Accepting card payments comes with important security and compliance responsibilities. Knowing where risk increases can help you build a stronger compliance program.
PCI compliance affects every business that accepts credit or debit card payments. Failing to meet PCI DSS requirements can put customer data — and your ability to process card payments — at risk. This primer explains PCI DSS requirements, how compliance changes as your business grows and practical ways to reduce risk.
First things first: What is PCI compliance, anyway? PCI compliance is based on the Payment Card Industry Data Security Standard (PCI DSS).
This standard is a set of rules designed to make sure that when consumers use a credit card, the businesses involved in collecting, processing, transmitting and storing cardholder data (CHD) all adhere to policies that protect the sensitive information involved in a financial transaction.
Although PCI DSS isn't a law, payment card brands and acquiring banks generally require merchants that accept card payments to comply with the standard.
The overarching goal of PCI DSS is preventing fraud, theft and inappropriate data exposure. Hundreds of specific rules make up the entire scope of PCI DSS. The rules break down into 12 broad requirements intended to achieve six objectives:
With every swipe, tap or Apple Pay authorization, a payment lifecycle begins. Here are the players and the process a payment goes through on its journey to transfer value from one place to another.
A lot happens behind the scenes every time someone taps a card or clicks "Pay." Payment information passes through several organizations before the transaction is approved and settled. Understanding that journey can help you see where cardholder data flows through your business and what falls within your PCI compliance responsibilities.
PCI compliance represents more than good policy. It’s a core business mandate that maintains a safe environment for cardholder data, prevents fraud, builds trust with your customer base and protects your organization’s reputation. It also keeps you in good standing with your bank and helps you avoid steep fines or losing the ability to accept card payments.
Given its centrality, leaders should recognize PCI compliance as a core, ongoing business activity rather than an annual exercise or just another bureaucratic hurdle to navigate when absolutely necessary. It’s not a checklist or an extraneous activity; PCI compliance must become business as usual — a consideration that figures into routine decisions and daily business activities.
The number of credit and debit card transactions your business handles each year determines the level of compliance you are required to meet. That’s why as your organization grows, so do your compliance responsibilities.
Businesses that handle the fewest card transactions can self-attest to adequate security protocols using a self-assessment questionnaire (SAQ). The SAQ asks about security protocols and processes you have in place. It’s designed to help you and your acquiring bank see how well your organization meets the security goals set forth in the PCI DSS.
Different SAQs apply depending on how your business accepts and processes card payments. Your annual transaction volume determines your PCI compliance level and the validation requirements you must meet. Organizations in levels 2 through 4 (with under 6 million annual transactions) typically complete the appropriate SAQ each year and may also need quarterly PCI vulnerability scans.
Organizations with 6 million or more annual card transactions are subject to level 1 PCI DSS reporting requirements. They must undergo an independent audit each year by a PCI qualified security assessor (QSA) and have a quarterly PCI vulnerability scan from an approved scanning vendor (ASV).
Your acquiring bank may require you to meet stricter PCI validation requirements than the PCI DSS minimum to reduce its own risk exposure. For example, acquiring banks often require an independent audit by a certified PCI auditor once a merchant reaches one million annual transactions.
In addition to requirements that change as your business grows, the compliance landscape changes with each update to the PCI DSS. The PCI Security Standards Council periodically revises the DSS to adapt to a changing threat environment. Updates have historically been released every few years, so you should stay informed about new requirements as they are introduced.
The PCI DSS requirements your organization has to meet for full compliance, or PCI scope, doesn’t depend exclusively on transaction volume. While PCI DSS is organized around 12 core objectives, meeting those objectives can involve close to 300 specific requirements. The number of payment types and channels your organization accepts and the way you handle card payments determines how many apply to your business.
The more contact your organization has with cardholder data (if you collect, process or store it within the business, for example) the more complex your compliance responsibilities become.
To optimize the way cardholder data moves through your organization, you need to understand which systems, people and vendors interact with it. Structuring data and systems for strong data flow visibility can help make PCI compliance more manageable by allowing you to pinpoint additional opportunities to limit scope.
Meeting your PCI compliance responsibilities can get harder as your organization scales for several reasons:
Leaders should understand how business growth affects PCI compliance and budget for the increased needs, regularly reviewing how changes to the business affect PCI compliance.
While compliance can be challenging and there’s no broad legal requirement to meet PCI DSS, there is a compelling business case for taking a serious approach to PCI compliance.
For starters, if you take card payments then you have a contractual obligation to meet PCI DSS as part of your agreement with acquiring banks and the card brands you accept. The acquiring bank may terminate your processing capabilities if they see you as insufficiently compliant, leaving you unable to accept card payments.
Other consequences of noncompliance can be dire as well, including:
Whether you're a small business or a large enterprise, these five strategies can help reduce risk and make PCI compliance easier.
Now that you understand the fundamentals of PCI compliance, the next step is putting them into practice. Learn how our cybersecurity consulting services can help you assess your current environment, reduce your compliance burden and build a scalable PCI compliance program.
Our seasoned audit experts can help you streamline your audit experience and strengthen your financials. Contact us today for a free scoping call to assess your needs.