Key facts
- Controls
- 12 high-level requirements covering ~300 sub-requirements (v4.0.1)
- Recertification cycle
- Annual revalidation (ROC or SAQ)
- Ongoing oversight
- Quarterly ASV scans for in-scope systems
- Public registry
- PCI SSC Qualified Security Assessor list β
- Common gap categories
- Network segmentation (Req 1); Encryption in transit and at rest (Req 3, 4); Vulnerability and patch management (Req 6, 11); Logging and monitoring (Req 10); Strong authentication (Req 8)
- Related standards
What is PCI DSS?
A global security standard (version 4.0, current release 4.0.1) maintained by the PCI Security Standards Council (founded by Visa, Mastercard, Amex, Discover, JCB), intended for entities that store, process, or transmit cardholder or sensitive authentication data, or that can impact the security of the cardholder data environment. Version 3.2.1 was retired March 31, 2024.
Is PCI DSS a certification or an attestation?
PCI DSS is a contractual compliance requirement, not a government certification. Validation is documented by the applicable SAQ or a QSA-led Report on Compliance (ROC), with a related Attestation of Compliance (AOC). The payment brand, acquirer, or other compliance-accepting entity sets the required method. PCI SSC issues no certificates.
Who needs PCI DSS?
Merchants, payment processors, SaaS platforms, and service providers that store, process, or transmit cardholder or sensitive authentication data, or can impact the security of the cardholder data environment. The payment brand, acquirer, or other compliance-accepting entity sets the validation method based on the entity's role, merchant transaction volume where applicable, and program rules; a QSA-led ROC is used when required.
What does PCI DSS cost and how long does it take?
Merchant SAQ path (merchant Levels 2β4): $1Kβ$40K over 3β6 months. Merchant QSA/ROC path (merchant Level 1): $30Kβ$200K for the assessment alone over 6β12 months end-to-end. These merchant-path estimates do not determine a service provider's validation method.
The SAQ vs. ROC split is the single biggest cost variable. A Level 4 SaaS startup and a Level 1 retailer face order-of-magnitude different costs.