✨ Standpoint covers PCI DSS readiness free for 14 days. Start your free trial →
Standpointby AI Service Pro
Frameworks / PCI DSS
Security · Industry-mandated standard (contractual)

PCI DSS

PCI DSS — the Payment Card Industry Data Security Standard — is the security rulebook for any organization that stores, processes, or transmits payment card data. It's published by the PCI Security Standards Council and enforced through your bank and the card brands, not by a government. If accepting card payments has put "PCI compliance" on your plate, here's the plain-language version: what PCI DSS is, who needs it, the 6 goals and 12 requirements, how merchant Levels and validation (SAQ vs QSA) work, and how to get ready.

What
PCI DSS (Payment Card Industry Data Security Standard), current version 4.0 — a set of security requirements for protecting cardholder data.
Who
merchants and service providers of any size that store, process, or transmit cardholder data — from a small online shop to a global payment processor.
How it's organized
6 high-level goals broken into 12 requirements, each with detailed sub-requirements.
Levels & validation
merchants are tiered into Levels 1–4 by yearly transaction volume; you validate either with a Self-Assessment Questionnaire (SAQ) or an on-site assessment by a Qualified Security Assessor (QSA).
// What Standpoint gives you

PCI DSS checklist

A goal-by-goal readiness checklist.

Free readiness assessment

See your PCI DSS gaps in minutes.

Map to other frameworks

How PCI DSS lines up with ISO 27001, NIST 800-53 & SOC 2.

// What the framework covers
Build & maintain a secure network and systemsGAP
Protect account dataPARTIAL
Maintain a vulnerability management programDONE
Implement strong access control measuresGAP
Regularly monitor & test networksPARTIAL
Maintain an information security policyDONE

Illustrative statuses. Your real assessment is generated from your answers in the app. Standpoint is a self-assessment aid, not legal advice.

// Go deeper

What is PCI DSS?

PCI DSS is a security standard, not a law and not a certification you frame on the wall. It defines a baseline of technical and operational controls that any business handling payment cards is expected to meet in order to protect account data and reduce card fraud. It's maintained by the PCI Security Standards Council (PCI SSC) — an industry body founded by Visa, Mastercard, American Express, Discover, and JCB — and it's enforced contractually: your acquiring bank and the card brands require compliance as a condition of accepting card payments. The current version, PCI DSS 4.0 (with the 4.0.1 …

Who needs PCI DSS?

In short: anyone who touches cardholder data. That's a wide net, and the depth of effort scales with your volume and role. Teams typically engage with PCI DSS when: - they're a merchant accepting card payments online, in-store, or by phone; - they're a service provider that stores, processes, or transmits card data on behalf of others (payment gateways, hosting providers, call centers, and similar); - they can affect the security of a client's cardholder data environment, even if they never see a full card number; - an acquiring bank, payment processor, or enterprise customer contractually requires proof of PCI DSS compliance.

The 6 goals and 12 requirements

PCI DSS organizes its 12 requirements under 6 control goals. The table below paraphrases each in plain language — it is not the official requirement text. PCI DSS 4.0 keeps this 6-goal / 12-requirement structure but adds a "customized approach" that lets mature teams meet a control's objective in their own way, and phases in new expectations (for example, broader MFA and stronger authentication).

Merchant Levels and validation (SAQ vs QSA)

Level 1 — The highest-volume merchants (commonly over 6 million card transactions a year) — typically require an on-site assessment by a Qualified Security Assessor (QSA) and a Report on Compliance (RoC). Level 2 — Mid-to-high volume merchants (commonly 1–6 million transactions a year) — usually a Self-Assessment Questionnaire (SAQ), sometimes with an on-site review. Level 3 — Lower-volume e-commerce merchants (commonly 20,000–1 million e-commerce transactions a year) — typically an SAQ. Level 4 — The smallest merchants (below the Level 3 e-commerce threshold or up to ~1 million total transactions) — typically an SAQ, as directed by your acquirer.

How PCI DSS relates to ISO 27001 & SOC 2

They overlap heavily. ISO 27001 is a certifiable information-security management-system standard, and SOC 2 is an attestation against the AICPA Trust Services Criteria — both cover access control, encryption, logging, vulnerability management, and change control, which are also the heart of PCI DSS. PCI DSS is narrower and more prescriptive: it's specifically about protecting cardholder data. Because the controls line up, evidence you gather for one framework advances the others. See the PCI DSS crosswalk for the detail.

A practical path to readiness

- Scope your cardholder data environment (CDE). Map exactly where card data is stored, processed, or transmitted — and shrink that footprint where you can. - Determine your Level and SAQ type. Confirm with your acquirer which validation path and which SAQ (or RoC) applies to you. - Run a gap assessment. Compare where you are today against the 12 requirements, goal by goal. - Remediate and evidence. Close the gaps and keep dated proof for each requirement (configs, scans, access reviews, logs, tests). - Validate — SAQ or QSA. Complete the SAQ or engage a QSA for a RoC, plus any required ASV scans, then keep controls operating year-round. The fastest start is a gap assessment after you've scoped the CDE. Our free PCI DSS readiness assessment shows where you stand, and the readiness checklist turns it into a working plan.

PCI DSS work counts elsewhere too

The crosswalk maps your PCI DSS evidence onto the frameworks it overlaps — so you move forward on several at once.

ISO 27001SOC 2

Get your PCI DSS readiness score.

Free to start. No card, no demo wall. You decide what leaves your device.

Run your free check →