Payments glossary · Compliance

PCI DSS

The Payment Card Industry Data Security Standard (PCI DSS) is the security standard for any organisation that stores, processes or transmits payment card data. The PCI Security Standards Council maintains it, while the card brands and acquirers enforce compliance.

How PCI DSS works

PCI DSS sets out 12 principal requirements covering network security, protection of stored account data, encryption in transit, vulnerability management, access control, logging and monitoring, testing and security policies. Version 4.0.1, published in June 2024, is the current version: v4.0 was retired at the end of 2024, and requirements that had been future-dated in v4.0 became mandatory from 31 March 2025.

The Council writes the standard, but each card brand decides who must validate compliance and how, usually through the merchant's acquirer. Most merchants complete a self-assessment questionnaire (SAQ) whose length depends on how they accept payments, while the largest usually need a formal assessment by a qualified security assessor. Non-compliance can lead to fines passed on by the acquirer and to liability for costs after a data breach.

The most effective way to reduce the burden is to reduce scope: use a hosted payment page or provider-hosted payment fields so card data never touches your servers, and store tokens rather than card numbers. E-commerce merchants using redirects or iframes still need to protect their own pages, because attackers target the scripts that load or link to the payment form.

Compare providers

Related terms

Sources

  1. PCI SSC blog: Just Published: PCI DSS v4.0.1
  2. PCI SSC: Merchant resources
  3. PCI SSC: Best Practices for Securing E-commerce (information supplement)

← All payments terms