PCI DSS
The Payment Card Industry Data Security Standard is a set of security requirements for organizations that store, process, or transmit cardholder data. The current major version is PCI DSS v4.0.
What PCI DSS is, in plain terms
The Payment Card Industry Data Security Standard is a security standard maintained by the PCI Security Standards Council for any organization that stores, processes, or transmits cardholder data. It is organized into six goals and twelve high-level requirements, and the current major version, v4.0, introduced a more flexible 'customized approach' alongside the traditional defined approach. Validation rigor scales with transaction volume.
Typical effort & timeline
How you validate depends on volume: smaller entities may complete a Self-Assessment Questionnaire (SAQ), while larger ones undergo a Report on Compliance (ROC) by a Qualified Security Assessor. Scope reduction is often the biggest lever on effort.
Is this framework for you?
- Merchants and service providers that handle payment card data.
- SaaS and platform companies whose systems touch cardholder data flows.
- Organizations whose acquirers or partners require PCI validation.
Key facts about PCI DSS
- Organized around six goals and twelve high-level requirements.
- Applies to any entity that stores, processes, or transmits cardholder data.
- Validation level depends on transaction volume (e.g., SAQ vs. ROC by a QSA).
- v4.0 introduced a customized-approach option alongside the defined approach.
Public information about the framework itself. We don't claim certifications, assessment status, or authorizations for our own product.
How we help with PCI DSS
- Map the twelve requirements to tests and evidence.
- Monitor in-scope systems and configurations continuously.
- Organize evidence the way an assessor expects to receive it.
- Reuse overlapping security evidence from SOC 2 or ISO 27001.
Get and stay compliant
How the platform supports your PCI DSS program, from first scope to ongoing monitoring.
Scope the cardholder data environment
Identify where cardholder data flows and minimize the systems in scope.
Map the twelve requirements
Connect each requirement to tests and the evidence that demonstrates it.
Monitor continuously
Keep in-scope systems and configurations monitored so they stay compliant between assessments.
Validate
Organize evidence for an SAQ or a QSA-led ROC depending on your level.
What PCI DSS covers
Public, high-level control or requirement areas, for orientation, not a complete control list.
Reuse evidence across frameworks
PCI DSS shares controls with frameworks you may already run. A passing test can satisfy requirements in more than one place, so adding the next framework means reusing work, not repeating it.
Common questions about PCI DSS
PCI DSS v4.0 is the current major version; it added a customized-approach option alongside the defined approach.
A Self-Assessment Questionnaire is used by lower-volume entities; a Report on Compliance by a Qualified Security Assessor applies at higher volumes.
Reducing the cardholder data environment scope is usually the most effective way to lower both effort and risk.
Get audit-ready for PCI DSS
Get a guided demo, or start by scanning any domain for free.