What is PCI DSS?
PCI DSS is the security standard for organisations that store, process or transmit payment card data. It is not an ISO standard and it is not certified by an accredited certification body. This page explains what it contains and how compliance is actually validated.
PCI DSS defined
PCI DSS stands for the Payment Card Industry Data Security Standard. It is administered by the PCI Security Standards Council, a body formed by the major payment card brands to maintain a common set of security requirements for the payment ecosystem. The Council writes and maintains the standard, runs the qualification programmes for assessors and scanning vendors, and publishes the supporting documents and templates.
The standard applies to any entity that stores, processes or transmits cardholder data, and to entities that could affect the security of that data. That covers merchants of every size, payment service providers, hosting providers, gateways and processors.
The active version is PCI DSS v4.0.1, published on 11 June 2024. It is a limited revision of v4.0, which was released in March 2022. The revision corrected formatting and typographical errors and clarified the intent of some requirements; no requirements were added or removed. PCI DSS v4.0 was retired on 31 December 2024, after which v4.0.1 became the only active version supported by the Council.
PCI DSS is not an ISO certification scheme
This distinction matters because the vocabulary of ISO certification is frequently and wrongly applied to PCI DSS.
- There is no accredited certification body issuing a PCI DSS certificate. The Council qualifies assessors; national accreditation bodies play no part.
- There is no Stage 1 and Stage 2 audit sequence.
- There are no annual surveillance audits within a three year certificate cycle. PCI DSS validation is an annual exercise, and certain technical requirements such as external vulnerability scanning operate on a quarterly rhythm.
- The standard is enforced contractually through the payment brands and the acquiring banks, not through an accreditation infrastructure.
Anyone describing PCI DSS in terms of Stage 1, Stage 2 and surveillance audits by an ISO certification body is describing a different scheme.
The twelve requirements
PCI DSS is structured as twelve requirements grouped under six goals:
- Build and maintain a secure network and systems. Requirement 1, install and maintain network security controls. Requirement 2, apply secure configurations to all system components.
- Protect account data. Requirement 3, protect stored account data. Requirement 4, protect cardholder data with strong cryptography during transmission over open, public networks.
- Maintain a vulnerability management programme. Requirement 5, protect all systems and networks from malicious software. Requirement 6, develop and maintain secure systems and software.
- Implement strong access control measures. Requirement 7, restrict access to system components and cardholder data by business need to know. Requirement 8, identify users and authenticate access to system components. Requirement 9, restrict physical access to cardholder data.
- Regularly monitor and test networks. Requirement 10, log and monitor all access to system components and cardholder data. Requirement 11, test security of systems and networks regularly.
- Maintain an information security policy. Requirement 12, support information security with organisational policies and programmes.
Scope is decided before any of this is applied. The cardholder data environment comprises the people, processes and technology that store, process or transmit account data, plus anything connected to it or able to affect its security. Reducing that footprint, through network segmentation or by moving card capture to a validated third party, is the single most effective way to reduce the effort of the standard.
How compliance is validated
How an entity validates depends on the level assigned to it. Levels are set by the individual payment brands, based principally on annual transaction volume, and are communicated through the acquiring bank. The Council does not assign an entity’s level, and an entity should confirm its obligations with its acquirer or the relevant payment brand.
- Qualified Security Assessor. A QSA is a company qualified by the Council to perform assessments. A QSA led assessment produces a Report on Compliance, the detailed record of how each requirement was tested and met.
- Attestation of Compliance. The AOC is the signed declaration that accompanies a Report on Compliance or a completed self-assessment, and it is the document normally submitted to the acquirer or requested by a customer.
- Self-Assessment Questionnaire. Eligible entities validate using an SAQ. Several types exist for different payment channels and configurations, including SAQ A, SAQ A-EP, SAQ B, SAQ B-IP, SAQ C, SAQ C-VT, SAQ P2PE and SAQ SPoC, with SAQ D used where no more specific type fits. Eligibility should be confirmed with the acquirer or payment brand before an SAQ is completed.
- Approved Scanning Vendor. External vulnerability scanning of internet facing systems must be carried out by an ASV approved by the Council, on the recurring schedule the standard sets, with passing results retained as evidence.
- Internal Security Assessor. Larger organisations may have staff qualified by the Council as ISAs to carry out internal assessment work.
Validation is a point in time exercise, but the requirements are continuous. A passing assessment does not suspend the obligation to keep patching, logging, scanning and reviewing access between assessments.
How Univate supports PCI DSS
- Scoping the cardholder data environment and identifying opportunities to reduce it through segmentation or channel redesign.
- Gap assessment against PCI DSS v4.0.1 and a prioritised remediation plan.
- Policy, standard and procedure development to meet Requirement 12 and the documentation expectations of the other requirements.
- Technical control design and evidence preparation across network security controls, cryptography, logging, access control and vulnerability management.
- Determining the applicable validation route with the client and its acquirer, and preparing for a QSA assessment or supporting completion of the correct SAQ.
- Readiness for external scanning and coordination with the approved scanning vendor.
Frequently asked questions
Who administers PCI DSS?
The PCI Security Standards Council administers the standard. It was formed by the major payment card brands and it maintains the standard, qualifies assessors and scanning vendors, and publishes the supporting documents.
Which version of PCI DSS is current?
PCI DSS v4.0.1, published on 11 June 2024. It is a limited revision of v4.0 that corrected errors and clarified intent without adding or removing requirements. PCI DSS v4.0 was retired on 31 December 2024, leaving v4.0.1 as the only active version.
Is PCI DSS an ISO standard?
No. PCI DSS is a payment industry standard administered by the PCI Security Standards Council. It is not published by ISO, it is not certified by an accredited certification body, and it does not use Stage 1 and Stage 2 audits or annual surveillance audits.
What is the difference between a Report on Compliance and a Self-Assessment Questionnaire?
A Report on Compliance is produced by a Qualified Security Assessor and records in detail how each requirement was tested and met. A Self-Assessment Questionnaire is completed by the entity itself where it is eligible to do so. Both are accompanied by a signed Attestation of Compliance.
Who decides whether an organisation needs a QSA assessment or can self-assess?
The payment brands set the levels and the associated validation requirements, and these are communicated through the acquiring bank. An entity should confirm its level and its validation route with its acquirer or the relevant payment brand before starting.
What is an Approved Scanning Vendor?
An ASV is an organisation approved by the PCI Security Standards Council to perform external vulnerability scans of internet facing systems in the cardholder data environment. Scanning must be carried out by an ASV and passing results retained as evidence.
Univate Solutions supports organisations across India, the GCC, South East Asia, Africa and the United States. Speak to a consultant about your scope.
Related Services & Resources
Univate Global delivers ISO certifications, data privacy compliance and cybersecurity frameworks across its international markets.








