Glossary
What is PCI DSS?
What is PCI DSS?
PCI DSS (Payment Card Industry Data Security Standard) is a set of security requirements designed to ensure that all organizations that accept, process, store, or transmit credit card information maintain a secure environment. It is managed by the PCI Security Standards Council (PCI SSC).
The 12 requirements
PCI DSS organizes controls into 12 high-level requirements:
- Install and maintain network security controls
- Apply secure configurations to all system components
- Protect stored account data
- Protect cardholder data with strong cryptography during transmission
- Protect all systems and networks from malicious software
- Develop and maintain secure systems and software
- Restrict access to system components and cardholder data by business need to know
- Identify users and authenticate access to system components
- Restrict physical access to cardholder data
- Log and monitor all access to system components and cardholder data
- Test security of systems and networks regularly
- Support information security with organizational policies and programs
Compliance levels
PCI DSS defines four merchant levels based on annual transaction volume:
| Level | Transactions per year | Validation |
|---|---|---|
| 1 | Over 6 million | Annual on-site audit by QSA |
| 2 | 1-6 million | Annual SAQ + quarterly network scan |
| 3 | 20,000-1 million (e-commerce) | Annual SAQ + quarterly network scan |
| 4 | Under 20,000 (e-commerce) or up to 1 million (other) | Annual SAQ + quarterly network scan |
PCI DSS 4.0
Version 4.0, released in March 2022, introduced significant changes:
- Customized approach — organizations can meet objectives with alternative controls if they can demonstrate equivalent security
- Targeted risk analysis — more flexibility in defining control frequencies based on risk
- Enhanced authentication — multi-factor authentication required for all access to the cardholder data environment
- Expanded scope — additional requirements for e-commerce, phishing protections, and automated log reviews
How episki helps with PCI DSS
episki maps controls to PCI DSS requirements, tracks evidence for QSA reviews, and connects cardholder data environment documentation to relevant controls. Learn more on our PCI DSS compliance page.
See how episki handles this
Start a free trial and explore controls, evidence, and automation firsthand.