Global

PCI DSS

Payment Card Industry Data Security Standard

The security standard for everyone who handles payment card data.

Map your PCI DSS evidence →All frameworks

Maintained by

PCI SSC

Region

Global

Latest version

4.0.1

Validation

SAQ / ROC by level

Overview

What is PCI DSS?

PCI DSS is the global security standard for organizations that store, process, or transmit cardholder data, maintained by the PCI Security Standards Council, which was founded by the major card brands. The current version is v4.0.1.

It defines 12 core requirements grouped under six goals. Your validation path depends on transaction volume — from a Self-Assessment Questionnaire (SAQ) for smaller merchants to a full Report on Compliance (ROC) by a Qualified Security Assessor for the largest.

Who needs it: Merchants, payment processors, and any service provider that touches cardholder data — and the SaaS vendors that support them.

Inside the framework

12 requirements across six goals

1

Build & maintain a secure network

Firewalls, secure configurations, and no vendor-default passwords.

2

Protect account data

Protect stored cardholder data and encrypt it in transit across open, public networks.

3

Maintain a vulnerability management program

Anti-malware plus secure, regularly patched systems and software.

4

Implement strong access control

Restrict access on a need-to-know basis, with unique IDs and physical controls.

5

Regularly monitor & test networks

Log and monitor all access to cardholder data, and test security systems and processes.

6

Maintain an information security policy

A policy that addresses information security for all personnel.

With RegShield

Get PCI DSS-ready in a fraction of the time

AI evidence mapping

Upload a policy, screenshot, or config and RegShield maps it to the right PCI DSS controls in seconds — with confidence scores you can defend in front of an auditor.

Reuse across frameworks

Evidence you collect for PCI DSS is automatically reused across every other framework you've activated — so the work compounds instead of repeating.

Gaps & audit-ready reports

See your PCI DSS readiness score, the exact gaps that remain, and concrete remediation steps — then export an audit-ready report.

FAQ

Common questions

Who has to comply?

Anyone who stores, processes, or transmits cardholder data — merchants and service providers of every size.

What's an SAQ vs a ROC?

Smaller merchants self-assess with a Self-Assessment Questionnaire; larger volumes require a Report on Compliance from a Qualified Security Assessor.

Can I reduce my scope?

Yes — using tokenization and a compliant payment processor reduces what's in scope. RegShield maps your remaining controls and gaps.

Make compliance
disappear.

Twenty-minute demo. Bring a policy document. We'll map it live.

Book a demo →info@regshield.in