Skip to content
Risk & Compliance

PCI DSS (Payment Card Industry Data Security Standard)

Security standards for handling card data. Compliance mandatory for all merchants processing card payments. Violations risk $5K-100K monthly fines.

Overview

What is PCI DSS?

PCI DSS (Payment Card Industry Data Security Standard) is a comprehensive set of security requirements established by major card networks (Visa, Mastercard, Amex, Discover) that all merchants handling cardholder data must follow. Compliance is legally mandatory - not optional - for any business that stores, processes, or transmits credit card information. Non-compliance risks $5K-100K monthly fines from card networks, potential merchant account termination, and massive liability if breaches occur. For high-risk merchants already facing elevated scrutiny, PCI compliance is table stakes for maintaining processing relationships.

PCI DSS compliance levels depend on transaction volume. Level 1 (>6M annual Visa/Mastercard transactions): requires annual on-site security audit by Qualified Security Assessor (QSA), quarterly network scans, $20K-50K annual compliance costs. Level 2 (1M-6M transactions): annual Self-Assessment Questionnaire (SAQ), quarterly scans, $5K-15K costs. Level 3 (20K-1M e-commerce transactions): annual SAQ, quarterly scans, $2K-5K costs. Level 4 (<20K e-commerce transactions): annual SAQ, quarterly scans as dictated by acquirer, $500-2K costs. Most small-to-mid-sized merchants are Level 3-4, while high-volume processors ($10M+ annually) typically hit Level 1-2.

The 12 PCI DSS requirements cover: (1) firewall configuration, (2) avoiding default passwords, (3) protecting stored cardholder data, (4) encrypting data transmission, (5) using anti-virus software, (6) maintaining secure systems, (7) restricting data access by business need, (8) assigning unique IDs to computer users, (9) restricting physical access to cardholder data, (10) tracking network access, (11) regularly testing security systems, (12) maintaining information security policies. Requirement #3 (no storing CVV codes) and #4 (encryption) are where most violations occur - merchants accidentally logging CVV data or transmitting card numbers unencrypted.

Reducing PCI scope dramatically lowers compliance costs and risk. Using tokenization (storing tokens not card numbers) moves most merchants from Level 1-2 to Level 3-4. Using hosted payment pages (PSP-controlled checkout where card data never touches your servers) reduces scope even further, qualifying for SAQ-A (simplest questionnaire, 14 questions vs. 329 for SAQ-D). This approach cuts compliance costs from $20K-50K to $500-2K annually while reducing breach liability. MIDs' gateway includes hosted payment pages and tokenization standard, minimizing client PCI scope and compliance burden.

In depth

Everything you need to know.

PCI compliance verification happens annually (or quarterly for Level 1 merchants). You complete a Self-Assessment Questionnaire (SAQ) appropriate to your integration type: SAQ A for hosted payment pages (14 questions), SAQ A-EP for embedded iframes (182 questions), SAQ D for direct API integration (329 questions). The questionnaire asks detailed questions about security practices: do you maintain firewall configurations, encrypt cardholder data transmission, use strong passwords, restrict access to card data, maintain anti-virus software, test security systems quarterly, etc. You answer yes/no with supporting evidence. Additionally, you must pass quarterly vulnerability scans performed by Approved Scanning Vendors (ASVs) who probe your systems for security weaknesses. For Level 1 merchants, a Qualified Security Assessor conducts on-site audits: interviewing staff, reviewing systems, testing security controls, examining documentation. Once all requirements are met, you receive an Attestation of Compliance certificate valid for 12 months. Your PSP requires this certificate to maintain your merchant account - failing to provide it risks processing suspension.

PCI compliance isn't optional - it's a contractual requirement of your merchant agreement. Non-compliance risks immediate consequences: $5K-25K monthly fines from card networks (increasing to $100K for prolonged violations), merchant account termination (forcing you to find new processing, often at higher rates), and massive liability if data breaches occur. A merchant suffering a data breach while non-compliant faces the full cost of breach remediation: forensic investigation ($50K-200K), card reissuance for affected cardholders ($5-10 per card), fraud monitoring services for victims ($50-100 per person), legal fees, and potential class-action liability. Breaches affecting 10,000+ cards can cost $500K-2M+. PCI-compliant merchants have far lower breach liability - many costs shift to PSPs and insurance. Compliance also protects reputation. Customers increasingly expect secure checkout - publicized breaches destroy trust, reduce conversion rates, and damage brand value for years. High-risk merchants already face customer skepticism; demonstrating security through PCI compliance builds credibility.

Illustrative example — not a specific client engagement.

  • A supplement merchant using direct API integration (SAQ-D) with $2M annual volume spent $8K annually on PCI compliance: vulnerability scans, documentation, security reviews. After switching to hosted payment pages (SAQ-A), compliance costs dropped to $1.2K annually - $6.8K savings while actually improving security and reducing breach liability.
  • An online dating platform accidentally stored CVV codes in transaction logs (violating Requirement #3). During their annual PCI assessment, auditors discovered the violation. The merchant faced immediate non-compliance, $15K monthly fines until remediation, and was required to complete forensic security audit at $35K cost. Total impact: $65K+ before returning to compliance.
  • A gaming operator suffered a breach affecting 15,000 cards while PCI-compliant. Because they met all requirements and used certified systems, their liability was limited to $50K forensic audit fees - the PSP and card networks absorbed $600K+ in card reissuance and fraud monitoring costs. A non-compliant merchant would have faced the entire $650K+ liability personally.
  • Use hosted payment pages or embedded iframes to minimize PCI scope - qualify for SAQ-A instead of SAQ-D, reducing compliance costs by $15K-45K annually
  • Implement tokenization for recurring billing - storing tokens not card numbers dramatically reduces breach liability and compliance burden
  • Schedule quarterly vulnerability scans proactively - don't wait for reminders from your PSP, complete scans on fixed schedule
  • Maintain detailed security documentation year-round - firewall configurations, access logs, system updates, security policies
  • Never store CVV codes even temporarily - configure systems to immediately discard CVV after initial authorization
  • Use strong, unique passwords for all payment systems - implement password managers and enforce minimum 12-character complexity
  • For Level 1 merchants: engage QSAs 2-3 months before compliance deadline to identify and fix issues before formal audit
  • Storing CVV codes even temporarily in logs or databases - this is explicitly prohibited and causes immediate PCI failure
  • Using direct API card capture when hosted pages would work - increases PCI scope from SAQ-A (14 questions) to SAQ-D (329 questions) unnecessarily
  • Transmitting card numbers over unencrypted connections (HTTP instead of HTTPS) - auto-fail PCI scans
  • Failing to complete quarterly vulnerability scans - many merchants only remember PCI during annual renewal, missing quarterly requirements
  • Using default passwords on payment systems and databases - Requirement #2 violation caught in every audit
  • Not restricting access to cardholder data - giving all employees access instead of role-based permissions violates Requirement #7

Keep exploring

Related terms

APPROVED

Put this to work
for your business.

MIDs structures high-risk acquiring across 30+ banks — smart routing, fraud and chargeback control built in. Tell us your category and volume and we'll build the setup around it.