Logo Menu

PaymentsΒ·Last verified

PCI DSS

Bottom line

PCI DSS is a contractual standard, not a government certification. Validation uses the applicable SAQ or, when required, a QSA-led Report on Compliance, with a related Attestation of Compliance. The payment brand, acquirer, or other compliance-accepting entity sets the method. Merchant-path costs span $1K–$40K (SAQ) to $30K–$200K (ROC).

Cost and timeline $1K–$200K / 3–12 months

Key facts

Controls
12 high-level requirements covering ~300 sub-requirements (v4.0.1)
Recertification cycle
Annual revalidation (ROC or SAQ)
Ongoing oversight
Quarterly ASV scans for in-scope systems
Common gap categories
Network segmentation (Req 1); Encryption in transit and at rest (Req 3, 4); Vulnerability and patch management (Req 6, 11); Logging and monitoring (Req 10); Strong authentication (Req 8)
Related standards
PCI PINPCI P2PEPCI 3DS CoreSOC 2

What is PCI DSS?

A global security standard (version 4.0, current release 4.0.1) maintained by the PCI Security Standards Council (founded by Visa, Mastercard, Amex, Discover, JCB), intended for entities that store, process, or transmit cardholder or sensitive authentication data, or that can impact the security of the cardholder data environment. Version 3.2.1 was retired March 31, 2024.

Is PCI DSS a certification or an attestation?

PCI DSS is a contractual compliance requirement, not a government certification. Validation is documented by the applicable SAQ or a QSA-led Report on Compliance (ROC), with a related Attestation of Compliance (AOC). The payment brand, acquirer, or other compliance-accepting entity sets the required method. PCI SSC issues no certificates.

Who needs PCI DSS?

Merchants, payment processors, SaaS platforms, and service providers that store, process, or transmit cardholder or sensitive authentication data, or can impact the security of the cardholder data environment. The payment brand, acquirer, or other compliance-accepting entity sets the validation method based on the entity's role, merchant transaction volume where applicable, and program rules; a QSA-led ROC is used when required.

What does PCI DSS cost and how long does it take?

Range $1K–$200K / 3–12 months

Merchant SAQ path (merchant Levels 2–4): $1K–$40K over 3–6 months. Merchant QSA/ROC path (merchant Level 1): $30K–$200K for the assessment alone over 6–12 months end-to-end. These merchant-path estimates do not determine a service provider's validation method.

One thing to watch

The SAQ vs. ROC split is the single biggest cost variable. A Level 4 SaaS startup and a Level 1 retailer face order-of-magnitude different costs.

Go deeper on this

Other frameworks buyers ask about

See all frameworks β†’