It applies through payment-system relationships to entities that store, process, or transmit cardholder data or sensitive authentication data, and to systems or providers that can affect the security of the cardholder data environment.
PCI DSS v4.0.1 is the current published revision. An entity determines scope, implements applicable requirements, and validates its status using the method required by the relevant payment brand or acquiring relationship, such as a Self-Assessment Questionnaire or an assessment by a Qualified Security Assessor.
Key points
ScopeIdentify account-data flows, connected and security-impacting systems, people, processes, service providers, and segmentation controls before selecting requirements or validation documents.
Implementation and maintenanceProtect stored and transmitted account data, control access, configure systems securely, manage vulnerabilities, log and test activity, and sustain documented policies and risk-based processes.
ValidationUse the applicable Report on Compliance or Self-Assessment Questionnaire and its corresponding Attestation of Compliance; confirm eligibility and submission expectations with the accepting entity.
Important limitationPCI DSS is not a general security certification or a guarantee against compromise. Validation covers a defined environment and time, while incorrect scope, later changes, control failures, and systems outside the cardholder data environment can leave material risk.