PCI DSS
Payment Card Industry Data Security Standard
PCI DSS (Payment Card Industry Data Security Standard) is an industry security standard for organisations that store, process, or transmit cardholder data, and for systems that can affect its security. Maintained by the PCI Security Standards Council, it sets technical and operational requirements for protecting payment account data. Validation obligations depend on the applicable payment-brand and acquirer rules.
The standard is organised around a set of core requirements covering areas like building secure networks, protecting stored cardholder data, managing vulnerabilities, restricting access, and regularly monitoring and testing systems.
The required validation method depends on payment-brand and acquirer rules as well as the merchant or service-provider situation; it may involve a Self-Assessment Questionnaire or a formal assessment. Reducing direct handling of card data can reduce scope, but outsourcing does not automatically eliminate responsibilities.
How PCI DSS works in practice
PCI DSS sets security requirements for environments relevant to payment card account data. Scoping starts with the payment journey: how card data is captured, transmitted, processed or stored, and which systems can affect the security of that environment. Record the connections, service providers and administrative access paths. A system can be relevant to scope even when it does not itself store full card numbers.
The standard addresses security controls and operating processes, including access, configuration, monitoring and testing. Implementation needs to reflect the payment architecture and applicable requirements. Keep evidence of actual control activity and document responsibilities shared with third parties. Outsourcing a payment component can reduce some work, but the merchant or service provider still needs to understand and manage its own responsibilities.
Who needs it and how validation is determined
Merchants and service providers involved in card payments should establish their applicable requirements with their acquirer, payment brands or appropriate specialists. The validation method can depend on the organisation's role and circumstances. Do not assume that a self-assessment questionnaire used by another business applies to yours. Different payment arrangements and eligibility conditions can lead to different evidence and assessment requirements.
Where specialist assessment is required, confirm the role and qualifications of the assessor. A readiness consultant may help map scope, assess gaps and support remediation, but cannot substitute an informal letter for the required validation. Ask how applications, infrastructure, third parties and any segmentation are being considered. A compliant payment provider's documentation is useful evidence, but it is not automatically evidence that your entire environment is compliant.
Keeping scope and evidence current
Work with engineering and payment owners when integrating a new checkout flow, mobile application or API. Check whether sensitive data appears in logs, analytics, support tickets or test systems. Data discovery and clear retention decisions can prevent unexpected expansion of scope. Restrict access based on job responsibilities and verify that required reviews and monitoring continue after the initial project.
Testing and change management should cover the actual payment environment and relevant security dependencies. Document exceptions and remediation with responsible owners rather than relying on a one-off checklist. Review the boundary after architecture or supplier changes. PCI DSS addresses payment-card security; it does not replace broader privacy obligations, fraud management or business continuity. Coordinate these programmes while keeping each requirement and evidence set distinct.
PCI DSS vs. GDPR
| Aspect | PCI DSS | GDPR |
|---|---|---|
| Primary concern | Protecting account data in payment-card environments. | Lawful handling of personal data within the GDPR's scope. |
| Assessment | Validation method depends on payment-brand/acquirer requirements and merchant or service-provider scope. | Data-protection obligations depend on processing, roles and territorial reach. |
Common misconceptions
- Using an external payment gateway does not automatically eliminate every PCI DSS responsibility. The integration and the systems affecting it still need review.
- A scan report alone is not a complete PCI DSS validation. Applicable controls and the required validation method depend on role and scope.
- PCI DSS and GDPR address different obligations. Payment security work does not automatically satisfy privacy law, and privacy policies do not secure a payment environment.
Frequently asked questions
Does outsourcing payments eliminate PCI DSS responsibilities?
Not necessarily. Outsourcing may reduce the systems in scope, but organisations should confirm their own validation obligations with their acquirer or payment brand.
Is PCI DSS a law?
PCI DSS is an industry security standard, not a statute. Payment brands and acquirers set compliance and validation expectations for participants.
Reference sources
Practical context
Using PCI DSS in a real decision
Definitions are most useful when they help a team decide what to scope, who should own the work, and what evidence supports the next step. Use these questions to turn the term into a practical conversation.
- Which customers, data, services, or contracts make this requirement relevant?
- What controls and evidence would demonstrate that the requirement is operating in practice?
- Who is accountable for the scope, reviews, and any remediation work?
