PCI DSS compliance guide
PCI DSS v4.0 explained for the team that has to implement it. Merchant levels, the right SAQ, the 12 requirements, and the scope-reduction moves that turn a six-month project into a six-week one.
PCI DSS v4.0 explained for the team that has to implement it. Merchant levels, the right SAQ, the 12 requirements, and the scope-reduction moves that turn a six-month project into a six-week one.
The Payment Card Industry Data Security Standard (PCI DSS) is the contractual security standard imposed by Visa, Mastercard, AmEx, Discover and JCB on any organisation that stores, processes or transmits cardholder data. It is enforced through your acquirer (your payment processor's bank), not by a government — but the contractual penalties and breach liabilities are substantial.
v4.0 is the current version. v3.2.1 was retired on 31 March 2024, and the future-dated v4.0 requirements become mandatory on 31 March 2025.
PCI DSS is the densest of the standards we cover — twelve requirements, dozens of sub-requirements, evidence per quarter. A workspace that ties requirements to controls, owners and evidence saves more time here than anywhere else.
ISO-STANDARD.app ships a ready-to-adopt PCI DSS workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.
Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.