PCI DSS

What Is PCI DSS?

The Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards designed to ensure that all companies that accept, process, store, or transmit credit card information maintain a secure environment. It was created by the Payment Card Industry Security Standards Council (PCI SSC) and applies to any organization that handles cardholder data.

Description

PCI DSS defines 12 core requirements organized around six control objectives, covering network security, access control, encryption, monitoring, and vulnerability management. Compliance is validated annually through a Qualified Security Assessor (QSA) or self-assessment questionnaire, depending on transaction volume. PCI DSS also requires regular penetration testing of the cardholder data environment.

Usage and Examples

Any organization that processes credit card payments — retailers, e-commerce platforms, payment processors, and financial institutions — must comply with PCI DSS. Non-compliance can result in fines, increased transaction fees, and the loss of the ability to process card payments.

Evolve Security offers PCI Penetration Testing to help organizations meet the penetration testing requirements of PCI DSS compliance.

Previous term
No previous terms!
Next term
No next terms!