What Is PCI DSS?

PCI DSS (Payment Card Industry Data Security Standard) is the security standard every organization that stores, processes, or transmits payment card data must follow. It's not a law — it's an industry requirement set by the major card brands, enforced through contracts with acquiring banks rather than government fines. The current version, PCI DSS 4.0.1, has been fully mandatory — including requirements that were previously optional — since March 2025.

The 12 requirements, grouped into 6 objectives

Build & Maintain a Secure Network

Req 1–2: network security controls and secure configurations on every system component.

Protect Account Data

Req 3–4: protect stored account data, and encrypt cardholder data in transit over open networks.

Manage Vulnerabilities

Req 5–6: protect against malicious software, and build and maintain secure systems and software.

Strong Access Control

Req 7–9: restrict access by need-to-know, authenticate every user, and restrict physical access.

Monitor & Test Regularly

Req 10–11: log and monitor all access, and test the security of systems and networks regularly.

Maintain a Security Policy

Req 12: support information security with organizational policies and programs.

Who actually has to comply

Any entity that stores, processes, or transmits cardholder data — merchants, payment processors, acquirers, issuers, and service providers. Obligations scale with volume through 4 merchant levels (Visa's framework; other card brands are broadly similar but not identical): Level 1 (over 6 million transactions/year) requires an annual on-site QSA audit and quarterly scans; Level 2 (1–6 million/year) and Level 3 (20,000–1 million e-commerce transactions/year) typically require an annual self-assessment questionnaire plus quarterly scans; Level 4 (under 20,000 e-commerce transactions/year) is the lightest tier, usually just an annual self-assessment.

What changed in version 4.0

Version 4.0 introduced 64 new requirements, 51 of which were "future-dated" with a grace period running until March 31, 2025. That deadline has now passed — every one of those requirements, including expanded multi-factor authentication scope, targeted risk analyses, and web-application anti-skimming controls, is now fully mandatory, not optional.

What happens if you're not compliant

Consequences flow through the payment chain rather than a government agency: fines from acquiring banks (commonly reported in the range of $5,000–$100,000+ per month of non-compliance, though this is contractual and varies by acquirer, not an official published schedule), increased transaction fees, being placed in a higher-risk merchant category, and potential loss of the ability to process card payments at all following a serious breach.

Common Questions

Is PCI DSS a law?

No. It's an industry standard created and maintained by the PCI Security Standards Council (founded by Visa, Mastercard, Amex, Discover, and JCB). Compliance is enforced through merchant agreements with acquiring banks, not through government regulators.

What's the difference between PCI DSS 4.0 and 4.0.1?

4.0.1 (June 2024) is a minor clarification release of 4.0, not a new set of requirements. The bigger milestone was March 31, 2025, when 51 "future-dated" requirements introduced in 4.0 — like expanded multi-factor authentication and anti-skimming controls — became fully mandatory rather than optional.

Does PCI DSS apply to small businesses too?

Yes, though the compliance burden scales with transaction volume. A small e-commerce business (Level 4, under 20,000 transactions a year) typically only needs an annual self-assessment questionnaire, while a large Level 1 merchant needs a full annual on-site audit.

Want hands-on practice with control testing?

Try the GRC Track in CX Challenges, or get a personalized roadmap through 1:1 GRC mentorship.

Keep Reading

What Is HIPAA?

Another sector-specific standard, this one for US healthcare data.

What Is ISO 27001?

The broader international security standard many PCI-compliant organizations also hold.