Security, Resilience & Assurance · Global
Payment Card Industry Data Security Standard
A global contractual security standard mandated by the major card networks for any organisation that stores, processes or transmits cardholder data. Compliance is enforced through merchant agreements rather than government law.
REGULATORPCI Security Standards Council
REGIONGlobal
EFFECTIVECurrent version PCI DSS 4.0.1
Who it applies to
- Merchants and service providers that store, process or transmit cardholder data
- Organisations of any size accepting card payments, with scope-appropriate requirements
- Third parties with access to the cardholder data environment (CDE)
Key requirements
- Network segmentation and protection of the cardholder data environment
- Strong access control and authentication measures
- Annual internal and external penetration testing under Requirement 11.4
- Segmentation testing every 6 months for service providers
- Ongoing vulnerability management and secure system configuration
Maximum penaltyContractual fines from card networks/acquiring banks, increased transaction fees, or loss of card processing privileges
Go to the source
Official resources
Praeferre's summary is a starting point, not legal advice. For the authoritative text and current guidance, go directly to the governing body.
Start your compliance journey
See how Praeferre automates PCI DSS compliance
Continuous monitoring, evidence and reporting for PCI DSS — alongside every other framework you need to satisfy.