What is PCI DSS and who must comply with it?
PCI DSS stands for Payment Card Industry Data Security Standard. It is a set of requirements designed to ensure that all companies that accept, process, store, or transmit credit card information maintain a secure environment. Compliance with PCI DSS is mandatory for QSAs [1], and entities that handle cardholder data, such as e-commerce merchants [2, 4], must adhere to its standards. The standard provides a framework for protecting cardholder data and includes requirements for security management, policies, procedures, network architecture, software design, and other critical protective measures.
5 verified sources
What changed in PCI DSS v4.0.1?
The context indicates that PCI DSS v4.0.1 was published on 11 June 2024 and is a limited revision with no new requirements added or removed compared to v4.0. Therefore, there were no changes in requirements between v4.0 and v4.0.1. [1]
5 verified sources
What is the PCI DSS v4.0.1 effective date and what are the key deadlines?
The PCI DSS v4.0.1 effective date is 31 March 2025. Key deadlines include:
- Future-dated v4.x requirements becoming mandatory in assessments from 31 March 2025 [1].
The last-verified date for this information is 2026-08-01.
5 verified sources
When did the future-dated PCI DSS v4.0 requirements become mandatory?
The future-dated PCI DSS v4.0 requirements became mandatory in assessments from 31 March 2025. [1]
5 verified sources
What are the PCI DSS merchant levels?
PCI DSS merchant levels are classified by Visa into four levels based on annual transaction volume:
- Level 1: More than 6 million Visa transactions per year across all channels (or any merchant designated Level 1 by Visa, e.g., after a compromise) - annual on-site assessment and Report on Compliance (ROC) plus quarterly network scan. [2]
- Level 2: 1 to 6 million transactions per year - annual Self-Assessment Questionnaire (SAQ) and quarterly scan. [2]
- Level 3: 20,000 to 1 million Visa e-commerce transactions per year - SAQ and quarterly scan. [2]
- Level 4: Fewer than 20,000 Visa e-commerce transactions, or up to 1 million total transactions per year - SAQ and scan as required by the acquirer. [2]
Other card brands set broadly similar but not identical thresholds; the acquirer confirms a merchant's level. [2]
5 verified sources
What are the PCI DSS SAQ types and when is a ROC required instead?
PCI DSS defines nine SAQ types, each scoped to how a merchant handles cardholder data:
- SAQ A (fully outsourced e-commerce or mail/telephone order, no data handling)
- SAQ A-EP (e-commerce that partially controls the payment page)
- SAQ B (imprint machines or standalone dial-out terminals, no electronic storage)
- SAQ B-IP (standalone PTS-approved IP-connected terminals)
- SAQ C-VT (web-based virtual terminal, one transaction at a time)
- SAQ C (payment application connected to the internet)
- SAQ P2PE (hardware terminals in a validated PCI P2PE solution)
- SAQ D for Merchants (all others that store, process or transmit cardholder data - the most comprehensive)
- SAQ D for Service Providers (applies to service providers)
A merchant who cannot meet an SAQ's eligibility criteria, or who is a Level 1 merchant, completes a full Report on Compliance (ROC) instead of an SAQ [1].
5 verified sources
What are the 12 requirements of PCI DSS?
The 12 requirements of PCI DSS are:
1. Build and maintain a secure network.
2. Build and maintain secure systems and applications.
3. Protect cardholder data.
4. Encrypt cardholder data during transmission over open, public networks.
5. Develop and maintain secure systems and applications.
6. Maintain a vulnerability management program.
7. Implement strong access control measures.
8. Regularly monitor and test networks.
9. Maintain a policy that addresses information security for employees and contractors.
10. Track and monitor all access to network resources and cardholder data.
11. Regularly test security systems and processes.
12. Maintain a written information security policy.
These requirements are structured under six goals as outlined in PCI DSS v4.0.1, which was published in June 2024. [1]
5 verified sources
What is PCI PIN Security?
PCI PIN Security is a standard from the PCI Security Standards Council governing the secure management, processing, and transmission of personal identification number (PIN) data during payment card transactions at ATMs and point-of-sale terminals. It applies to acquirers, processors, and their agents that handle PIN-based transactions and cryptographic key management. The requirements are grouped into control objectives covering secure equipment and key management, PIN encryption, and the generation, distribution, and destruction of cryptographic keys. [1]
5 verified sources
What is PCI Point-to-Point Encryption (P2PE)?
PCI Point-to-Point Encryption (P2PE) is a standard defined by the PCI Security Standards Council. It specifies requirements for solutions that cryptographically protect account data from the point of capture at a merchant device until it reaches a secure decryption environment. This standard applies to P2PE solution providers, component providers, and merchants using PCI-listed P2PE solutions. A validated P2PE solution can significantly reduce a merchant's applicable PCI DSS scope. The requirements encompass secure devices, secure applications, encryption and decryption environments, and cryptographic key operations. [1]
5 verified sources
What is the PCI 3DS Core Security Standard?
The PCI 3DS Core Security Standard, from the PCI Security Standards Council, defines physical and logical security requirements for environments where EMV 3-D Secure functions such as the Access Control Server (ACS), Directory Server (DS) and 3DS Server (3DSS) are performed. It applies to entities performing these 3DS functions and is separate and independent from PCI DSS. It is structured in two parts: baseline security requirements for the environment, and 3DS-specific requirements protecting 3DS data, technologies and processes that support card-not-present authentication. [1]
5 verified sources
What is the PCI Software Security Framework?
The PCI Software Security Framework (SSF) is a collection of standards and validation programmes from the PCI Security Standards Council that promotes security in payment software and replaced PA-DSS. It comprises two standards: the Secure Software Standard, which assesses payment-software products, and the Secure Software Lifecycle (Secure SLC) Standard, which assesses a vendor's ongoing secure-development processes. It applies to payment-software vendors and their products; PA-DSS was formally retired at the end of October 2022, after which the SSF became the applicable framework. [1]
5 verified sources