If your business accepts credit or debit card payments — whether in person, online, or over the phone — you've probably encountered the term PCI DSS. You may have been asked by your bank, payment processor, or a customer whether you're "PCI compliant." And you may have had no idea what that actually means or where to start.
This guide explains PCI DSS in plain language: what it is, who it applies to, what it requires, and how to begin figuring out your obligations.
What PCI DSS Actually Is
PCI DSS is a set of security requirements created to protect cardholder data — meaning a payment card's account number (the long number on the front, known as the Primary Account Number or PAN) along with related details like the cardholder name, expiration date, and service code. The standard protects that data wherever it lives: whenever it is stored, processed, or transmitted. It was established in 2006 by the Payment Card Industry Security Standards Council (PCI SSC), which was founded jointly by the major card brands: American Express, Discover, JCB, Mastercard, and Visa.
The standard exists because payment card fraud is a significant and ongoing problem. When cardholder data is stolen — whether through a data breach, a skimming device, or insecure systems — real people lose money and businesses face serious consequences. PCI DSS is the industry's framework for reducing that risk.
Who Does PCI DSS Apply To?
PCI DSS applies to any organization that stores, processes, or transmits cardholder data — and also to organizations that don't touch the data directly but could affect the security of the systems that do. In practice, this means:
- Merchants — businesses that accept payment cards as payment for goods or services
- Service providers — companies that process, store, or transmit cardholder data on behalf of other businesses, or that can otherwise impact its security
One important catch: outsourcing your card handling to a third party does not remove your responsibility. If you use a payment processor or gateway, you are still accountable for confirming that they protect the data, and some requirements continue to apply to you. The scale of your obligations depends on how you handle card data — what systems and processes touch it, and what your processor handles for you — not just whether you accept cards.
What Does "Compliance" Actually Mean?
PCI DSS compliance means demonstrating that your organization meets the requirements defined in the standard. The current version is PCI DSS v4.0.1.
The standard is organized around twelve high-level requirements covering areas like network security, access control, encryption, monitoring, and vulnerability management. Within those twelve requirements are hundreds of specific sub-requirements — which is part of why PCI DSS can feel overwhelming.
Not every requirement applies to every organization. Your specific compliance obligations depend on your cardholder data environment — how you accept payments, what systems touch card data, and what your payment processor handles on your behalf.
SAQs and Formal Assessments
Many merchants validate their compliance through a Self-Assessment Questionnaire (SAQ) — a document that asks questions about your security practices. There are several different SAQ types, and which one applies to you depends on how you accept and process payments.
Some merchants, and many service providers, are instead required to undergo a formal assessment conducted by a Qualified Security Assessor (QSA) — an independent, PCI SSC-qualified security professional — resulting in a Report on Compliance (ROC).
An important point that trips people up: whether you self-assess with an SAQ or need a formal QSA assessment, how often, and which SAQ applies, is not something you decide on your own. It is set by your acquiring bank or the payment brands, based on factors that include your transaction volume. Transaction volume affects how you validate your compliance — it does not change whether PCI DSS applies to you. PCI DSS applies to every organization that handles card data, regardless of size or volume.
The Most Common Source of Confusion
Most organizations don't struggle with PCI DSS because the requirements are impossible to meet. They struggle because they can't determine which requirements apply to them in the first place.
Which SAQ do I use? Am I even in scope? Does my payment processor handle this for me?
These are the questions that consume hours of research and often lead to expensive consultant engagements before any actual security work begins.
Where to Start
The most important first step is understanding your cardholder data environment — how payment data flows through your systems, what you store, and what your payment processor or gateway handles on your behalf. From there, you can determine your applicable SAQ and the specific requirements that apply to your situation.
That's exactly what PCI Clarity is built to help with.
Still Unsure Where You Stand?
PCI Clarity provides instant, authoritative guidance on your PCI DSS scope, applicable requirements, and next steps — built on a proprietary knowledge base assembled by practicing PCI professionals.
Try PCI Clarity Free →