The Payment Card Industry Data Security Standard, governed by the PCI Security Standards Council, applies to any organization that stores, processes, or transmits cardholder data.
PCI-DSS v4.0 sets out 12 core requirements spanning network security, encryption, access control, monitoring, and testing. The level of validation required — from a self-assessment questionnaire to a full Report on Compliance by a Qualified Security Assessor — scales with annual transaction volume.
Core requirements
PCI Security Standards Council
PCI-DSS v4.0