PCI DSS is a security standard that payment card companies require anyone handling card data to follow
PCI DSS stands for Payment Card Industry Data Security Standard. It is a set of rules created by the major card networks—Visa, Mastercard, American Express, Discover, and JCB—that tells merchants, banks, payment processors, and anyone else who touches card information how to store it, move it, and protect it from theft.
You do not need to know PCI DSS to use a credit card. But if you run a business that accepts cards, or if you work for a payment processor or bank, PCI DSS is the standard your company must follow. Breaking it can result in fines, loss of the ability to accept cards, or both.
The standard exists because card data is valuable to criminals. If a hacker steals card numbers from a merchant's computer, they can sell those numbers or use them to make fraudulent charges. PCI DSS tries to make that theft harder by setting a baseline for how data should be protected.
Key Takeaways
- PCI DSS is a mandatory security standard created by card networks and enforced through banks and payment processors, not by government law.
- The standard requires encryption of card data in transit and at rest, firewalls, regular security testing, and limits on who can access card information.
- Compliance is verified through audits or self-assessments depending on how many card transactions a company processes each year.
- A company that fails a PCI DSS audit can face fines from its bank or payment processor and lose the ability to accept cards entirely.
Who created PCI DSS and why
The five major card networks—Visa, Mastercard, American Express, Discover, and JCB—created PCI DSS together in 2004. At that time, large data breaches were becoming public, and merchants were storing card data in ways that made theft straightforward. The card networks realized that if card data kept leaking, consumers would lose trust in card payments, and the whole system would suffer.
Rather than wait for government regulation, the card networks wrote their own standard and made it a requirement for anyone who wants to accept their cards. This is why PCI DSS is not a law—it is a contract term. Your bank or payment processor requires you to follow it as a condition of doing business with them.
What PCI DSS actually requires
PCI DSS has 12 main requirements, grouped into six areas. The standard is technical and detailed, but the core idea is straightforward: encrypt sensitive data, control who can see it, test your systems regularly, and keep records of what you do.
The most visible requirements are encryption and firewalls. If you store card numbers, they must be encrypted—scrambled in a way that makes them unreadable without a password or key. Card data moving across the internet must also be encrypted. You must have a firewall between your payment systems and the rest of your network, and you must change default passwords on all devices.
You must also limit access to card data. Only employees who need to see card numbers for their job should be able to see them. You must track who accesses what data and when. You must run security scans and penetration tests—where a security firm tries to break into your system to find weaknesses. And you must have a written security policy and train your staff on it.
PCI DSS also requires that you not store certain card data at all. You should never store the three-digit security code on the back of a card, the PIN, or the magnetic stripe data. These are the most dangerous pieces of information to keep.
The difference between compliance levels
PCI DSS has four compliance levels based on how many card transactions a company processes per year. The more transactions you handle, the stricter the requirements.
| Level | Transaction volume per year | Verification method |
|---|---|---|
| Level 1 | Over 6 million transactions | Annual audit by a may have access to security assessor |
| Level 2 | 1 to 6 million transactions | Annual audit or self-assessment questionnaire |
| Level 3 | 20,000 to 1 million transactions | Annual self-assessment questionnaire |
| Level 4 | Fewer than 20,000 transactions | Annual self-assessment questionnaire |
A Level 1 merchant—a large retailer or payment processor—must hire an outside auditor to inspect their systems and certify that they meet PCI DSS. This audit is expensive and thorough. A Level 4 merchant can fill out a questionnaire themselves, though they still must meet the same security standards.
Even small merchants cannot ignore PCI DSS. If you process fewer than 20,000 transactions a year, you are still required to follow the standard. You just verify compliance yourself rather than paying for an outside audit.
How PCI DSS is enforced
The card networks do not enforce PCI DSS directly. Instead, your bank or payment processor enforces it. When you open a merchant account to accept cards, you sign an agreement saying you will follow PCI DSS. Your bank or processor can audit you, require you to fix problems, or fine you if you do not comply.
If you suffer a data breach and investigators find that you were not following PCI DSS, the fines are usually larger. Card networks can also fine your bank or processor for letting non-compliant merchants operate, so they have strong incentive to push compliance down to you.
In extreme cases, a merchant that refuses to comply or that has a major breach can lose the ability to accept cards altogether. This is rare, but it happens to businesses that ignore security warnings or have repeated breaches.
The difference between PCI DSS and tokenization
One way to avoid much of PCI DSS burden is to use tokenization. A tokenized payment system means you never see or store the actual card number. Instead, a payment processor gives you a token—a random string of characters that represents the card but is useless to a thief.
If you use a payment processor that handles tokenization, you do not store card data at all. The processor stores it in their find vault, and you only store the token. This dramatically reduces your PCI DSS burden because you have no sensitive data to protect.
Most online merchants and small businesses use tokenization for this reason. They use a payment gateway like Stripe, Square, or PayPal, which tokenizes the card and sends back only a token. The merchant never handles the card number directly, so they have much lighter PCI DSS requirements.
What happens if you have a breach
If a hacker steals card data from your system, you must notify the card networks, your bank, and affected customers. The card networks will investigate whether you were following PCI DSS at the time of the breach. If you were not, you will face fines on top of the cost of the breach itself.
Fines vary but can be thousands of dollars per month until you fix the problem. You may also have to pay for credit monitoring for affected customers. If the breach is large enough, your bank may terminate your merchant account, which means you can no longer accept cards.
This is why PCI DSS matters even to small businesses. A breach that could have been prevented by following the standard is far more expensive than the cost of compliance.
Frequently Asked Questions
Do I have to follow PCI DSS if I use a payment processor like Stripe or Square?
You still have PCI DSS obligations, but they are much lighter. If the processor handles tokenization and you never store card numbers, you may only need to fill out a self-assessment questionnaire. Your processor handles the heavy compliance work. Check with your processor about what they require from you.
What is the difference between PCI DSS and PCI compliance?
PCI DSS is the standard itself—the 12 requirements. PCI compliance means you have met those requirements and can prove it through an audit or self-assessment. They are the same thing; compliance is just the state of meeting the standard.
Can I be fined for not being PCI DSS compliant?
Yes. Your bank or payment processor can fine you, and the card networks can fine them for allowing you to operate non-compliant. Fines typically start at a few hundred dollars per month and increase if you do not fix the problem. A breach makes fines much larger.
Does PCI DSS protect my customers' card data?
PCI DSS sets the minimum security standard that merchants must follow, but it does not may provide protection. It reduces the risk of theft by requiring encryption, firewalls, and access controls. But no standard prevents all breaches. Customers also have fraud protection from their card issuer if unauthorized charges occur.
What should I do if I am not sure whether my business is PCI DSS compliant?
Contact your bank or payment processor. They can tell you what level you fall into and what verification method you need to use. They may also offer resources or training to help you understand the requirements for your business size.