PCI DSS
PCI DSS — the Payment Card Industry Data Security Standard — is the security rulebook for any organization that stores, processes, or transmits payment card data. It's published by the PCI Security Standards Council and enforced through your bank and the card brands, not by a government. If accepting card payments has put "PCI compliance" on your plate, here's the plain-language version: what PCI DSS is, who needs it, the 6 goals and 12 requirements, how merchant Levels and validation (SAQ vs QSA) work, and how to get ready.
PCI DSS checklist
A goal-by-goal readiness checklist.
Free readiness assessment
See your PCI DSS gaps in minutes.
Map to other frameworks
How PCI DSS lines up with ISO 27001, NIST 800-53 & SOC 2.
Illustrative statuses. Your real assessment is generated from your answers in the app. Standpoint is a self-assessment aid, not legal advice.
What is PCI DSS?
PCI DSS is a security standard, not a law and not a certification you frame on the wall. It defines a baseline of technical and operational controls that any business handling payment cards is expected to meet in order to protect account data and reduce card fraud. It's maintained by the PCI Security Standards Council (PCI SSC) — an industry body founded by Visa, Mastercard, American Express, Discover, and JCB — and it's enforced contractually: your acquiring bank and the card brands require compliance as a condition of accepting card payments. The current version, PCI DSS 4.0 (with the 4.0.1 …
Who needs PCI DSS?
In short: anyone who touches cardholder data. That's a wide net, and the depth of effort scales with your volume and role. Teams typically engage with PCI DSS when: - they're a merchant accepting card payments online, in-store, or by phone; - they're a service provider that stores, processes, or transmits card data on behalf of others (payment gateways, hosting providers, call centers, and similar); - they can affect the security of a client's cardholder data environment, even if they never see a full card number; - an acquiring bank, payment processor, or enterprise customer contractually requires proof of PCI DSS compliance.
The 6 goals and 12 requirements
PCI DSS organizes its 12 requirements under 6 control goals. The table below paraphrases each in plain language — it is not the official requirement text. PCI DSS 4.0 keeps this 6-goal / 12-requirement structure but adds a "customized approach" that lets mature teams meet a control's objective in their own way, and phases in new expectations (for example, broader MFA and stronger authentication).
Merchant Levels and validation (SAQ vs QSA)
Level 1 — The highest-volume merchants (commonly over 6 million card transactions a year) — typically require an on-site assessment by a Qualified Security Assessor (QSA) and a Report on Compliance (RoC). Level 2 — Mid-to-high volume merchants (commonly 1–6 million transactions a year) — usually a Self-Assessment Questionnaire (SAQ), sometimes with an on-site review. Level 3 — Lower-volume e-commerce merchants (commonly 20,000–1 million e-commerce transactions a year) — typically an SAQ. Level 4 — The smallest merchants (below the Level 3 e-commerce threshold or up to ~1 million total transactions) — typically an SAQ, as directed by your acquirer.
How PCI DSS relates to ISO 27001 & SOC 2
They overlap heavily. ISO 27001 is a certifiable information-security management-system standard, and SOC 2 is an attestation against the AICPA Trust Services Criteria — both cover access control, encryption, logging, vulnerability management, and change control, which are also the heart of PCI DSS. PCI DSS is narrower and more prescriptive: it's specifically about protecting cardholder data. Because the controls line up, evidence you gather for one framework advances the others. See the PCI DSS crosswalk for the detail.
A practical path to readiness
- Scope your cardholder data environment (CDE). Map exactly where card data is stored, processed, or transmitted — and shrink that footprint where you can. - Determine your Level and SAQ type. Confirm with your acquirer which validation path and which SAQ (or RoC) applies to you. - Run a gap assessment. Compare where you are today against the 12 requirements, goal by goal. - Remediate and evidence. Close the gaps and keep dated proof for each requirement (configs, scans, access reviews, logs, tests). - Validate — SAQ or QSA. Complete the SAQ or engage a QSA for a RoC, plus any required ASV scans, then keep controls operating year-round. The fastest start is a gap assessment after you've scoped the CDE. Our free PCI DSS readiness assessment shows where you stand, and the readiness checklist turns it into a working plan.
PCI DSS work counts elsewhere too
The crosswalk maps your PCI DSS evidence onto the frameworks it overlaps — so you move forward on several at once.