PCI DSS for retail and ecommerce
PCI DSS 4.0.1 applies to any retailer or ecommerce business that stores, processes, or transmits cardholder data. For most merchants the practical goal is to reduce how much of your environment touches card data.
Why it matters for retail and ecommerce
Card networks require PCI DSS compliance to accept payments. For retail and ecommerce, non-compliance risks fines and losing the ability to take card payments, which is existential for a store.
What to focus on
Using a compliant payment processor, hosted payment pages, and tokenization keeps most of your systems out of scope. The less of your environment that touches card data, the smaller and cheaper your assessment.
PCI DSS groups controls into 12 requirements spanning network security, protecting cardholder data, vulnerability management, access control, monitoring, and policy. Many overlap with general security hygiene.
Your transaction volume sets your merchant level, which determines whether you validate with a Self-Assessment Questionnaire or a full Report on Compliance. Your acquiring bank confirms which applies.
Do it once, not twice
Keel is built on one crosswalked control library, so a control you implement for PCI DSS counts toward every other framework it satisfies. Add a second framework later and it mostly reuses this work. See the crosswalk explorer for the exact overlap.
Start free Check your readinessCommon questions
How do retailers lower PCI DSS cost?
By reducing scope: use a PCI-compliant processor and tokenization so your own systems rarely touch raw card data. Less scope means a simpler assessment and lower ongoing cost.
Which PCI DSS version applies?
PCI DSS 4.0.1 is the current version. Keel authors its PCI DSS content against 4.0 (requirements unchanged in 4.0.1).
Framework names are referenced factually for guidance. Keel is not affiliated with or endorsed by the bodies that publish them. See our legal and trademarks page.