The PCI DSS is a set of security rules that card networks require any business handling credit or debit card data to follow.
The Payment Card Industry Data Security Standard (PCI DSS) is not a law passed by Congress or a regulation written by a government agency. It is a standard created and enforced by the major card networks—Visa, Mastercard, American Express, Discover, and JCB—that applies to every business that accepts, stores, or transmits card data. If you swipe a card at a store, the store must follow PCI DSS rules. If you enter your card number on a website, that website must follow PCI DSS rules. If a payment processor handles your card details, they must follow PCI DSS rules.
The standard exists because card networks want to reduce fraud and data breaches. When a business gets hacked and millions of card numbers leak, the card networks lose money through fraud claims, and cardholders dispute charges. PCI DSS sets a floor for how securely a business must handle card data. Businesses that ignore it face fines from card networks, loss of the ability to accept cards, and liability if a breach happens.
Key Takeaways
- PCI DSS is created by card networks (Visa, Mastercard, Amex, Discover, JCB), not by government, and applies to any business that touches card data.
- The standard requires businesses to encrypt card data, use firewalls, limit who can access card information, and test their systems for vulnerabilities.
- Compliance is mandatory for businesses that accept cards; non-compliance can result in fines, loss of card processing ability, and liability for breaches.
- Compliance levels depend on how many card transactions a business processes per year, with smaller merchants facing lighter requirements than large retailers.
- A business does not need to be PCI DSS certified to be compliant, but it must meet the standard's requirements and document that it does.
Who has to follow PCI DSS and why
Any business that accepts credit or debit cards must follow PCI DSS. This includes retail stores, restaurants, gas stations, online merchants, nonprofits that take donations by card, and payment processors themselves. Even a small business that processes only a few hundred card transactions per month is technically subject to the standard.
The card networks enforce PCI DSS through acquiring banks—the banks that let merchants accept cards. If a merchant is found to be non-compliant after a breach, the acquiring bank can fine the merchant, sometimes thousands of dollars per month until compliance is restored. The merchant can also lose the ability to accept cards altogether. Card networks also reserve the right to fine acquiring banks that allow non-compliant merchants to operate, which creates pressure down the chain.
What PCI DSS actually requires
PCI DSS has 12 main requirements, grouped into six categories. The requirements are technical and operational, not just theoretical. A business cannot straightforward claim it cares about security; it must implement specific controls and be able to prove it.
The technical requirements include installing and maintaining a firewall, not using default passwords on systems, encrypting card data both when it is stored and when it travels across networks, and running regular scans to find vulnerabilities in the network. The operational requirements include restricting who can access card data (only employees who need it for their job), logging and monitoring access to card data so breaches can be detected, and testing the security of the system at least once per year through an external scan or penetration test.
A business also must have a written policy for handling card data, train employees on that policy, and maintain records showing it has done these things. If a business stores card data, it must have a plan for what to do if that data is breached—who to notify, how quickly, and what steps to take to prevent it happening again.
Compliance levels and what they mean
PCI DSS has four compliance levels based on how many card transactions a business processes per year. The levels determine how much documentation and testing a business must do, but all businesses at all levels must meet the same 12 requirements.
| Level | Transaction Volume (per year) | Main Requirement |
|---|---|---|
| Level 1 | Over 6 million | Annual audit by a may have access to security assessor; quarterly network scans |
| Level 2 | 1 to 6 million | Annual self-assessment questionnaire; quarterly network scans |
| Level 3 | 20,000 to 1 million (online) | Annual self-assessment questionnaire; annual network scan |
| Level 4 | Under 20,000 (online) or under 1 million (in-person) | Annual self-assessment questionnaire; annual network scan |
A Level 1 merchant—a large retailer or payment processor—must hire a may have access to Security Assessor (QSA), a third-party firm certified by the card networks to audit PCI DSS compliance. The QSA conducts a detailed review of the business's systems, policies, and practices and issues a report. A Level 2, 3, or 4 merchant can complete a self-assessment questionnaire, which is a detailed checklist that the business fills out to show it meets each requirement. Even with self-assessment, these merchants must still hire a scanning vendor to run automated tests on their network.
What PCI DSS does not cover
PCI DSS applies only to card data—the card number, expiration date, CVV, and cardholder name. It does not cover other personal information a business might collect, like a customer's address, phone number, or email. If a business collects that information, it may be covered by other laws like state data breach notification laws or the FTC's safeguards rule, but not by PCI DSS itself.
PCI DSS also does not explore to businesses that never touch card data directly. If a business uses a payment processor that handles all card information—the customer enters their card number on the processor's find form, not on the business's website—then the business itself may not be subject to PCI DSS. The payment processor is responsible for compliance instead. However, the business is still responsible for choosing a processor that is compliant and for not storing card data on its own systems.
How businesses prove they are compliant
Compliance is not a one-time event. A business must maintain compliance year-round and document it. For Level 1 merchants, this means an annual audit by a QSA and quarterly network scans. For other levels, it means completing an annual self-assessment questionnaire and submitting it to the acquiring bank, along with results from an annual network scan.
The self-assessment questionnaire asks detailed questions about the business's network, systems, policies, and practices. A business must answer honestly and completely. If a business claims it is compliant but a breach later reveals it was not, the acquiring bank and card networks can investigate and impose fines. Some breaches have resulted in settlements in the millions of dollars.
A business does not need to be "PCI DSS certified"—that is not a real credential. What matters is that the business meets the 12 requirements and can prove it through documentation, testing, and audit.
What happens if a business is not compliant
If a business is found to be non-compliant, the acquiring bank typically gives it a window to fix the problems—often 30 to 90 days. During that time, the business may face monthly fines from the card networks, usually $100 to $500 per month, though fines can be higher. If the business does not come into compliance, the acquiring bank can terminate the merchant account, meaning the business can no longer accept cards.
If a non-compliant business experiences a breach, the consequences are much worse. The business may face fines from the card networks, lawsuits from cardholders, notification costs (sending letters to affected customers), credit monitoring costs, and reputational damage. Some breaches have cost businesses millions of dollars in settlements and remediation.
Frequently Asked Questions
Do I need to be PCI DSS certified?
No. "PCI DSS certified" is not a real credential. You need to be compliant with the standard, which means meeting the 12 requirements and documenting that you do. Depending on your transaction volume, you may need an audit by a may have access to Security Assessor or a self-assessment questionnaire, but certification itself is not required.
What if I use a payment processor and never see card numbers?
If the processor handles all card data and you never store or transmit card numbers yourself, you may not be directly subject to PCI DSS. However, you are still responsible for choosing a processor that is compliant and for not storing card data on your own systems. Ask your processor for proof of their compliance.
How often do I need to test my systems?
At minimum, you must run an external network scan at least once per year and after any major change to your network. Level 1 merchants must scan quarterly. Many businesses scan more often to catch vulnerabilities early. You should also conduct a penetration test—a simulated attack—at least once per year to find weaknesses a scanner might miss.
What card data am I allowed to store?
You should store as little as possible. You can store the card number, expiration date, and cardholder name if you have a business reason to do so and you encrypt it. You must never store the CVV (the three-digit code on the back), the PIN, or the magnetic stripe data. If you do not need to store card data, do not.
What should I do if I think I have been breached?
Notify your acquiring bank and payment processor when ready. They will guide you through the breach response process, which typically includes hiring a forensics firm to investigate, notifying affected cardholders, and submitting a breach report to the card networks. Do not delay—the longer you wait, the worse the consequences.