Skip to main content
Security & PCI5 min read

What Is PCI DSS?

PCI DSS is the Payment Card Industry Data Security Standard — a set of requirements designed to protect cardholder data, maintained by the PCI Security Standards Council and applicable to any organization that stores, processes, or transmits card data.

By ONKORE Payment Solutions

Direct Answer

PCI DSS is the Payment Card Industry Data Security Standard — a set of requirements designed to protect cardholder data, maintained by the PCI Security Standards Council and applicable to any organization that stores, processes, or transmits card data.

Direct Answer

PCI DSS (Payment Card Industry Data Security Standard) is a set of security requirements designed to protect cardholder data. It is maintained by the PCI Security Standards Council, which was founded by Visa, Mastercard, American Express, Discover, and JCB. PCI DSS applies to any organization — regardless of size — that stores, processes, or transmits cardholder data.

How It Works

PCI DSS organizes security requirements around goals such as building and maintaining secure networks, protecting cardholder data, maintaining a vulnerability-management program, implementing strong access controls, monitoring and testing networks, and maintaining an information-security policy. Depending on your transaction volume and how you handle card data, you validate compliance through a self-assessment questionnaire or a formal audit by a Qualified Security Assessor.

Key Points

  • PCI DSS applies to any business that accepts card payments, not just large enterprises.
  • Compliance requirements scale with your transaction volume and how you store or transmit card data.
  • Using validated, PCI-compliant payment terminals and gateways can reduce the systems you must secure yourself.
  • Non-compliance can result in fees, fines, or restrictions from your processor or acquiring bank.

What Merchants Should Know

Most merchants do not need to become PCI experts. Using PCI-compliant hardware, point-to-point encryption, and tokenization can shift much of the cardholder-data risk to your processor. Confirm with your processor which validation path applies to you, and complete your annual self-assessment on time to avoid non-compliance fees.

Related Resources

Related Guides

PCI Center

Share This Article

Ready to optimize your payments?

Get a free payment processing review and see how your rates compare.

PCI Compliant Guided onboarding No long-term contracts