Payment Card Industry Data Security Standard (PCI DSS)
A global security standard maintained by the PCI Security Standards Council that sets technical and operational requirements for organisations that store, process or transmit payment card account data.
PCI DSS applies to merchants, payment processors, service providers and any other entities that handle cardholder data or sensitive authentication data, or that could affect the security of the cardholder data environment. It is organised into 12 principal requirements under six goals: building and maintaining a secure network and systems, protecting account data, maintaining a vulnerability management programme, implementing strong access control measures, regularly monitoring and testing networks, and maintaining an information security policy.
The PCI Security Standards Council was founded by major payment card brands, which, together with acquiring banks, enforce compliance through contracts. Depending on transaction volume and role, organisations validate compliance through a self-assessment questionnaire or an assessment by a Qualified Security Assessor documented in a report on compliance. Version 4.0 introduced a customised approach for meeting requirement objectives, along with new requirements, many of which became mandatory on 31 March 2025.
Reducing the scope of the cardholder data environment through network segmentation, tokenisation and outsourcing to validated payment providers is a common strategy, since every system in scope must meet the requirements. Compliance is validated at a point in time and does not guarantee security between assessments. PCI DSS is an industry standard enforced contractually rather than a law, although some jurisdictions reference it in legislation.
Key points
- Applies to any entity that stores, processes or transmits cardholder data.
- Organised into 12 principal requirements under six goals.
- Validated through self-assessment or a Qualified Security Assessor.
- Scope reduction through segmentation and tokenisation simplifies compliance.
Where AiVibe comes in
AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.
Related terms
- Encryption at Rest and in TransitCybersecurity & Compliance
- Web Application Firewall (WAF)Cybersecurity & Compliance
- Penetration TestingCybersecurity & Compliance
- Multi-Factor Authentication (MFA)Cybersecurity & Compliance
- Vulnerability ManagementCybersecurity & Compliance
- Compliance Gap AnalysisCybersecurity & Compliance