GRC Oversight

PCI DSS

The Payment Card Industry Data Security Standard is a set of security requirements for organizations that store, process, or transmit cardholder data. The current major version is PCI DSS v4.0.

Governed by PCI Security Standards Council
What it is

What PCI DSS is, in plain terms

The Payment Card Industry Data Security Standard is a security standard maintained by the PCI Security Standards Council for any organization that stores, processes, or transmits cardholder data. It is organized into six goals and twelve high-level requirements, and the current major version, v4.0, introduced a more flexible 'customized approach' alongside the traditional defined approach. Validation rigor scales with transaction volume.

Typical effort & timeline

How you validate depends on volume: smaller entities may complete a Self-Assessment Questionnaire (SAQ), while larger ones undergo a Report on Compliance (ROC) by a Qualified Security Assessor. Scope reduction is often the biggest lever on effort.

Who needs it

Is this framework for you?

  • Merchants and service providers that handle payment card data.
  • SaaS and platform companies whose systems touch cardholder data flows.
  • Organizations whose acquirers or partners require PCI validation.
About the framework

Key facts about PCI DSS

  • Organized around six goals and twelve high-level requirements.
  • Applies to any entity that stores, processes, or transmits cardholder data.
  • Validation level depends on transaction volume (e.g., SAQ vs. ROC by a QSA).
  • v4.0 introduced a customized-approach option alongside the defined approach.

Public information about the framework itself. We don't claim certifications, assessment status, or authorizations for our own product.

With this platform

How we help with PCI DSS

  • Map the twelve requirements to tests and evidence.
  • Monitor in-scope systems and configurations continuously.
  • Organize evidence the way an assessor expects to receive it.
  • Reuse overlapping security evidence from SOC 2 or ISO 27001.
Step by step

Get and stay compliant

How the platform supports your PCI DSS program, from first scope to ongoing monitoring.

Scope the cardholder data environment

Identify where cardholder data flows and minimize the systems in scope.

Map the twelve requirements

Connect each requirement to tests and the evidence that demonstrates it.

Monitor continuously

Keep in-scope systems and configurations monitored so they stay compliant between assessments.

Validate

Organize evidence for an SAQ or a QSA-led ROC depending on your level.

Representative areas

What PCI DSS covers

Public, high-level control or requirement areas, for orientation, not a complete control list.

Build & maintain secure networks
Protect cardholder data
Vulnerability management
Strong access control
Monitor & test networks
Information security policy
Do it once

Reuse evidence across frameworks

PCI DSS shares controls with frameworks you may already run. A passing test can satisfy requirements in more than one place, so adding the next framework means reusing work, not repeating it.

FAQ

Common questions about PCI DSS

PCI DSS v4.0 is the current major version; it added a customized-approach option alongside the defined approach.

A Self-Assessment Questionnaire is used by lower-volume entities; a Report on Compliance by a Qualified Security Assessor applies at higher volumes.

Reducing the cardholder data environment scope is usually the most effective way to lower both effort and risk.

Get audit-ready for PCI DSS

Get a guided demo, or start by scanning any domain for free.