What Is PCI DSS? A Plain-English Guide
The Payment Card Industry Data Security Standard, or PCI DSS, is a set of security requirements for any organisation that stores, processes, or transmits cardholder data.
It is maintained by the PCI Security Standards Council, founded by the major card brands (Visa, Mastercard, American Express, Discover, and JCB). Compliance is enforced through your acquiring bank and the card brands rather than a single government regulator.
Who has to comply
Any merchant or service provider that touches payment card data is in scope, from a small online store to a global payment processor.
Even if you outsource payments to a provider like Stripe, you usually still have a reduced compliance obligation, typically a short self-assessment questionnaire.
What counts as cardholder data
Cardholder data includes the primary account number (PAN), and may include cardholder name, expiry date, and service code. Sensitive authentication data, such as the full magnetic stripe, CVV, or PIN, must never be stored after authorisation.
Reducing where this data lives in your systems is the single most effective way to shrink your PCI scope.
Why it matters
Non-compliance can lead to fines from the card brands, higher transaction fees, and in serious cases the loss of the ability to accept cards. After a breach, fines and forensic costs can be severe.
PCI DSS policy templates
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Automate PCI DSS with Vanta
Vanta maps the controls, collects evidence automatically, and keeps you audit-ready. The market-leading compliance automation platform.
FAQ
- Is PCI DSS a law?
- No, it is a contractual standard enforced by the card brands and your acquiring bank, not government legislation. But for most businesses it is effectively mandatory to accept cards.
- Do I still need PCI DSS if I use Stripe or PayPal?
- Usually yes, but with a much smaller obligation, often a simplified self-assessment questionnaire, because the provider handles most of the risk.