What is PCI? Understanding the Importance of PCI Compliance

Atualizado: agosto 13, 2026 Tempo de leitura: ~

TL;DR

PCI DSS (Payment Card Industry Data Security Standard) is a mandatory security framework that governs how businesses handle credit card data. Governed by the Payment Card Industry Council — founded in 2006 by American Express, Discover, JCB International, Mastercard, and Visa — the standard applies to any organization that accepts, stores, or transmits cardholder information, regardless of size. Non-compliance can result in fines of up to $500,000 per breach, legal liability, and reputational damage. Compliance is structured around six core goals and eleven technical requirements, ranging from firewall configuration and password hygiene to physical access controls and staff training. Businesses are also tiered into four compliance levels based on annual transaction volume, with larger organizations facing more rigorous documentation requirements. Maintaining compliance is an ongoing, evolving responsibility — not a one-time checklist.


Understanding PCI DSS and credit card data security

The Payment Card Industry Data Security Standard (PCI DSS) is a framework that governs how companies handle credit card data. If your company processes, stores, or transmits credit card information, PCI DSS compliance is critical for you.

The PCI DSS ensures that cardholder information is used, stored, and transmitted safely. Following the rules is an industry best practice. You prove to your customers that your company is trustworthy.

But if you're not PCI compliant, you could also face steep fines that could cripple your business.

What is PCI compliance? 

PCI compliance is the process of meeting the security standards set by the Payment Card Industry Council to protect cardholder data. Guidelines start the PCI compliance process. You must know what your company is expected to do, and you must build processes accordingly. Then, documentation begins. You must prove that you're doing all you can to keep cardholder data secure. 

Who founded the PCI Council?

PCI compliance begins with the PCI itself. The Payment Card Industry Council was founded in 2006 by representatives from:

  • American Express
  • Discover
  • JCB International
  • MasterCard
  • Visa

Each company shares council responsibilities equally, and they all require PCI DSS compliance from their business partners.

PCI created the Data Security Standard (DSS), along with the supporting materials, such as:

  • Specification frameworks
  • Toolkits
  • Measurement guides
  • Supporting materials

Any company that accepts, stores, or transmits cardholder data must be PCI DSS compliant. Even very small companies, and those that work with third-party payment processors, must be compliant. 

What happens if you're not compliant?

If you're not compliant, you could face a fine of up to $500,000 per security breach incident. Additionally, you must notify every person who might have been exposed in an attack, and those notifications can be costly.

Consumers may also choose to sue you independently. And you could face government fines too.

Are you PCI compliant?

Don't make assumptions about the safety of cardholder data you collect. Learn more about what the guidelines say and walk through your processes to ensure compliance.

PCI DSS standards start with six goals. Each company should:

  1. Build and maintain a secure network.
  2. Protect cardholder data.
  3. Maintain a vulnerability management program.
  4. Implement strong access control measures.
  5. Regularly monitor and test networks.
  6. Maintain an information security policy.

What are the PCI DSS requirements?

How can you meet these goals? PCI DSS requirements lay out the steps.

  1. Start with firewalls. Install and maintain a firewall, and configure it as best you can to keep intruders out. 
  2. Strengthen passwords. Don't use passwords that come with your devices, and look for ways to ensure you're following password best practices.
  3. Protect in storage. If you store cardholder data, ensure that you surround it with security.
  4. Protect in transit. If you move data across networks, ensure that it's encrypted.
  5. Stop attacks. Install anti-virus programs, and keep them updated.
  6. Tighten. Create secure systems and maintain them.
  7. Restrict electronic access. Don't allow everyone to touch cardholder data. Ensure only those who need to know about it can see it.
  8. Track. Give each person with access to your company computer a unique ID.
  9. Restrict physical access. Don't allow everyone to touch hard copies of cardholder data.
  10. Test. Set up a regular testing schedule and follow it.
  11. Codify. Create a document that spells out your policy regarding employee and contractor security.

What are the PCI compliance levels?

Every company that collects cardholder data, no matter how small, is required to achieve PCI DSS compliance. But larger companies must take more steps to prove that they both know and understand the rules.

Consider Visa. This company (the largest major payment network worldwide) creates four compliance levels.

Those four levels are:

LevelAnnual Visa Transaction VolumeDocumentation Requirement
Level 1More than 6 million Visa transactions annuallyTwo accounting forms
Level 21 to 6 million Visa transactions annuallyMore documentation than Level 3/4
Level 320,000 to 1 million Visa transactions annuallyMore documentation than Level 4
Level 4Less than 20,000 Visa ecommerce transactions annually and up to 1 million Visa transactionsQuestionnaire only

The rules don't change from group to group. But the risks you face with larger transaction numbers do. As a result, Visa requires more documentation from larger companies to prove compliance.

If you're a small, Level 4 company, you may only need to complete a questionnaire. But if you're a Level 1 company, you'll need to complete two accounting forms.

What are the PCI DSS do's and don'ts?

The rules may seem simple. But it's easy for companies to grow confused about what they should and shouldn't do with the data they collect. Understanding a few best practices may help.

You ShouldYou Should Not
Stay abreast. Follow the PCI closely, and read up on new releases. As the industry changes and new risks emerge, the rules you must follow can also change.Take partnerships lightly. Don't look for the best deals on point-of-sale (POS) hardware and software. Make sure that any company you work with is also PCI DSS compliant and takes the risks seriously.
Conduct risk assessments. Evaluate your environment regularly. When you spot an area of concern, mitigate the risks as quickly as possible.Merge networks. Cardholder data shouldn't be accessible to hackers who get into your company's open servers. Segment as much as you can to keep data safe.
Hold regular trainings. Staff left unattended can create workarounds (such as saving cardholder data in spreadsheets on the server) that puts compliance at risk. Expect to re-train your staff.Forget it. Compliance is an ever-shifting target. Keep your security at the forefront of your mind at all times.

If you're looking for a partner to help ensure PCI DSS compliance, consider Okta. Download our white paper to find out how we can help you on your compliance journey.

Frequently asked questions

What does PCI DSS stand for?

PCI DSS stands for the Payment Card Industry Data Security Standard. It is a mandatory security framework that governs how businesses handle credit card data, ensuring that cardholder information is used, stored, and transmitted safely.

Who is required to be PCI DSS compliant?

PCI DSS compliance is universal — it applies to every business that touches cardholder data in any way, from large enterprises to small merchants and even those relying on third-party payment processors.

What fines can a business face for failing to comply with PCI DSS?

Non-compliance carries serious financial consequences. A single security breach can trigger fines reaching $500,000, mandatory breach notifications to all affected individuals, independent consumer lawsuits, and additional government-imposed penalties.

How are PCI compliance levels determined?

PCI compliance levels are based on annual transaction volume. Visa, for example, defines four levels: Level 1 for more than 6 million transactions, Level 2 for 1 to 6 million, Level 3 for 20,000 to 1 million, and Level 4 for less than 20,000 ecommerce transactions and up to 1 million total transactions. Larger companies face more rigorous documentation requirements to prove compliance.

What are the most common PCI DSS compliance mistakes to avoid?

Common mistakes include taking partnerships lightly — failing to verify that vendors and partners are also PCI DSS compliant. Businesses should also avoid merging networks, since cardholder data shouldn't be accessible to hackers who get into open servers. Finally, treating compliance as a one-time task rather than an ongoing responsibility is a significant risk.

Is PCI DSS compliance a one-time requirement or an ongoing process?

PCI DSS is not a one-and-done certification. The threat landscape evolves continuously, meaning the standards themselves are updated over time. Businesses must treat compliance as a living program — conducting periodic risk assessments, retraining staff regularly, and staying current with PCI Council updates.

References

About Us. PCI Security Standards Council.

PCI-DSS: Security Penalties. UC Santa Cruz.

Maintaining Payment Security. PCI Security Standards Council.

Credit Card Companies: 15 Largest Issuers of 2021. CardRates.com.

PCI Compliance Helps Keep You and Your Customers' Data Safe. Visa.

 

Continue your Identity journey