
Sagar Joshi
Sagar Joshi is a former content marketing specialist at G2 in India. He is an engineer with a keen interest in data analytics and cybersecurity. He writes about topics related to them. You can find him reading books, learning a new language, or playing pool in his free time.
Last updated: August 10, 2026
What is PCI compliance?
PCI compliance is a set of security standards, formally the Payment Card Industry Data Security Standard (PCI DSS), that any business that accepts, stores, processes, or transmits credit card data must follow to prevent fraud and data theft. The standards are set by the PCI Security Standards Council and enforced by the major card brands like Visa and Mastercard.
PCI compliance is a continuous effort to protect cardholder data wherever it is stored, transmitted, or processed. Many organizations manage it using security compliance software that automates evidence collection, continuous monitoring, and PCI DSS reporting.
As of 2026, the current version of the standard is PCI DSS v4.0.1, released in 2024. All v4.0 requirements became mandatory on March 31, 2025, replacing the older v3.2.1 standard, so businesses should validate against v4.0.1 today.
TL;DR: PCI compliance definition, levels, and requirements
PCI compliance means following the PCI DSS, the card industry's security standard for protecting cardholder data. A business's obligations scale with its yearly transaction volume across four levels, and compliance rests on 12 core requirements covering network security, encryption, access control, monitoring, and security policy.
What are the PCI compliance levels?
There are four PCI compliance levels, determined by how many card transactions a business processes per year, and the level sets how a business must validate compliance.
- Level 1: Merchants that process over 6 million card transactions per year.
- Level 2: Merchants that process 1 to 6 million card transactions per year.
- Level 3: Merchants that process 20,000 to 1 million card transactions per year.
- Level 4: Merchants that process fewer than 20,000 card transactions per year.
For organizations at PCI compliance level 1, achieving PCI compliance requires external audits by a qualified security assessor (QSA) or an internal security assessor (ISA). QSA or ISA conducts an on-site evaluation to:
- Validate the scope of assessment
- Review technical information and documentation,
- Determine if PCI requirements are met
- Offer guidance and support during the compliance process
- Evaluate compensating controls
After a successful evaluation, the qualified security assessor submits a Report on Compliance (RoC) to the organization’s operational banks to demonstrate compliance.
PCI compliance Level 2 organizations should also complete an RoC.
Organizations at Levels 3 to 4 can complete a self-assessment questionnaire instead of external audits to determine compliance.
What are the benefits of PCI DSS compliance?
The benefits of PCI DSS compliance include layered security, protection against evolving threats, a lower risk of data breaches, and stronger customer trust. PCI compliance regulations help protect both customers and businesses.
- PCI DSS compliance ensures that company assets have multiple layers of security.
- It enlists evolving threats and attack vectors, making the data environment more secure.
- PCI DSS involves setting up firewalls, SIEM systems, and other security infrastructure to gather threat intelligence in the event of anomalies.
- PCI compliance emphasizes encrypting cardholder data, making a PCI DSS-compliant business a less valuable target for cybercriminals.
- PCI compliance principles put a strong focus on protecting cardholder data as it’s stored or transmitted. It emphasizes enforcing PCI principles with an appropriate security infrastructure to help organizations prevent data breaches.
- PCI DSS compliance builds and maintains customer trust and makes data security hassle-free.
- PCI compliance helps align businesses with industry-accepted standards in storing, processing, and transmitting cardholder information.
- PCI DSS compliance helps organizations comply with industry-recognized data security standards.
On G2, the security compliance platforms most often used for this, including Vanta, Drata, Sprinto, and Secureframe, are among the highest rated in the category, each holding 4.6 stars or higher across hundreds to thousands of reviews.
What are the 12 PCI DSS requirements?
The 12 PCI DSS requirements are grouped into six control objectives and cover network security, cardholder data protection, vulnerability management, access control, monitoring and testing, and security policy. They focus on achieving PCI compliance and protecting cardholder data from unauthorized access.
1. Install and maintain network security controls
Steps you can take to protect your network:
- Configure firewalls to secure the company network and regulate incoming and outgoing traffic according to organizational criteria.
- Use hardware firewalls and software firewalls to protect the network.
- Configure the firewalls for inbound and outbound traffic. If an attacker penetrates the system, it’ll be difficult for them to export the stolen information owing to outbound rules.
2. Apply secure configurations to all system components
To comply with the second requirement of PCI compliance:
- Change default passwords and implement system hardening and system configuration management.
- Address all vulnerabilities in the system, remediate and report them, and ensure that the system hardening standards align with industry best practices.
- Adopt system management software, which serves as a complete package for monitoring, scanning, and configuring devices and system hardening options.
- Verify that the system hardening standard is securely implemented as new devices and applications are introduced into the system environment.
3. Protect stored account data
Adopt the following measures to protect cardholder data against unauthorized access:
- Encrypt cardholder data using strong and industry-accepted encryption standards like AES-256.
- Ensure that the systems store confidential cardholder details in an encrypted format.
- Create and document the cardholder data (CHD) flow diagram. It’s a graphical representation of the data flow within an organization.
- Use a sensitive data discovery tool to find sensitive information like social security numbers in the company systems to encrypt or remove it.
4. Protect cardholder data with strong cryptography during transmission over open, public networks
Consider the following to encrypt the transmission of cardholder data across open or public networks:
- Identify how and where the data is being transmitted. Keep track of all areas where similar details are being sent.
- Make the transition from Secure Sockets Layer (SSL) and early versions of Transport Layer Security (TLS) to more secure versions of TLS.
- Check the gateways, terminal providers, service providers, and banks to see if they use updated encryption for transactional applications.
5. Protect all systems and networks from malicious software
Adopt the following measures to comply with the fifth PCI DSS requirement.
- Use antivirus software and anti-malware tools to protect systems from known malware.
- Update the antivirus software regularly.
- Gather information on emerging malware and the different ways it can penetrate company systems.
- Configure the systems and design processes to be alerted when any malicious activity occurs in the system environment.
- Run periodic malware scans to ensure that you have a process designed to implement it.
6. Develop and maintain secure systems and software
Practice the following methods to develop and maintain secure systems and applications:
- Patch security weaknesses with recent patches released by the software provider.
- Install the latest security updates and patch vulnerabilities in applications and systems that are crucial to the flow of card data.
- Install critical patches within a month of their release to ensure compliance
- Be proactive in patch management and implementation as soon as the patch is released.
7. Restrict access to system components and cardholder data by business need-to-know
Consider the following to restrict access to cardholder data:
- Ensure strict access controls to cardholder data by implementing role-based access control (RBAC) systems that grant access to cardholder details on a need-to-know basis.
- Refrain from creating group users or share a common user account with other users. It’ll be challenging to track data breaches.
8. Identify users and authenticate access to system components
Take the following steps to comply with the eighth requirement of the PCI DSS:
- Assign a unique ID to each user with computer access and create strong passwords to prevent unauthorized access.
- Create multiple layers of security when protecting user accounts.
- Use multi-factor authentication solutions to provide additional layers of defense and to shield your systems from attackers.
9. Restrict physical access to cardholder data
Important things to consider to comply with the ninth requirement of PCI DSS:
- Limit employee access to areas with stored cardholder data.
- Document employees with access to secure environments and those in need of access privileges. List all authorized device users, locations where the device isn’t allowed, and where it’s currently located. Note all applications that can be accessed on a device. Record what, where, when, and why devices are being used.
- Differentiate between employees and visitors in the organization, and use methods to monitor people with access to secure environments.
- Ensure that the user’s access privileges are removed, and physical access mechanisms like keys and access cards are disabled or returned when offboarding employees.
10. Log and monitor all access to system components and cardholder data
Crucial points to consider while tracking and monitoring access to network resources and cardholder data:
- Implement and maintain a logging system to view all logs and get alerts in the event of anomalies.
- Check the system event logs at least once a day to identify patterns, gather threat intelligence, and detect behaviors that contradict expected trends.
- Use security information and event management (SIEM) solutions to build and manage a centralized log collection system, monitoring, and inspection.
11. Test the security of systems and networks regularly
Follow the practices mentioned below to comply with the eleventh requirement of PCI DSS.
- Conduct frequent vulnerability scans to identify if the security weaknesses were successfully patched.
- Perform quarterly vulnerability scans for all external IPs and domains exposed in the cardholder data environment using a PCI-approved scanning vendor (ASV).
- Conduct regular penetration tests to identify different ways hackers can exploit vulnerabilities to safely configure your security systems and protect the data against similar malicious tactics. (Penetration test frequency depends on your self-assessment questionnaire (SAQ), environment, size, procedures, and other factors.
12. Support information security with organizational policies and programs
Adopt the following practices to comply with the final requirement of PCI DSS compliance:
- Document all policies, procedures, and evidence associated with the organization’s information security practices.
- Assess formal and annual risks to determine critical threats, vulnerabilities, and associated risks.
What is the difference between PCI DSS and SOC 2?
The difference between PCI DSS and SOC 2 is that PCI DSS is a mandatory standard specifically for protecting credit card data, while SOC 2 is a voluntary audit report that shows how a company safeguards customer data more broadly. Many companies pursue both, and they share a good deal of overlap in technical controls.
| PCI DSS | SOC 2 |
| Protects cardholder data such as card numbers, PINs, and account data. | Protects general customer data against the five trust services criteria. |
| Mandatory for any business that handles credit card payments. | Voluntary, but often required by B2B customers before a deal. |
| Prescriptive: a fixed set of 12 requirements and controls. | Flexible: controls are designed around the company's own risk profile. |
| Enforced by the card brands through fines and loss of processing rights. | Audited by a licensed CPA firm and driven by market demand. |
Related resources:
Frequently asked questions about PCI compliance
Here are the most commonly asked questions about PCI compliance.
Q1. Is PCI compliance a legal requirement?
PCI compliance is not a law in most places, but it is contractually required by the card brands and acquiring banks for any business that accepts card payments. A handful of jurisdictions also reference PCI DSS in their regulations, and failing to comply can still carry heavy financial and contractual consequences.
Q2. Who enforces PCI compliance?
PCI compliance is enforced by the major card brands (Visa, Mastercard, American Express, Discover, and JCB) through the acquiring banks that process a merchant's payments, not by a government agency. The PCI Security Standards Council writes and maintains the standard, while the card brands set and enforce the penalties.
Q3. What happens if a business is not PCI compliant?
A business that is not PCI compliant can face monthly fines from its acquiring bank, higher transaction fees, greater liability if a breach occurs, and ultimately lose the ability to accept card payments. After a breach, non-compliant organizations may also face forensic audit costs and reputational damage.
Q4. How much does PCI compliance cost?
The cost of PCI compliance varies widely by a business's level and complexity. Small merchants completing a self-assessment questionnaire may spend relatively little, while Level 1 organizations that need external audits, scanning, and remediation can spend significantly more each year. Compliance automation software can reduce the ongoing effort and cost.
Q5. Who is responsible for PCI compliance in a company?
PCI compliance is a shared responsibility: the merchant is ultimately accountable, but payment processors, gateways, and hosting providers each cover parts of the environment. Internally, it is usually led by security, IT, and compliance teams, with executive sponsorship because the requirements span technology, policy, and people.
To see how PCI fits alongside the other rules your business may need to meet, explore regulatory compliance and how organizations manage it.
