# What is the Payment Card Industry Data Security Standard (PCI DSS)?

> The Payment Card Industry Data Security Standard (PCI DSS) is an industry security standard containing technical and operational requirements for protecting payment account data.

- Canonical URL: https://yellowcube.eu/glossary/payment-card-industry-data-security-standard/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It applies through payment-system relationships to entities that store, process, or transmit cardholder data or sensitive authentication data, and to systems or providers that can affect the security of the cardholder data environment.

PCI DSS v4.0.1 is the current published revision. An entity determines scope, implements applicable requirements, and validates its status using the method required by the relevant payment brand or acquiring relationship, such as a Self-Assessment Questionnaire or an assessment by a Qualified Security Assessor.

### Key points

- **Scope:** Identify account-data flows, connected and security-impacting systems, people, processes, service providers, and segmentation controls before selecting requirements or validation documents.
- **Implementation and maintenance:** Protect stored and transmitted account data, control access, configure systems securely, manage vulnerabilities, log and test activity, and sustain documented policies and risk-based processes.
- **Validation:** Use the applicable Report on Compliance or Self-Assessment Questionnaire and its corresponding Attestation of Compliance; confirm eligibility and submission expectations with the accepting entity.
- **Important limitation:** PCI DSS is not a general security certification or a guarantee against compromise. Validation covers a defined environment and time, while incorrect scope, later changes, control failures, and systems outside the cardholder data environment can leave material risk.

### Related terms

[Data security](<https://yellowcube.eu/glossary/data-security/>) · [Data classification](<https://yellowcube.eu/glossary/data-classification/>) · [Network segmentation](<https://yellowcube.eu/glossary/network-segmentation/>) · [Third-party cyber risk](<https://yellowcube.eu/glossary/third-party-cyber-risk/>) · [Security audit](<https://yellowcube.eu/glossary/security-audit/>) · [Point-of-sale (POS) security](<https://yellowcube.eu/glossary/point-of-sale-security/>)

### Sources

[PCI Security Standards Council, PCI Data Security Standard](https://www.pcisecuritystandards.org/standards/pci-dss/) · [PCI Security Standards Council, Document Library—PCI DSS v4.0.1](https://www.pcisecuritystandards.org/document_library/) · [PCI Security Standards Council, SAQs for PCI DSS v4.0.1 Now Available](https://www.pcisecuritystandards.org/wp-content/uploads/2024/10/SAQs_for_PCI_DSS_v4.0.1_Bulletin.pdf)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

