Build & maintain a secure network
Requirements 1–2: install and maintain network security controls (firewalls) and apply secure configurations instead of vendor defaults.
Frameworks · Compliance & contractual
If you touch card payments, this one isn’t optional.
PCI DSS is the security standard that applies to any organization that stores, processes, or transmits payment-card data. Unlike NIST or ISO, it is not optional or aspirational: it is a contractual requirement imposed by the card brands through your bank and payment processor, and it carries real consequences (fines, higher fees, or losing the ability to take cards) if you ignore it.
Its single purpose is to protect cardholder data wherever it flows through your business, from a card reader at a counter to a checkout page on your website. It is maintained by the PCI Security Standards Council, the body the major card networks created to run it.
The current edition, v4.0.1 (2024), modernized the standard for today’s threats and gave organizations more flexibility in how they meet each requirement, alongside a stricter baseline for things like authentication.
PCI DSS is organized as twelve requirements grouped under six goals. The requirements are concrete and technical (secure your network, protect stored data, encrypt transmissions, manage access, monitor, and test) and they apply to your "cardholder data environment": the systems that store, process, or transmit card data, plus anything connected to them.
Scope is the most important concept to grasp. The more card data your systems touch, the larger and more expensive compliance becomes, which is why a core strategy is to shrink scope, for example by using a payment processor’s hosted page so card data never lands on your own systems. How you validate compliance (a Self-Assessment Questionnaire versus an on-site assessment by a Qualified Security Assessor) depends on your transaction volume and how you accept payments.
Requirements 1–2: install and maintain network security controls (firewalls) and apply secure configurations instead of vendor defaults.
Requirements 3–4: protect stored cardholder data and encrypt it whenever it is transmitted across open or public networks.
Requirements 5–6: protect against malware and develop and maintain secure systems and software, including timely patching.
Requirements 7–9: restrict access on a need-to-know basis, authenticate every user (with MFA), and restrict physical access to card data.
Requirements 10–11: log and monitor all access to systems and data, and regularly test security systems and processes.
Requirement 12: support information security with organizational policies, training, and programs.
PCI DSS applies to every merchant and service provider that accepts, processes, stores, or transmits payment cards, from a small retailer with a single terminal to an e-commerce platform handling millions of transactions. If you take card payments in any form, it applies to you.
The depth of effort scales with volume and method. A small business using a fully outsourced, hosted checkout may validate with a short Self-Assessment Questionnaire, while a large merchant or a service provider storing card data faces a full assessment by a Qualified Security Assessor. Reducing how much card data you handle is the most effective way to reduce both effort and risk.
It is not a general-purpose security framework; it protects card data specifically. Organizations that take payments still need a broader program (NIST, CIS) for everything PCI does not cover.
PCI DSS overlaps heavily with the CIS Controls and NIST CSF (firewalls, secure configuration, MFA, logging, and patching all appear in each), so a solid general security program does much of the PCI groundwork for you. The difference is that PCI is mandatory, narrowly focused on card data, and externally validated.
Think of PCI as a specific obligation layered on top of your foundational framework, not a substitute for it. The frameworks make you secure, and PCI proves, to your bank and the card brands, that the part of you that handles their data meets their baseline.
PCI DSS is technology-neutral; FioSec's seven layers are where its outcomes become real controls. Here is roughly where each one lands.
Free readiness checklist
Answer honestly across the 5 areas below for an instant read on where you stand. "Not sure" is a valid answer. Nothing is sent anywhere; your answers are scored right here in your browser.
Your result
Know your scope
—Protect the data
—Secure network & systems
—Control access
—Monitor, test & validate
—This is a self-assessment, not a formal audit or a guarantee of compliance. Talk to our team for a detailed gap review.
Authoritative source: PCI Security Standards Council (pcisecuritystandards.org)
FioSec helps Ontario organizations turn frameworks into working controls, vendor-agnostic, from assessment and design through implementation and ongoing support.