Businesses that process, store or transmit payment card data are attractive targets for cybercriminals. A successful attack against an organisation’s payment environment can potentially expose the information of thousands or even millions of cardholders.
The Payment Card Industry Data Security Standard (PCI DSS) was created to help organisations protect payment account data and reduce the risk of payment card fraud and data breaches.
Whether you are an online retailer, service provider or large enterprise, understanding your PCI DSS responsibilities is an important part of protecting your customers and your organisation.
What is PCI DSS?
PCI DSS is a global information security standard designed to protect payment account data.
The standard is managed by the PCI Security Standards Council (PCI SSC), which was founded by major payment brands including American Express, Discover, JCB International, Mastercard and Visa.
PCI DSS applies to organisations that store, process or transmit cardholder data and can also apply to organisations whose systems or services could affect the security of the cardholder data environment (CDE).
The current version of the standard is PCI DSS v4.0.1. It was released in June 2024 as a limited revision to PCI DSS v4.0, clarifying requirements and guidance without introducing or removing requirements.
If you need help determining how the standard applies to your organisation, OmniCyber’s PCI DSS compliance services can help you understand your scope, obligations and route to compliance.
Is PCI DSS compliance mandatory?
PCI DSS should not be thought of as an optional cyber security certification.
For merchants accepting payment cards, compliance requirements are generally enforced through relationships with acquiring banks and payment brands. Service providers may also need to demonstrate PCI DSS compliance because of contractual or customer requirements.
The way an organisation validates its compliance depends on factors including its transaction volumes, payment channels, merchant or service provider status, acquiring bank and applicable payment-brand requirements.
Non-compliance can have significant consequences. Depending on the circumstances, these can include additional fees or penalties within the payment ecosystem, increased compliance obligations, reputational damage and potentially restrictions on an organisation’s ability to process card payments.
For organisations unsure about their responsibilities, our guide to who needs to comply with PCI DSS provides further guidance.
What are the 12 PCI DSS requirements?
PCI DSS v4.0.1 is structured around 12 principal requirements:
- Install and maintain network security controls.
- Apply secure configurations to all system components.
- Protect stored account data.
- Protect cardholder data with strong cryptography during transmission over open, public networks.
- Protect all systems and networks from malicious software.
- Develop and maintain secure systems and software.
- Restrict access to system components and cardholder data by business need to know.
- Identify users and authenticate access to system components.
- Restrict physical access to cardholder data.
- Log and monitor all access to system components and cardholder data.
- Test the security of systems and networks regularly.
- Support information security with organisational policies and programmes.
Each of these requirements contains more detailed controls and testing procedures.
Our PCI DSS checklist provides a more detailed breakdown of the areas organisations need to consider when preparing for PCI DSS compliance.
What are PCI DSS compliance levels?
You will often hear organisations described as Level 1, Level 2, Level 3 or Level 4 merchants.
These levels are primarily used by payment brands and acquiring banks to determine how merchants should validate their PCI DSS compliance. They should not be confused with different versions or strengths of PCI DSS itself.
The underlying PCI DSS requirements do not simply become less important because an organisation processes fewer transactions.
Transaction thresholds and validation requirements can also vary between payment brands. For that reason, organisations should confirm their individual validation requirements with their acquiring bank and applicable payment brands.
As an example, Visa generally categorises merchants according to annual Visa transaction volumes, with organisations processing more than six million Visa transactions annually falling into its Level 1 category.
Depending on your circumstances, validating PCI DSS compliance may involve:
- completing an appropriate Self-Assessment Questionnaire (SAQ);
- completing an Attestation of Compliance (AOC);
- undertaking external vulnerability scanning by an Approved Scanning Vendor (ASV);
- completing a Report on Compliance (ROC); and
- undergoing an assessment by a Qualified Security Assessor (QSA).
Your transaction volume is therefore important, but it should not be used in isolation to determine exactly what your organisation needs to do.
What is a PCI DSS QSA?
A Qualified Security Assessor (QSA) is an individual employed by a QSA Company that has been qualified by the PCI Security Standards Council to perform PCI DSS assessments.
For organisations that require a formal assessment, working with an experienced QSA can help establish the correct scope, assess applicable controls, review evidence and identify issues that need to be addressed.
OmniCyber Security is a PCI DSS Qualified Security Assessor company and can support organisations through the assessment and compliance process.
Our PCI DSS compliance and QSA services include scope reviews, Report on Compliance assessments and ongoing PCI DSS consultancy.
What is PCI DSS ASV scanning?
External vulnerability scanning is another important element of PCI DSS for applicable environments.
Where required, external vulnerability scans must be performed by a PCI SSC Approved Scanning Vendor (ASV) at least once every three months. Organisations must also address applicable vulnerabilities and meet the requirements for a passing ASV scan.
OmniCyber provides managed PCI ASV external vulnerability scanning, including:
- unlimited on-demand and routine scanning;
- vulnerability reporting and remediation recommendations;
- ASV certificates;
- false-positive reporting; and
- access to a dedicated ASV scanning portal.
Although PCI DSS may require quarterly scanning, more frequent scanning can help organisations identify vulnerabilities earlier rather than waiting until the next compliance deadline.
You can learn more about ASV scanning through our PCI DSS compliance and vulnerability scanning services.
Does PCI DSS require penetration testing?
Penetration testing is required in applicable PCI DSS environments and plays an important role in determining whether security weaknesses could be exploited.
Testing may need to cover internal and external infrastructure as well as systems that could affect the security of the cardholder data environment. Segmentation controls may also require testing where network segmentation is being used to reduce PCI DSS scope.
Penetration testing requirements can apply at least annually and following significant changes to the environment, depending on the applicable PCI DSS requirements and scope.
OmniCyber’s PCI DSS penetration testing services help organisations identify exploitable weaknesses within their cardholder data environments and understand the remediation required.
For organisations requiring security testing beyond PCI DSS, we also provide broader CREST-certified penetration testing services.
How can OmniCyber help with PCI DSS compliance?
PCI DSS compliance can become complicated quickly, particularly when an organisation has multiple payment channels, third-party providers, legacy systems or a large cardholder data environment.
Correctly establishing the scope at the beginning of the process can make a substantial difference.
OmniCyber Security can support organisations with:
- PCI DSS scope reviews to identify systems, people, processes and third parties that fall within scope;
- PCI DSS consultancy for organisations requiring ongoing access to PCI expertise;
- QSA assessments and Reports on Compliance for organisations requiring formal assessment;
- PCI ASV external vulnerability scanning to meet applicable scanning requirements;
- internal vulnerability management for in-scope environments;
- PCI DSS penetration testing and segmentation testing; and
- remediation guidance to help address issues identified during the compliance process.
As a PCI DSS QSA company, OmniCyber combines compliance expertise with practical cyber security testing to help organisations establish, demonstrate and maintain PCI DSS compliance.
Need help with PCI DSS 4.0.1?
Whether you are approaching PCI DSS for the first time, preparing for an assessment or looking to reduce the complexity of your existing cardholder data environment, our PCI specialists can help.
Speak to OmniCyber’s PCI DSS specialists about your compliance requirements and arrange a conversation about the most appropriate route for your organisation.