PCI DSS · 7 min read · Updated 2026-06-05

What Is PCI DSS? A Plain-English Guide

The Payment Card Industry Data Security Standard, or PCI DSS, is a set of security requirements for any organisation that stores, processes, or transmits cardholder data.

It is maintained by the PCI Security Standards Council, founded by the major card brands (Visa, Mastercard, American Express, Discover, and JCB). Compliance is enforced through your acquiring bank and the card brands rather than a single government regulator.

Who has to comply

Any merchant or service provider that touches payment card data is in scope, from a small online store to a global payment processor.

Even if you outsource payments to a provider like Stripe, you usually still have a reduced compliance obligation, typically a short self-assessment questionnaire.

What counts as cardholder data

Cardholder data includes the primary account number (PAN), and may include cardholder name, expiry date, and service code. Sensitive authentication data, such as the full magnetic stripe, CVV, or PIN, must never be stored after authorisation.

Reducing where this data lives in your systems is the single most effective way to shrink your PCI scope.

Why it matters

Non-compliance can lead to fines from the card brands, higher transaction fees, and in serious cases the loss of the ability to accept cards. After a breach, fines and forensic costs can be severe.

PCI DSS policy templates

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map

Automate PCI DSS with Vanta

Vanta maps the controls, collects evidence automatically, and keeps you audit-ready. The market-leading compliance automation platform.

FAQ

Is PCI DSS a law?
No, it is a contractual standard enforced by the card brands and your acquiring bank, not government legislation. But for most businesses it is effectively mandatory to accept cards.
Do I still need PCI DSS if I use Stripe or PayPal?
Usually yes, but with a much smaller obligation, often a simplified self-assessment questionnaire, because the provider handles most of the risk.