Payments Glossary · Risk & Compliance

PCI DSS

Also called Payment Card Industry Data Security Standard, PCI compliance

The card brands' contractual security standard for anyone who stores, processes or transmits cardholder data.

What it is

PCI DSS is the Payment Card Industry Data Security Standard, maintained by the PCI Security Standards Council, which was founded by Visa, Mastercard, American Express, Discover and JCB. It is not a statute. No legislature passed it. It reaches you through contract: your merchant agreement obligates you to comply, your acquirer is obligated to the networks, and the networks enforce through the acquirer. The standard is organized into twelve high-level requirements covering network security, protection of stored account data, encryption in transit, vulnerability management, access control, monitoring and testing, and a written information security policy. How much of it applies to you depends entirely on how card data flows through your business. A restaurant using a validated point-to-point encryption terminal has a dramatically smaller obligation than an e-commerce store that collects card numbers in its own web form. Validation, as distinct from compliance, is the paperwork: most small merchants validate annually with a Self-Assessment Questionnaire and an Attestation of Compliance, plus quarterly scans by an Approved Scanning Vendor where the SAQ requires them. Larger merchants get a Report on Compliance from a Qualified Security Assessor. Compliance is a continuous state; validation is an annual snapshot. The current version is PCI DSS v4.0.1. Version 3.2.1 retired March 31, 2024, and the previously future-dated v4.0 requirements became mandatory March 31, 2025, applying to assessments from April 1, 2025 forward.

Why it matters to your business

PCI is the one compliance obligation that shows up on your statement every month whether you engage with it or not. Doing the annual questionnaire honestly, with someone who understands your card flow, is usually a two-hour exercise that eliminates a recurring fee and materially reduces what a breach would cost you. Ignoring it does not make it go away; it converts it into a line item. This entry is education, not legal advice. Your specific PCI obligations flow from your merchant agreement and your card data environment, and a breach involves state notification statutes that a qualified attorney should advise on.

Where it gets contested

The fight in the SMB channel is not about the standard. It is about who profits from it. Processors bill a monthly PCI program fee, commonly around 10 dollars a month, and separately a PCI non-compliance fee when the merchant never completes the questionnaire. The program fee is defensible when real services attach: scanning, a validation portal, breach warranty, live help. Where nothing attaches, it is margin dressed as compliance. There is precedent for pushing back. A class action alleged that Banc of America Merchant Services charged unauthorized data-security fees. More broadly, the industry has never resolved a basic tension: the party selling compliance services is also the party that assesses the penalty for not buying them. The gray area merchants live in is simpler and worse. Many small businesses are technically non-compliant, know it, pay the fee, and treat it as a cost of doing business. That works until there is a breach, at which point the forensic and reissuance costs are the actual risk, not the monthly fee.

How to check it yourself

Pull your last merchant statement and find every line with PCI in the name. Then log into your processor's compliance portal and check the date your last Attestation of Compliance was filed. If it is more than twelve months old, you are almost certainly paying a non-compliance fee right now.

Receipts

Claims above that are checkable, with where to check them. Published so you do not have to take anyone's word for it.