PCI compliance fosters the adoption of data security standards and resources designed to prevent fraud and make payments safe.
Read our article to find out more about PCI data security standards and the steps merchants need to take to become compliant.
The PCI Data Security Standard (PCI-DSS) is a set of requirements designed to protect payment account data through the payment lifecycle. It includes standards for merchants, payment service providers and financial institutions regarding security practices, technologies and processes as well as standards for developers and vendors for creating secure payment products and solutions. An entity achieves PCI compliance by consistently adhering to these standards.
PCI standards are periodically updated to address emerging threats and new technologies. In March 2022, the PCI Security Standards Council announced that in 2024 an updated set of requirements (PCI-DSS version 4.0) will replace the standards currently in effect (PCI-DSS version 3.2.1).
Three groups play a role in merchants’ PCI compliance, they are:
PCI Security Standards Council (PCI SSC): This global forum brings together payments industry stakeholders to develop data security standards and drive adoption worldwide. Card networks (e.g., Visa, Mastercard, etc.). The networks have their own specific data security requirements for merchants guided by PCI data security standards. Merchant services providers (e.g., processors, payment service providers). Merchant services providers must be PCI compliant themselves and typically incorporate PCI compliance requirements for merchants into their service agreements.
What are the PCI requirements for merchants?
The twelve key PCI DSS requirements for merchants are as follows (Source: PCI Security Standards website):





