PCI DSS
Also known as: Payment Card Industry Data Security Standard
Industry standard for organizations handling branded credit cards from major card networks.
The Payment Card Industry Data Security Standard (PCI DSS) is the cybersecurity standard governing organizations that store, process, or transmit branded credit-card data, developed and maintained by the PCI Security Standards Council (founded 2006 by American Express, Discover, JCB, Mastercard, and Visa). PCI DSS originated from each major card network's separate security programs (Visa CISP, Mastercard SDP, etc.) being unified into a common standard, with PCI DSS 1.0 published December 2004. Current PCI DSS 4.0 (March 2022, with full transition required by March 2025) consists of 12 high-level requirements organized into 6 control objectives, with 305 sub-requirements. The 12 requirements: (1) Install and maintain a firewall; (2) Do not use vendor-supplied defaults for system passwords; (3) Protect stored cardholder data; (4) Encrypt transmission of cardholder data across public networks; (5) Use and regularly update anti-virus software; (6) Develop and maintain secure systems and applications; (7) Restrict access by business need-to-know; (8) Assign a unique ID to each person with computer access; (9) Restrict physical access to cardholder data; (10) Track and monitor all access to network resources; (11) Regularly test security systems and processes; (12) Maintain an information security policy. Validation requirements scale with merchant level (1-4 based on transaction volume), with Level 1 requiring annual on-site assessment by a Qualified Security Assessor (QSA). PCI DSS is contractually enforced by card networks rather than legally mandated, with non-compliance penalties including substantial fines and potential loss of card-processing privileges. The standard has been substantially influential in shaping cybersecurity practice in retail, hospitality, e-commerce, and financial services.
Core components
- 12 requirements organized in 6 control objectives: Build and Maintain a Secure Network
- Protect Cardholder Data
- Maintain a Vulnerability Management Program
- Implement Strong Access Control
- Regularly Monitor and Test Networks
- Maintain an Information Security Policy
- Four merchant levels based on transaction volume
- Validation methods: Self-Assessment Questionnaire (SAQ), Report on Compliance (ROC) by Qualified Security Assessor
- Quarterly Approved Scanning Vendor (ASV) external scans
- Annual penetration testing (Level 1)
- Tokenization and encryption requirements
- Connection to broader payment ecosystem
- Contractual rather than legal enforcement
Primary use case
Cybersecurity compliance for organizations handling credit card data — virtually all retailers, e-commerce, hospitality, and many service providers; foundation for substantial cybersecurity programs across affected industries; basis for merchant validation across card networks; integration with broader information security programs; reference framework in payment-security education; foundation for substantial QSA and ASV consulting industry.
Common criticisms
- Tendency toward checklist compliance rather than substantive security — many breaches have occurred at PCI-compliant organizations (notable examples include Target 2013, Home Depot 2014)
- compliance scope (Cardholder Data Environment) creates incentive to narrow CDE artificially, sometimes producing weaker overall security
- 12 high-level requirements expand to 305 sub-requirements, creating substantial compliance complexity
- QSA quality varies substantially across assessors
- commercial QSA industry has financial incentive to perpetuate compliance complexity
- the standard's contractual enforcement (vs legal mandate) creates uneven application — some non-compliant organizations face few consequences while others face severe penalties
- cross-walking with other frameworks (NIST, ISO, HITRUST) requires substantial duplicative effort
- PCI DSS 4.0 transition has created industry friction with substantial new requirements (customized validation paths, additional cryptographic controls, expanded scope of MFA)
- merchant-level definitions are based on transaction volume that doesn't always match risk
- tokenization and encryption requirements have improved substantially but legacy systems often lag.
Lineage
- Siblings
- HITRUST CSF