Compliance · Global
PCI DSS v4.0Mandated by card brands

PCI DSS

Plain-English definition

The Payment Card Industry Data Security Standard is a contractual requirement, not a law: card brands (Visa, Mastercard, and others) require it of any merchant or service provider that stores, processes, or transmits cardholder data, enforced through merchant agreements with acquiring banks. Version 4.0's full requirement set became mandatory in March 2025.

Validation method (self-assessment questionnaire vs. a QSA-led Report on Compliance) depends on your transaction volume and merchant level, not on the standard itself.

Who needs it

Any merchant or service provider that stores, processes, or transmits payment card data, regardless of company size; the validation burden scales with transaction volume, but the underlying requirements apply to everyone in scope.

Key requirements

12 core requirements spanning network security, cardholder data protection (including encryption), vulnerability management, strong access control, monitoring and testing, and a formal information security policy.

Cyber/privacy implications

Cardholder data environment scope directly determines audit burden, so network segmentation isolating payment systems from the rest of your infrastructure is often the single highest-leverage control.

Assessment methodology

Cardholder data environment scoping and network segmentation review, gap assessment against the 12 requirements, and validation-method determination (SAQ vs. formal Report on Compliance with a QSA).

Implementation phases

01
Scope

Map the cardholder data environment and confirm segmentation.

02
Remediate

Close gaps against the 12 requirements, prioritizing encryption and access control.

03
Validate

Complete the appropriate SAQ or support a QSA-led Report on Compliance.

Evidence & documentation requirements

Network diagrams showing cardholder data flow and segmentation, encryption and key management documentation, vulnerability scan results, and access control logs.

Common mistakes

Under-scoping the cardholder data environment, which looks favorable short-term but creates real exposure and audit risk; treating quarterly vulnerability scans as sufficient without addressing findings between scan cycles.

Related standards

Expert review

Nitzan Levi
Nitzan Levi
Co-Founder, Cybecs · Co-Founder, RedRok · Executive Director, Privacy & GRC · CISM, CISSP, CDPSE, CCSK, CSA

FAQ

Do we need a Qualified Security Assessor?
Only merchants above certain transaction volume thresholds (Level 1) require a QSA-led Report on Compliance; smaller merchants typically self-assess via SAQ, and we support both paths.
Can reducing our cardholder data environment reduce our burden?
Yes, tokenization and outsourcing card handling to a compliant payment processor can significantly shrink what's actually in scope for your own assessment.
What changed in v4.0?
Expanded authentication requirements, more explicit encryption and monitoring expectations, and new requirements that only became mandatory in March 2025 after a transition period.

Request a Gap Assessment

Map your cardholder data environment and see where your controls stand.

Request a Gap Assessment →