What is PCI DSS?
PCI DSS is the Payment Card Industry Data Security Standard: a set of 12 core requirements for any organization that stores, processes, or transmits cardholder data. The current version is PCI DSS v4.0.1.
Definition
PCI DSS (Payment Card Industry Data Security Standard) is a security standard maintained by the PCI Security Standards Council. It applies to every organization that stores, processes, or transmits cardholder data, and defines controls to protect that data.
Background
PCI DSS was created by the major card brands and is governed by the PCI Security Standards Council. The standard organizes controls into 12 requirements under six goals (build and maintain a secure network, protect account data, maintain a vulnerability management program, implement strong access control, monitor and test networks, and maintain an information security policy). The current version is PCI DSS v4.0.1. How you validate depends on your transaction volume and how you handle card data, ranging from a Self-Assessment Questionnaire (SAQ) to an audit by a Qualified Security Assessor.
Why it matters
If your business handles payment cards, PCI DSS is effectively mandatory: it is enforced through your contracts with acquirers and card brands. Failing to comply can mean fines and losing the ability to accept cards.
Step by step
- Determine how card data flows through your systems and where it is stored.
- Reduce scope wherever possible, for example by using a tokenizing payment processor so raw card data never touches your servers.
- Identify your merchant or service-provider level and the right SAQ or assessment path.
- Implement the 12 requirements across your in-scope environment.
- Validate (SAQ or QSA audit) and complete the attestation.
- Maintain the controls and re-validate on the required cadence.
Examples
- An e-commerce SMB uses a hosted payment page so cardholder data bypasses its servers, dramatically reducing PCI scope.
- A SaaS platform that stores card numbers must implement the full set of requirements and validate at a higher level.
Common mistakes
- Storing card data you don’t need, which expands scope and risk.
- Assuming a payment processor makes you automatically compliant; you still own the parts of the environment you control.
- Treating PCI as an annual event rather than continuous control operation.
FAQ
How many requirements does PCI DSS have?
Twelve core requirements, grouped under six goals. Each requirement contains detailed sub-requirements.
What is the current version of PCI DSS?
PCI DSS v4.0.1, published by the PCI Security Standards Council as the current standard.
Can I avoid full PCI scope?
Often, yes. Using a tokenizing or hosted payment provider so raw cardholder data never touches your systems can move you to a much smaller Self-Assessment Questionnaire.
Do this in Keel, not a spreadsheet
Keel is the AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.
Start free