Every organization that accepts, processes, stores, or transmits payment card data must protect that data. The global standard for payment account data protection is PCI DSS, or Payment Card Industry Data Security Standard. The PCI Security Standards Council (PCI SSC) develops and maintains this standard.
What Is PCI DSS?
According to the PCI Security Standards Council:
“PCI DSS provides a baseline of technical and operational requirements designed to protect payment account data.”
What is PCI DSS? It is a data security standard that defines technical and operational requirements for protecting payment account data. The standard also supports consistent security practices across the global payment ecosystem.
PCI DSS applies to entities that store, process, or transmit cardholder data (CHD) or sensitive authentication data (SAD). It also applies to entities that can affect the security of the cardholder data environment (CDE).
These entities include merchants, payment processors, acquirers, issuers, and service providers involved in card payment processing.
Official source: PCI Security Standards Council – PCI DSS
Why Is Payment Data Security Important?
The main objective of PCI DSS is to protect payment account data through structured and verifiable security controls. As a result, organizations can establish a consistent approach to payment data security.
From a business perspective, implementing the standard can help organizations:
- Reduce the risk of payment card data breaches and related financial or reputational impacts.
- Meet contractual obligations from payment brands, acquirers, and business partners.
- Strengthen customer confidence in payment data protection.
- Establish security controls that are measurable, documented, and auditable.
However, PCI SSC does not enforce compliance. Payment brands and/or acquiring banks determine compliance obligations and enforcement requirements.
What Are the Six PCI DSS Control Objectives?
The PCI DSS standard v4.0.1 organizes 12 primary requirements into six control objectives:
| Control Objective | Requirements |
|---|---|
| Build and Maintain a Secure Network and Systems | Req. 1 & 2: Network security controls and secure configurations |
| Protect Account Data | Req. 3 & 4: Stored account data and transmission over open networks |
| Maintain a Vulnerability Management Program | Req. 5 & 6: Malware protection, secure software, and vulnerability management |
| Implement Strong Access Control Measures | Req. 7, 8 & 9: Access control, authentication, and physical access |
| Regularly Monitor and Test Networks | Req. 10 & 11: Logging, monitoring, and security testing |
| Maintain an Information Security Policy | Req. 12: Policies, risk analysis, third-party management, and incident response |
PCI DSS v4.0.1, published in June 2024, is a limited revision of v4.0. It provides corrections and clarifications without adding or removing requirements.
Since March 31, 2025, requirements that were previously future-dated have become mandatory.
Which Organizations Need PCI DSS?
The standard applies to entities that:
- Store, process, or transmit cardholder data (CHD) or sensitive authentication data (SAD).
- Can affect the security of the cardholder data environment (CDE).
This includes merchants, e-commerce businesses, payment processors, service providers, acquirers, issuers, and other organizations involved in the card payment ecosystem.
For example, an e-commerce company may use an external payment gateway and avoid storing card data in its internal systems. Even so, the company still needs to understand its payment flow and determine its scope.
The organization should also review its payment integration method and responsibilities with the payment provider. Using a third-party payment page does not automatically remove applicable security requirements.
Related article: What Is SOC 2? Definition, Objectives, and Benefits for Companies
How Does PCI DSS Certification Work?
The term PCI DSS certification often appears in searches. However, organizations should distinguish certification from compliance and validation.
PCI SSC does not issue a generic compliance certificate. Instead, the Council recognizes official validation documents that use PCI SSC templates.
These documents include:
- Report on Compliance (ROC)
- Attestation of Compliance (AOC)
- Self-Assessment Questionnaire (SAQ)
- Attestation of Scan Compliance for ASV scans
Therefore, certificates or compliance documents that do not use official PCI SSC templates are not recognized as valid validation documentation.
Official source: PCI SSC FAQ – Compliance Certificates
How Can Companies Prepare for PCI DSS?
Organizations should determine their scope before working through a security checklist. This approach helps teams focus on the systems, data, processes, and controls that actually matter.
A practical approach is:
SCOPE → CONTROL → EVIDENCE → VALIDATE
| Stage | Focus |
|---|---|
| 1. Scope | Identify systems, data, processes, networks, and third parties within the CDE or able to affect CDE security. |
| 2. Control | Map applicable requirements to existing technical and operational controls. |
| 3. Evidence | Prepare evidence that demonstrates how controls operate, such as configurations, logs, policies, and testing results. |
| 4. Validate | Determine the appropriate assessment method, such as an SAQ or ROC, and prepare the required validation documents. |
The framework above is a practical approach, not an official PCI SSC framework. Meanwhile, PCI SSC provides guidance on scoping and segmentation through its official Guidance for PCI DSS Scoping and Segmentation document.
Need Support for PCI DSS Compliance?
Preparing for PCI DSS compliance requires a clear understanding of scope, applicable requirements, security controls, and supporting evidence.
If your organization needs to determine its scope, evaluate control readiness, or prepare for assessment and validation, CBQA Global can help discuss your requirements based on your business and technology environment.
CBQA Global provides Certification, Audit, Training, Verification, and Validation services to support organizational assurance and compliance needs.
Contact CBQA Global:
Email: info@cbqaglobal.com
Email Marketing: marketing.cbqaglobal@gmail.com
WhatsApp: 08118468777
Phone: +62 21 2781 4200
CBQA Global. We Inspire in Trust.
Certification | Audit | Training | Sustainability