCI DSS controls.

FAQ

Who has to comply with PCI DSS?

Any organization that stores, processes, or transmits branded credit card data must comply. That covers merchants, processors, gateways, service providers, and outsourced BPO call centers taking card orders. Volume sets assessment level, not whether the rules apply.

How much does PCI DSS non-compliance cost?

Card brands can fine acquiring banks $5,000 to $100,000 per month, and banks pass those fines to the merchant. Breach costs run much higher; Target’s 2013 exposure eventually cost more than $200 million once fines, forensics, and civil litigation were tallied.

What changed in PCI DSS v4.0.1?

Version 4.0.1 kept the 12 core requirements but added 51 future-dated controls covering multi-factor authentication for all access, targeted risk analyses, phishing defenses, and continuous script tracking on payment pages. Full enforcement began 31 March 2025.

Is PCI DSS a law?

No; PCI DSS is a contractual standard the card brands enforce through acquiring banks, not a government law.

Ready to hire a PCI DSS-compliant partner? Browse vetted outsourcing providers on the OA directory and shortlist ones that publish a current AoC.

Companies you might be interested in

Get Inside Outsourcing

An insider's view on why remote and offshore staffing is radically changing the future of work.

Order now

Start your
journey today

  • Independent
  • Secure
  • Transparent

About OA

Outsource Accelerator is the trusted source of independent information, advisory and expert implementation of Business Process Outsourcing (BPO).

The #1 outsourcing authority

Outsource Accelerator offers the world’s leading aggregator marketplace for outsourcing. It specifically provides the conduit between world-leading outsourcing suppliers and the businesses – clients – across the globe.

The Outsource Accelerator website has over 5,000 articles, 450+ podcast episodes, and a comprehensive directory with 4,700+ BPO companies… all designed to make it easier for clients to learn about – and engage with – outsourcing.

About Derek Gallimore

Derek Gallimore has been in business for 20 years, outsourcing for over eight years, and has been living in Manila (the heart of global outsourcing) since 2014. Derek is the founder and CEO of Outsource Accelerator, and is regarded as a leading expert on all things outsourcing.

“Excellent service for outsourcing advice and expertise for my business.”

Learn more
Banner Image
Get 3 Free Quotes Verified Outsourcing Suppliers
4,000 firms.Just 2 minutes to complete.
SAVE UP TO
70% ON STAFF COSTS
Learn more

Connect with over 4,000 outsourcing services providers.

Banner Image

Transform your business with skilled offshore talent.

  • 4,000 firms
  • Simple
  • Transparent
Banner Image