PCI DSS
Payment Card Industry Data Security Standard
The security standard for everyone who handles payment card data.
Maintained by
PCI SSC
Region
Global
Latest version
4.0.1
Validation
SAQ / ROC by level
Overview
What is PCI DSS?
PCI DSS is the global security standard for organizations that store, process, or transmit cardholder data, maintained by the PCI Security Standards Council, which was founded by the major card brands. The current version is v4.0.1.
It defines 12 core requirements grouped under six goals. Your validation path depends on transaction volume — from a Self-Assessment Questionnaire (SAQ) for smaller merchants to a full Report on Compliance (ROC) by a Qualified Security Assessor for the largest.
Who needs it: Merchants, payment processors, and any service provider that touches cardholder data — and the SaaS vendors that support them.
Inside the framework
12 requirements across six goals
Build & maintain a secure network
Firewalls, secure configurations, and no vendor-default passwords.
Protect account data
Protect stored cardholder data and encrypt it in transit across open, public networks.
Maintain a vulnerability management program
Anti-malware plus secure, regularly patched systems and software.
Implement strong access control
Restrict access on a need-to-know basis, with unique IDs and physical controls.
Regularly monitor & test networks
Log and monitor all access to cardholder data, and test security systems and processes.
Maintain an information security policy
A policy that addresses information security for all personnel.
With RegShield
Get PCI DSS-ready in a fraction of the time
AI evidence mapping
Upload a policy, screenshot, or config and RegShield maps it to the right PCI DSS controls in seconds — with confidence scores you can defend in front of an auditor.
Reuse across frameworks
Evidence you collect for PCI DSS is automatically reused across every other framework you've activated — so the work compounds instead of repeating.
Gaps & audit-ready reports
See your PCI DSS readiness score, the exact gaps that remain, and concrete remediation steps — then export an audit-ready report.
FAQ
Common questions
Who has to comply?
Anyone who stores, processes, or transmits cardholder data — merchants and service providers of every size.
What's an SAQ vs a ROC?
Smaller merchants self-assess with a Self-Assessment Questionnaire; larger volumes require a Report on Compliance from a Qualified Security Assessor.
Can I reduce my scope?
Yes — using tokenization and a compliant payment processor reduces what's in scope. RegShield maps your remaining controls and gaps.