PCI DSS

Also known as: Payment Card Industry Data Security Standard

framework · cybersecurity · regulatory-standard

Industry standard for organizations handling branded credit cards from major card networks.

The Payment Card Industry Data Security Standard (PCI DSS) is the cybersecurity standard governing organizations that store, process, or transmit branded credit-card data, developed and maintained by the PCI Security Standards Council (founded 2006 by American Express, Discover, JCB, Mastercard, and Visa). PCI DSS originated from each major card network's separate security programs (Visa CISP, Mastercard SDP, etc.) being unified into a common standard, with PCI DSS 1.0 published December 2004. Current PCI DSS 4.0 (March 2022, with full transition required by March 2025) consists of 12 high-level requirements organized into 6 control objectives, with 305 sub-requirements. The 12 requirements: (1) Install and maintain a firewall; (2) Do not use vendor-supplied defaults for system passwords; (3) Protect stored cardholder data; (4) Encrypt transmission of cardholder data across public networks; (5) Use and regularly update anti-virus software; (6) Develop and maintain secure systems and applications; (7) Restrict access by business need-to-know; (8) Assign a unique ID to each person with computer access; (9) Restrict physical access to cardholder data; (10) Track and monitor all access to network resources; (11) Regularly test security systems and processes; (12) Maintain an information security policy. Validation requirements scale with merchant level (1-4 based on transaction volume), with Level 1 requiring annual on-site assessment by a Qualified Security Assessor (QSA). PCI DSS is contractually enforced by card networks rather than legally mandated, with non-compliance penalties including substantial fines and potential loss of card-processing privileges. The standard has been substantially influential in shaping cybersecurity practice in retail, hospitality, e-commerce, and financial services.

Originators

PCI Security Standards Council (founded 2006); American Express, Discover, JCB, Mastercard, Visa (founding card networks); intellectual antecedents in each network's prior security programs high

Year / Decade

2004 (PCI DSS 1.0); 2006 (PCI SSC founded); 2022 (PCI DSS 4.0); 2025 (4.0 full effective date) high

Primary sources

PCI Security Standards Council (2022). Payment Card Industry Data Security Standard Version 4.0, PCI SSC (ongoing). Self-Assessment Questionnaires, Report on Compliance templates, Approved Scanning Vendor program documentation high

Core components

Primary use case

Cybersecurity compliance for organizations handling credit card data — virtually all retailers, e-commerce, hospitality, and many service providers; foundation for substantial cybersecurity programs across affected industries; basis for merchant validation across card networks; integration with broader information security programs; reference framework in payment-security education; foundation for substantial QSA and ASV consulting industry.

Common criticisms

Lineage

Siblings
HITRUST CSF