What Is PCI DSS Compliance and Why It Matters
Understand PCI DSS compliance and secure your cardholder data. Learn the requirements and certification process here.
What Is PCI DSS Compliance

What Is PCI DSS Compliance Certification
What Is PCI DSS Level Compliance
PCI DSS Compliance Levels
-
Level 1
-
Applicable to: Merchants that process more than 6 million credit card transactions annually, including large retailers and financial institutions.
-
Requirements:
-
Annual on-site audit by a Qualified Security Assessor (QSA) approved by the PCI SSC.
-
Quarterly network scans by an Approved Scanning Vendor (ASV).
-
Completion of an Attestation of Compliance (AOC) form.
-
-
Example: Large multinational retailers and financial institutions.
-
-
Level 2
-
Applicable to: Merchants that process between 1 and 6 million credit card transactions annually.
-
Requirements:
-
Annual Self-Assessment Questionnaire (SAQ) completion.
-
Quarterly network scans by an ASV.
-
For high-security risk merchants (e.g., those completing SAQ A, A-EP, or D), an annual audit by a QSA or Internal Security Assessor (ISA) is required.
-
-
Example: Mid-sized businesses with significant transaction volumes.
-
-
Level 3
-
Applicable to: Merchants that process between 20,000 and 1 million e-commerce transactions annually.
-
Requirements:
-
Annual Self-Assessment Questionnaire (SAQ) completion.
-
Quarterly network scans by an ASV.
-
Completion of an Attestation of Compliance (AOC) form.
-
-
Example: Smaller e-commerce operations with moderate transaction volumes.
-
-
Level 4
-
Applicable to: Merchants that process fewer than 20,000 e-commerce transactions or up to 1 million total credit card transactions annually.
-
Requirements:
-
Annual Self-Assessment Questionnaire (SAQ) completion.
-
Quarterly network scans by an ASV.
-
-
Example: Small businesses, local retailers, and service providers with smaller transaction volumes.
-
Related Terms
-
Annual Number of Credit or Debit Card Transactions: The total number of credit or debit card transactions processed by a merchant in a year. This number determines the PCI DSS compliance level.
-
E-commerce Transactions: Transactions conducted over the internet, typically involving credit or debit cards.
-
Merchants: Businesses that accept credit or debit card payments from customers.
-
Real-World Transactions: Transactions that occur in physical stores or through other non-digital means.
-
PCI DSS Compliance Levels: The four levels of compliance (Level 1, Level 2, Level 3, Level 4) based on the number of annual transactions.
-
Approved Scanning Vendor (ASV): A vendor approved by the PCI SSC to perform quarterly network scans to ensure compliance.
-
Qualified Security Assessor (QSA): A professional approved by the PCI SSC to conduct on-site audits for Level 1 merchants.
-
Self-Assessment Questionnaire (SAQ): A form completed by merchants to self-assess their compliance with PCI DSS requirements.
-
Attestation of Compliance (AOC): A form completed by merchants to detail their internal security standards and processes.
What Is Required for PCI DSS Compliance
-
Install and Maintain Firewall Configurations
-
Create and maintain standards for firewall and router configurations to ensure that cardholder data is secure against inbound or outbound access. Regularly review and update these configuration rules.
-
-
Do Not Use Vendor-Supplied Defaults
-
Avoid using vendor-provided defaults and settings for network devices. Change them or deactivate unnecessary default accounts, use strong cryptography, and craft configuration standards for maximum security.
-
-
Protect Stored Cardholder Data
-
Cardholder data should only be retained when necessary for business operations. Limit storage, make sensitive authentication data unrecoverable, and obscure Primary Account Numbers (PAN) when displayed to protect against fraud or breaches.
-
-
Encrypt Transmission of Cardholder Data Across Open Networks
-
Use strong encryption standards and secure protocols to protect sensitive cardholder data transmission over open/public networks. Follow best industry practices and standards to maintain authentication and shield transmission.
-
-
Protect Against Malware and Keep Anti-Virus Software Updated
-
Install anti-virus software on personal computers and servers. Regularly assess evolving malware threats, conduct in-depth scans, and ensure all anti-virus tools are up-to-date. Monitor anti-virus mechanisms to ensure their proper functioning.
-
-
Maintain Secure Systems and Applications
-
Prioritize security by promptly installing relevant security updates. Maintain and protect systems and applications from threats by performing yearly assessments of application vulnerabilities and using automated tools.
-
-
Restrict Access to Cardholder Data
-
Limit access to system components and cardholder data to specific employees. Implement access control systems and document security policies and procedures consistently across the organization to ensure awareness and compliance.
-
-
Authenticate System Access
-
Ensure every individual accessing the system or related components is uniquely identified by assigning them a distinct user ID. Develop policies and procedures to manage user identification effectively for both regular users and administrators across all system components.
-
-
Restrict Physical Access to Cardholder Data
-
Implement effective facility entry controls to regulate and oversee physical access to systems. Establish procedures to easily differentiate between staff and visitors, such as issuing ID badges.
-
-
Track and Monitor All Access to Network Resources and Cardholder Data
-
Use logging software and mechanisms to track and monitor access to network resources and cardholder data. Implement automated audit trails, utilize time synchronization technology, and review security events critically to identify anomalies.
-
-
Regularly Test Security Systems and Processes
-
Regularly test security systems and processes to identify vulnerabilities. This includes quarterly network scans by Approved Scanning Vendors (ASVs) and annual penetration testing for Level 1 merchants.
-
-
Maintain a Policy That Addresses Information Security
-
Develop and maintain a comprehensive information security policy that addresses all personnel and security needs. Ensure that all employees are aware of and adhere to these policies.
-
Related Terms
-
PCI Requirement 6.6: This requirement includes options to address common threats to cardholder data in web application environments, such as e-commerce. It involves application reviews and the use of web application firewalls.
-
Cardholder Data Access: Limiting access to cardholder data to only those who need it for business purposes.
-
Cardholder Data Transmissions: Ensuring that cardholder data is encrypted during transmission over open networks.
-
Firewall Configuration: Setting up and maintaining firewalls to protect cardholder data from unauthorized access.
-
Physical Access: Controlling physical access to systems that store or process cardholder data.
-
Secure Cardholder Data: Protecting stored cardholder data using encryption and other protective measures.
-
Security Infrastructure: The overall security measures and systems in place to protect cardholder data.
-
Stored Cardholder Data: Data that is retained in the system, which must be protected and limited.
-
System Passwords: Changing default passwords and using strong, unique passwords for system access.
-
Tracked and Monitored Access: Logging and monitoring all access to cardholder data and network resources to detect and respond to security incidents.
