PCI DSS
Who needs it
Any merchant or service provider that stores, processes, or transmits payment card data, regardless of company size; the validation burden scales with transaction volume, but the underlying requirements apply to everyone in scope.
Key requirements
12 core requirements spanning network security, cardholder data protection (including encryption), vulnerability management, strong access control, monitoring and testing, and a formal information security policy.
Cyber/privacy implications
Cardholder data environment scope directly determines audit burden, so network segmentation isolating payment systems from the rest of your infrastructure is often the single highest-leverage control.
Assessment methodology
Cardholder data environment scoping and network segmentation review, gap assessment against the 12 requirements, and validation-method determination (SAQ vs. formal Report on Compliance with a QSA).
Implementation phases
Scope
Map the cardholder data environment and confirm segmentation.
Remediate
Close gaps against the 12 requirements, prioritizing encryption and access control.
Validate
Complete the appropriate SAQ or support a QSA-led Report on Compliance.
Evidence & documentation requirements
Network diagrams showing cardholder data flow and segmentation, encryption and key management documentation, vulnerability scan results, and access control logs.
Common mistakes
Under-scoping the cardholder data environment, which looks favorable short-term but creates real exposure and audit risk; treating quarterly vulnerability scans as sufficient without addressing findings between scan cycles.
Related standards
Expert review
FAQ
Request a Gap Assessment
Map your cardholder data environment and see where your controls stand.
Request a Gap Assessment →