Skip to content
FioSec Consulting

Frameworks · Compliance & contractual

Payment Card Industry Data Security Standard

If you touch card payments, this one isn’t optional.

Maintained by
PCI Security Standards Council (founded by the major card brands)
Origin
International · current version PCI DSS v4.0.1 (2024)
Certifiable?
Validated by self-assessment (SAQ) or an external assessor (QSA), depending on volume.

What it is

PCI DSS is the security standard that applies to any organization that stores, processes, or transmits payment-card data. Unlike NIST or ISO, it is not optional or aspirational: it is a contractual requirement imposed by the card brands through your bank and payment processor, and it carries real consequences (fines, higher fees, or losing the ability to take cards) if you ignore it.

Its single purpose is to protect cardholder data wherever it flows through your business, from a card reader at a counter to a checkout page on your website. It is maintained by the PCI Security Standards Council, the body the major card networks created to run it.

The current edition, v4.0.1 (2024), modernized the standard for today’s threats and gave organizations more flexibility in how they meet each requirement, alongside a stricter baseline for things like authentication.

How it's structured

PCI DSS is organized as twelve requirements grouped under six goals. The requirements are concrete and technical (secure your network, protect stored data, encrypt transmissions, manage access, monitor, and test) and they apply to your "cardholder data environment": the systems that store, process, or transmit card data, plus anything connected to them.

Scope is the most important concept to grasp. The more card data your systems touch, the larger and more expensive compliance becomes, which is why a core strategy is to shrink scope, for example by using a payment processor’s hosted page so card data never lands on your own systems. How you validate compliance (a Self-Assessment Questionnaire versus an on-site assessment by a Qualified Security Assessor) depends on your transaction volume and how you accept payments.

Build & maintain a secure network

Requirements 1–2: install and maintain network security controls (firewalls) and apply secure configurations instead of vendor defaults.

Protect account data

Requirements 3–4: protect stored cardholder data and encrypt it whenever it is transmitted across open or public networks.

Maintain a vulnerability program

Requirements 5–6: protect against malware and develop and maintain secure systems and software, including timely patching.

Implement strong access control

Requirements 7–9: restrict access on a need-to-know basis, authenticate every user (with MFA), and restrict physical access to card data.

Monitor & test networks

Requirements 10–11: log and monitor all access to systems and data, and regularly test security systems and processes.

Maintain a security policy

Requirement 12: support information security with organizational policies, training, and programs.

Who it's for

PCI DSS applies to every merchant and service provider that accepts, processes, stores, or transmits payment cards, from a small retailer with a single terminal to an e-commerce platform handling millions of transactions. If you take card payments in any form, it applies to you.

The depth of effort scales with volume and method. A small business using a fully outsourced, hosted checkout may validate with a short Self-Assessment Questionnaire, while a large merchant or a service provider storing card data faces a full assessment by a Qualified Security Assessor. Reducing how much card data you handle is the most effective way to reduce both effort and risk.

It is not a general-purpose security framework; it protects card data specifically. Organizations that take payments still need a broader program (NIST, CIS) for everything PCI does not cover.

How it compares

PCI DSS overlaps heavily with the CIS Controls and NIST CSF (firewalls, secure configuration, MFA, logging, and patching all appear in each), so a solid general security program does much of the PCI groundwork for you. The difference is that PCI is mandatory, narrowly focused on card data, and externally validated.

Think of PCI as a specific obligation layered on top of your foundational framework, not a substitute for it. The frameworks make you secure, and PCI proves, to your bank and the card brands, that the part of you that handles their data meets their baseline.

How it maps to a Layered Defence

PCI DSS is technology-neutral; FioSec's seven layers are where its outcomes become real controls. Here is roughly where each one lands.

Free readiness checklist

How ready are you for PCI DSS?

Answer honestly across the 5 areas below for an instant read on where you stand. "Not sure" is a valid answer. Nothing is sent anywhere; your answers are scored right here in your browser.

Know your scope

The first and most important question.

Do you know exactly where card data is stored, processed, or transmitted across your business?
Have you minimized scope, e.g. using a hosted/tokenized payment page so card data never touches your systems?

Protect the data

Requirements 3–4.

Do you avoid storing card data you don’t need, and protect anything you must keep?
Is card data encrypted whenever it crosses public networks?

Secure network & systems

Requirements 1–2, 5–6.

Are network security controls (firewalls) in place and is the environment segmented?
Are systems hardened from defaults, patched promptly, and protected against malware?

Control access

Requirements 7–9.

Is access to card data restricted to need-to-know, with MFA on access to the environment?

Monitor, test & validate

Requirements 10–12.

Are access and activity logged and monitored, with regular vulnerability scans or testing?
Do you complete the required validation (the right SAQ or assessment) each year?

No email required; scored in your browser, never sent anywhere.

Authoritative source: PCI Security Standards Council (pcisecuritystandards.org)

Explore other frameworks

Need help putting PCI DSS into practice?

FioSec helps Ontario organizations turn frameworks into working controls, vendor-agnostic, from assessment and design through implementation and ongoing support.