TLDR
PCI DSS is a global security standard for protecting cardholder data. Learn who needs to comply, what the main requirements are, and how PCI DSS affects payment processing.
What is PCI DSS?
PCI DSS stands for Payment Card Industry Data Security Standard. It is a global security standard that defines technical and operational requirements for protecting cardholder data and sensitive authentication data during payment processing. The standard is maintained by the Payment Card Industry Security Standards Council, founded by major card networks including Visa, Mastercard, American Express, Discover, and JCB.
The standard is a complex system of requirements aimed at protecting cardholders' data during payments. Certification for compliance with these requirements indicates that the company cares about the security of its customers' personal information.
PCI DSS helps organisations reduce the risk of card data theft, payment fraud, and unauthorised access to cardholder information.
Who needs to comply with PCI DSS?
PCI DSS applies to any organisation that stores, processes, or transmits cardholder data. This includes:
- online and offline merchants;
- payment service providers;
- payment processors;
- acquirers and issuers;
- banks and financial institutions;
- service providers that support card payment processing;
- any other organisation that can affect the security of cardholder data.
Both large organisations and small companies are required to undergo certification.
Looking for secure payment solutions?👀 Our PCI DSS L1-compliant payment platform brings you a data protection toolkit to handle your company's sensitive payment information. Minimise risks and enjoy peace of mind by relying on industry-leading security practices. Learn more
What are the PCI DSS requirements?
PCI DSS includes 12 core requirements grouped around security areas such as network protection, account data security, vulnerability management, access control, monitoring, testing, and information security policies.
Here's a gist of the PCI DSS requirements:
- Build and maintain a secure network by installing and maintaining a firewall configuration and avoiding default passwords or other predefined security settings.
- Protect cardholders' financial information and other data with efficient encryption protocols and ensure safe data storage.
- Maintain a vulnerability management programme that includes secure systems, regular updates, anti-malware tools, and vulnerability scanning.
- Restrict access to cardholder data based on business need, both in digital systems and physical environments.
- Continuously monitor and test the network for threats.
- Develop a security policy that adheres to information security and data privacy principles.
PCI DSS L1 compliant payment platform at your service
How about we steal a few minutes for a chat? I'd love to brainstorm our potential partnership. Oleg Ishchenko, Sales Manager
Why PCI DSS matters for payment businesses
PCI DSS affects how businesses design payment flows, choose providers, store payment data, and manage integrations. For merchants, it can influence checkout architecture, provider selection, and the decision to use hosted payment pages or server-to-server integrations.
For PSPs and payment businesses, PCI DSS is part of the operational foundation. It shapes infrastructure security, access control, monitoring, incident response, and how cardholder data is handled across payment systems.
What is PCI DSS compliance?
PCI DSS compliance means meeting the applicable requirements of the standard and validating that compliance through the required assessment process.
To validate compliance, organisations may need to complete a Self-Assessment Questionnaire (SAQ), submit an Attestation of Compliance (AOC), perform vulnerability scans through an Approved Scanning Vendor (ASV), or undergo an independent assessment by a Qualified Security Assessor (QSA), depending on their role, transaction volume, and acquiring bank requirements.
Merchant compliance levels are usually based on annual card transaction volume and determine the type of validation process required. In many cases, merchants are grouped into compliance levels based on annual card transaction volume. Level 1 usually applies to the largest merchants and requires the most detailed assessment, often including a Report on Compliance completed by a QSA. Lower levels may be able to validate compliance through an SAQ, although acquiring banks and card schemes may set additional requirements.
The availability of the PCI DSS compliance certificate proves the company's serious approach to security and clients' data protection. It is perceived as a quality mark that indicates the reliability and trustworthiness of such a business.
Non-compliance can lead to serious consequences, including fines imposed by acquiring banks, higher processing costs, increased audit requirements, account restrictions, or termination of payment processing services.
For a deeper overview, read our quick guide to PCI DSS compliance.
Is Corefy PCI DSS certified?
Corefy is PCI DSS Level 1 certified and undergoes regular assessment by a Qualified Security Assessor (QSA). This validates the security controls applied to Corefy's in-scope infrastructure, development, operations, support, and payment services.
Using Corefy-hosted payment flows can help reduce a client’s PCI DSS scope because sensitive card data is handled within Corefy’s certified environment. However, each business should confirm its own PCI DSS responsibilities based on its payment setup, integration type, and acquiring requirements.
Related terms
Go deeper
- Blog post
How to build a payment gateway from scratch: 6-step guide
PCI DSS compliance is mandatory for any entity handling cardholder data.
- Blog post
PCI DSS compliance explained: scope, cost, and staying audit-ready
A 2026 guide to what falls inside PCI DSS scope, what it costs, and how to stay audit-ready.