PCI Compliance

by Sagar Joshi
PCI compliance is the set of PCI DSS standards businesses must follow to protect credit card data. Learn its levels, 12 requirements, and benefits.
Sagar Joshi
SJ

Sagar Joshi

Sagar Joshi is a former content marketing specialist at G2 in India. He is an engineer with a keen interest in data analytics and cybersecurity. He writes about topics related to them. You can find him reading books, learning a new language, or playing pool in his free time.

Last updated: August 10, 2026

What is PCI compliance?

PCI compliance is a set of security standards, formally the Payment Card Industry Data Security Standard (PCI DSS), that any business that accepts, stores, processes, or transmits credit card data must follow to prevent fraud and data theft. The standards are set by the PCI Security Standards Council and enforced by the major card brands like Visa and Mastercard.

PCI compliance is a continuous effort to protect cardholder data wherever it is stored, transmitted, or processed. Many organizations manage it using security compliance software that automates evidence collection, continuous monitoring, and PCI DSS reporting.

As of 2026, the current version of the standard is PCI DSS v4.0.1, released in 2024. All v4.0 requirements became mandatory on March 31, 2025, replacing the older v3.2.1 standard, so businesses should validate against v4.0.1 today.

What are the PCI compliance levels?

There are four PCI compliance levels, determined by how many card transactions a business processes per year, and the level sets how a business must validate compliance.

  • Level 1: Merchants that process over 6 million card transactions per year.
  • Level 2: Merchants that process 1 to 6 million card transactions per year.
  • Level 3: Merchants that process 20,000 to 1 million card transactions per year.
  • Level 4: Merchants that process fewer than 20,000 card transactions per year.

For organizations at PCI compliance level 1, achieving PCI compliance requires external audits by a qualified security assessor (QSA) or an internal security assessor (ISA). QSA or ISA conducts an on-site evaluation to: 

  • Validate the scope of assessment 
  • Review technical information and documentation, 
  • Determine if PCI requirements are met 
  • Offer guidance and support during the compliance process 
  • Evaluate compensating controls

After a successful evaluation, the qualified security assessor submits a Report on Compliance (RoC) to the organization’s operational banks to demonstrate compliance. 

PCI compliance Level 2 organizations should also complete an RoC. 

Organizations at Levels 3 to 4 can complete a self-assessment questionnaire instead of external audits to determine compliance. 

What are the benefits of PCI DSS compliance?

The benefits of PCI DSS compliance include layered security, protection against evolving threats, a lower risk of data breaches, and stronger customer trust. PCI compliance regulations help protect both customers and businesses.

  • PCI DSS compliance ensures that company assets have multiple layers of security. 
  • It enlists evolving threats and attack vectors, making the data environment more secure.
  • PCI DSS involves setting up firewalls, SIEM systems, and other security infrastructure to gather threat intelligence in the event of anomalies.
  • PCI compliance emphasizes encrypting cardholder data, making a PCI DSS-compliant business a less valuable target for cybercriminals.
  • PCI compliance principles put a strong focus on protecting cardholder data as it’s stored or transmitted. It emphasizes enforcing PCI principles with an appropriate security infrastructure to help organizations prevent data breaches. 
  • PCI DSS compliance builds and maintains customer trust and makes data security hassle-free.
  • PCI compliance helps align businesses with industry-accepted standards in storing, processing, and transmitting cardholder information. 
  • PCI DSS compliance helps organizations comply with industry-recognized data security standards.

On G2, the security compliance platforms most often used for this, including Vanta, Drata, Sprinto, and Secureframe, are among the highest rated in the category, each holding 4.6 stars or higher across hundreds to thousands of reviews.

What are the 12 PCI DSS requirements?

The 12 PCI DSS requirements are grouped into six control objectives and cover network security, cardholder data protection, vulnerability management, access control, monitoring and testing, and security policy. They focus on achieving PCI compliance and protecting cardholder data from unauthorized access.

1. Install and maintain network security controls

Steps you can take to protect your network:

  • Configure firewalls to secure the company network and regulate incoming and outgoing traffic according to organizational criteria.
  • Use hardware firewalls and software firewalls to protect the network.
  • Configure the firewalls for inbound and outbound traffic. If an attacker penetrates the system, it’ll be difficult for them to export the stolen information owing to outbound rules.

2. Apply secure configurations to all system components

To comply with the second requirement of PCI compliance:

  • Change default passwords and implement system hardening and system configuration management.
  • Address all vulnerabilities in the system, remediate and report them, and ensure that the system hardening standards align with industry best practices.
  • Adopt system management software, which serves as a complete package for monitoring, scanning, and configuring devices and system hardening options.
  • Verify that the system hardening standard is securely implemented as new devices and applications are introduced into the system environment.

3. Protect stored account data

Adopt the following measures to protect cardholder data against unauthorized access:

  • Encrypt cardholder data using strong and industry-accepted encryption standards like AES-256.
  • Ensure that the systems store confidential cardholder details in an encrypted format.
  • Create and document the cardholder data (CHD) flow diagram. It’s a graphical representation of the data flow within an organization.
  • Use a sensitive data discovery tool to find sensitive information like social security numbers in the company systems to encrypt or remove it.

4. Protect cardholder data with strong cryptography during transmission over open, public networks

Consider the following to encrypt the transmission of cardholder data across open or public networks:

  • Identify how and where the data is being transmitted. Keep track of all areas where similar details are being sent.
  • Make the transition from Secure Sockets Layer (SSL) and early versions of Transport Layer Security (TLS) to more secure versions of TLS.
  • Check the gateways, terminal providers, service providers, and banks to see if they use updated encryption for transactional applications.

5. Protect all systems and networks from malicious software

Adopt the following measures to comply with the fifth PCI DSS requirement.

  • Use antivirus software and anti-malware tools to protect systems from known malware.
  • Update the antivirus software regularly.
  • Gather information on emerging malware and the different ways it can penetrate company systems.
  • Configure the systems and design processes to be alerted when any malicious activity occurs in the system environment.
  • Run periodic malware scans to ensure that you have a process designed to implement it.

6. Develop and maintain secure systems and software

Practice the following methods to develop and maintain secure systems and applications:

  • Patch security weaknesses with recent patches released by the software provider.
  • Install the latest security updates and patch vulnerabilities in applications and systems that are crucial to the flow of card data.
  • Install critical patches within a month of their release to ensure compliance
  • Be proactive in patch management and implementation as soon as the patch is released.

7. Restrict access to system components and cardholder data by business need-to-know

Consider the following to restrict access to cardholder data:

  • Ensure strict access controls to cardholder data by implementing role-based access control (RBAC) systems that grant access to cardholder details on a need-to-know basis.
  • Refrain from creating group users or share a common user account with other users. It’ll be challenging to track data breaches.

8. Identify users and authenticate access to system components

Take the following steps to comply with the eighth requirement of the PCI DSS:

  • Assign a unique ID to each user with computer access and create strong passwords to prevent unauthorized access. 
  • Create multiple layers of security when protecting user accounts.
  • Use multi-factor authentication solutions to provide additional layers of defense and to shield your systems from attackers.

9. Restrict physical access to cardholder data

Important things to consider to comply with the ninth requirement of PCI DSS:

  • Limit employee access to areas with stored cardholder data.
  • Document employees with access to secure environments and those in need of access privileges. List all authorized device users, locations where the device isn’t allowed, and where it’s currently located. Note all applications that can be accessed on a device. Record what, where, when, and why devices are being used.
  • Differentiate between employees and visitors in the organization, and use methods to monitor people with access to secure environments.
  • Ensure that the user’s access privileges are removed, and physical access mechanisms like keys and access cards are disabled or returned when offboarding employees.

10. Log and monitor all access to system components and cardholder data

Crucial points to consider while tracking and monitoring access to network resources and cardholder data:

  • Implement and maintain a logging system to view all logs and get alerts in the event of anomalies. 
  • Check the system event logs at least once a day to identify patterns, gather threat intelligence, and detect behaviors that contradict expected trends.
  • Use security information and event management (SIEM) solutions to build and manage a centralized log collection system, monitoring, and inspection.

11. Test the security of systems and networks regularly

Follow the practices mentioned below to comply with the eleventh requirement of PCI DSS.

  • Conduct frequent vulnerability scans to identify if the security weaknesses were successfully patched.
  • Perform quarterly vulnerability scans for all external IPs and domains exposed in the cardholder data environment using a PCI-approved scanning vendor (ASV).
  • Conduct regular penetration tests to identify different ways hackers can exploit vulnerabilities to safely configure your security systems and protect the data against similar malicious tactics. (Penetration test frequency depends on your self-assessment questionnaire (SAQ), environment, size, procedures, and other factors.

12. Support information security with organizational policies and programs

Adopt the following practices to comply with the final requirement of PCI DSS compliance:

  • Document all policies, procedures, and evidence associated with the organization’s information security practices.
  • Assess formal and annual risks to determine critical threats, vulnerabilities, and associated risks.

What is the difference between PCI DSS and SOC 2?

The difference between PCI DSS and SOC 2 is that PCI DSS is a mandatory standard specifically for protecting credit card data, while SOC 2 is a voluntary audit report that shows how a company safeguards customer data more broadly. Many companies pursue both, and they share a good deal of overlap in technical controls.

PCI DSS SOC 2
Protects cardholder data such as card numbers, PINs, and account data. Protects general customer data against the five trust services criteria.
Mandatory for any business that handles credit card payments. Voluntary, but often required by B2B customers before a deal.
Prescriptive: a fixed set of 12 requirements and controls. Flexible: controls are designed around the company's own risk profile.
Enforced by the card brands through fines and loss of processing rights. Audited by a licensed CPA firm and driven by market demand.

Frequently asked questions about PCI compliance

Here are the most commonly asked questions about PCI compliance.

Q1. Is PCI compliance a legal requirement?

PCI compliance is not a law in most places, but it is contractually required by the card brands and acquiring banks for any business that accepts card payments. A handful of jurisdictions also reference PCI DSS in their regulations, and failing to comply can still carry heavy financial and contractual consequences.

Q2. Who enforces PCI compliance?

PCI compliance is enforced by the major card brands (Visa, Mastercard, American Express, Discover, and JCB) through the acquiring banks that process a merchant's payments, not by a government agency. The PCI Security Standards Council writes and maintains the standard, while the card brands set and enforce the penalties.

Q3. What happens if a business is not PCI compliant?

A business that is not PCI compliant can face monthly fines from its acquiring bank, higher transaction fees, greater liability if a breach occurs, and ultimately lose the ability to accept card payments. After a breach, non-compliant organizations may also face forensic audit costs and reputational damage.

Q4. How much does PCI compliance cost?

The cost of PCI compliance varies widely by a business's level and complexity. Small merchants completing a self-assessment questionnaire may spend relatively little, while Level 1 organizations that need external audits, scanning, and remediation can spend significantly more each year. Compliance automation software can reduce the ongoing effort and cost.

Q5. Who is responsible for PCI compliance in a company?

PCI compliance is a shared responsibility: the merchant is ultimately accountable, but payment processors, gateways, and hosting providers each cover parts of the environment. Internally, it is usually led by security, IT, and compliance teams, with executive sponsorship because the requirements span technology, policy, and people.

To see how PCI fits alongside the other rules your business may need to meet, explore regulatory compliance and how organizations manage it.

PCI Compliance Software

This list shows the top software that mention pci compliance most on G2.

VGS is the modern approach to data security. Its SaaS solution gives you all the benefits of interacting with sensitive and regulated data without the liability of securing it.

Stripe offers solutions for web and mobile payments that are built for developers. Stripe provides a set of unified APIs and tools that instantly enable businesses to accept and manage online payments.

AlienVault USM (from AT&T Cybersecurity) is a platform that provides five essential security capabilities in a single console to manage both compliance and threats, understanding the sensitive nature of IT environments, include active, passive and host-based technologies to match the requirements of each particular environment.

Clover is a comprehensive, cloud-based point-of-sale (POS) system designed to streamline business operations across various industries, including restaurants, retail, eCommerce, and service sectors. By integrating payment processing, inventory management, and customer engagement tools into a single platform, Clover empowers businesses to manage daily tasks efficiently from anywhere, at any time. Its customizable solutions cater to businesses of all sizes, offering a range of devices and applications tailored to specific operational needs. Key Features and Functionality: - Versatile Payment Processing: Accepts all major credit and debit cards, mobile wallets, and contactless payments, ensuring a seamless transaction experience for customers. - Comprehensive Inventory Management: Organizes and tracks inventory in real-time, helping businesses maintain optimal stock levels and reduce losses. - Customer Relationship Management (CRM): Stores customer information, tracks purchase histories, and facilitates targeted marketing campaigns to enhance customer loyalty. - Employee Management: Manages staff schedules, sets individual permissions, and monitors sales performance to optimize team productivity. - Real-Time Reporting: Provides live sales data and customizable reports, enabling informed decision-making and performance tracking. - Online Ordering Integration: Supports in-house, pickup, and delivery orders, expanding sales channels and improving customer convenience. - App Market Access: Offers a wide range of third-party applications to extend functionality, including tools for accounting, marketing, and more. Primary Value and Solutions Provided: Clover addresses the complexities of modern business management by offering an all-in-one POS solution that simplifies operations, enhances customer experiences, and drives growth. By consolidating essential business functions into a single, user-friendly platform, Clover reduces the need for multiple disparate systems, thereby saving time and reducing operational costs. Its scalability ensures that as businesses grow, Clover can adapt to evolving needs, providing a reliable foundation for long-term success.

Discover, assess, prioritize, and patch critical vulnerabilities in real time and across your global hybrid-IT landscape — all from a single solution.

PCI Pal is a suite of solutions designed to help run your customer contact operations in adherence with the Payment Card Industry Data Security Standard (PCI DSS).

With BlueSnap, you finally get everything you need to process payments – a payment gateway solution, merchant account, and advanced features to boost your bottom line – all in one place.

Shopify is a cloud-based commerce platform designed for small and medium-sized businesses. Merchants can use the software to design, set up and manage their stores across multiple sales channels, including web, mobile, social media, brick-and-mortar locations, and pop-up shops.

Braintree's robust, multifaceted platform is ideal for subscription-based businesses wanting to set up recurring billing or accept repeat payments online.

It was clear that security and privacy had become mainstream issues, and that we all increasingly relied on cloud services to store everything from our personal photos to our communications at work. Vanta’s mission is to be the layer of trust on top of these services, and to secure the internet, increase trust in software companies, and keep consumer data safe. Today, we're a growing team in San Francisco passionate about making the internet more secure and elevating the standards for technology companies.

Chargent payment processing for Salesforce. 100% native credit card/ACH payment processing on Opportunities, Cases, Chargent Orders, or Force.com sites.

EBizCharge payment gateway integrates with over 50 ERP, CRM, accounting, and eCommerce solutions, and is designed to: reduce processing costs by 15-40%, increase payment processing efficiency, eliminate double entry, reduce human error, improve security and simplify the customer experience. EBizCharge provides online and mobile credit card processing, unlimited transaction history, customizable reports, electronic invoicing, secure encryption and tokenization, and more.

LogRhythm empowers organizations on six continents to successfully reduce risk by rapidly detecting, responding to, and neutralizing damaging cyberthreats

REPAY (NASDAQ: RPAY) is a payment technology provider that offers card and ACH processing, Instant Funding, automated outbound accounts payable functions, and online bill payment systems with web, text, mobile app, and IVR capabilities. With REPAY’s integrated omni-channel payment solutions, customers can pay and get paid anytime, anywhere. Learn more: www.repay.com

The billing and monetization platform built for the AI economy.

Zuora provides a leading monetization platform to build, run and grow a modern business through a dynamic mix of usage-based models, subscription bundles and everything in between. From pricing and packaging, to billing, payments and revenue recognition, Zuora’s flexible, modular software solutions are designed to help companies evolve and scale monetization with demand. More than 1,000 customers around the world, including BMC Software, Box, Caterpillar, General Motors, The New York Times, Schneider Electric and Zoom use Zuora’s unique combination of technology and expertise to transform their financial operations and how they go to market. Zuora is headquartered in Silicon Valley with offices in the Americas, EMEA and APAC. To learn more, please visit zuora.com.

Ostendio is a cloud-based cybersecurity and information management platform that delivers an easy to use, cost-effective way for companies to demonstrate information security compliance to multiple industry standards and regulations.