PCI DSS (Payment Card Industry Data Security Standard) is the security standard every organization that stores, processes, or transmits payment card data must follow. It's not a law — it's an industry requirement set by the major card brands, enforced through contracts with acquiring banks rather than government fines. The current version, PCI DSS 4.0.1, has been fully mandatory — including requirements that were previously optional — since March 2025.
The 12 requirements, grouped into 6 objectives
Build & Maintain a Secure Network
Req 1–2: network security controls and secure configurations on every system component.
Protect Account Data
Req 3–4: protect stored account data, and encrypt cardholder data in transit over open networks.
Manage Vulnerabilities
Req 5–6: protect against malicious software, and build and maintain secure systems and software.
Strong Access Control
Req 7–9: restrict access by need-to-know, authenticate every user, and restrict physical access.
Monitor & Test Regularly
Req 10–11: log and monitor all access, and test the security of systems and networks regularly.
Maintain a Security Policy
Req 12: support information security with organizational policies and programs.
Who actually has to comply
Any entity that stores, processes, or transmits cardholder data — merchants, payment processors, acquirers, issuers, and service providers. Obligations scale with volume through 4 merchant levels (Visa's framework; other card brands are broadly similar but not identical): Level 1 (over 6 million transactions/year) requires an annual on-site QSA audit and quarterly scans; Level 2 (1–6 million/year) and Level 3 (20,000–1 million e-commerce transactions/year) typically require an annual self-assessment questionnaire plus quarterly scans; Level 4 (under 20,000 e-commerce transactions/year) is the lightest tier, usually just an annual self-assessment.
What changed in version 4.0
Version 4.0 introduced 64 new requirements, 51 of which were "future-dated" with a grace period running until March 31, 2025. That deadline has now passed — every one of those requirements, including expanded multi-factor authentication scope, targeted risk analyses, and web-application anti-skimming controls, is now fully mandatory, not optional.
What happens if you're not compliant
Consequences flow through the payment chain rather than a government agency: fines from acquiring banks (commonly reported in the range of $5,000–$100,000+ per month of non-compliance, though this is contractual and varies by acquirer, not an official published schedule), increased transaction fees, being placed in a higher-risk merchant category, and potential loss of the ability to process card payments at all following a serious breach.