Skip to content
Oluma Cyber Security Awareness
Standard · Payment Card Security

PCI DSS

The rulebook for anyone who touches a credit card number — twelve requirements standing between a business and the most attacked data on earth.

v4.0.1 · 202412 Requirements6 Goals4 Merchant Levels
01 The Problem

Five card brands, five conflicting rulebooks

Card numbers are pure gold to attackers — instantly sellable, endlessly reusable. Yet in the early 2000s, each card brand ran its own security program, so a single merchant could face five overlapping, conflicting sets of requirements at once.

The result was predictable: confusion, patchy protection, and a steady stream of breaches dumping millions of card numbers. What the industry lacked was one standard everyone agreed on.

03 The Story Behind It

From alignment to continuous security

2004
The brands align
PCI DSS 1.0 united five competing card-brand programs into a single Data Security Standard.
2006
A council to own it
The PCI Security Standards Council was formed to maintain, evolve, and govern the standard independently of any one brand.
2022 · v4.0
The biggest update in a decade
Introduced the flexible “customized approach,” pushed security toward a continuous, business-as-usual practice, and added modern defenses against e-skimming and phishing.
2024–25 · v4.0.1
Now fully mandatory
A June 2024 clarification revision. Then on March 31, 2025, all 51 future-dated requirements became mandatory — MFA everywhere, payment-page script controls, authenticated scans, 12-character passwords.
04 How It Works

6 goals, 12 requirements, and scope is everything

The standard groups into six goals and twelve requirements, which fan out into hundreds of sub-requirements. But the real game is scope: everything that stores, processes, or transmits card data is your Cardholder Data Environment — and the smaller you make it, the smaller your burden.

Build & maintain secure networksProtect account dataVulnerability managementStrong access controlMonitor & testSecurity policy

How you prove it depends on your merchant level (set by transaction volume): smaller merchants complete a Self-Assessment Questionnaire; the largest need a full Report on Compliance from a Qualified Security Assessor. The twelve requirements:

1 Install & maintain network security controls
2 Apply secure configurations
3 Protect stored account data
4 Encrypt data in transit
5 Protect against malware
6 Develop & maintain secure systems
7 Restrict access by need-to-know
8 Identify users & authenticate access
9 Restrict physical access
10 Log & monitor all access
11 Test security regularly
12 Maintain a security policy
It’s a contract, not a law

PCI DSS is enforced by acquiring banks and card brands. Fall out of compliance and you face fines, higher processing fees, or losing the ability to take cards — penalties that hit the business directly.

06 Who Uses It

Everyone who takes a payment

🛒
Retail & e-commerce
Any store, online or off, that accepts card payments — from a single terminal to a global checkout.
💳
Processors & fintech
Payment gateways, processors, and platforms that move cardholder data on others’ behalf.
☁️
SaaS & hosting
Service providers whose systems store or touch card data as part of what they deliver.

It’s its own regime, but the discipline it demands overlaps neatly with broader security programs.

overlaps ISO 27001SOC 2NIST CSFCIS Controls
07 Career Relevance

Where security meets the checkout

PCI work is everywhere money moves — retail, banking, fintech, hospitality. It’s also concrete: scope a Cardholder Data Environment, segment a network, complete an SAQ or ROC, and you’ve produced something a business can literally bank on.

QSA / ISA
Assess & certify
Qualified and internal assessors validate compliance and sign the reports acquirers rely on.
GRC analyst
Scope & evidence
Define the CDE, drive segmentation, and assemble the evidence that keeps annual validation painless.
Security engineer
Build the controls
Implement the technical requirements — encryption, logging, MFA, script integrity — that the standard demands.

Understanding scope reduction alone makes you valuable: it’s the difference between a business sweating an audit and sailing through one.

09 Final Takeaway

If your business touches a card, PCI DSS isn’t homework — it’s the price of admission.

Twelve requirements, six goals, and one insight that decides everything: control your scope. Master what falls inside the Cardholder Data Environment and what you can keep out, and the most feared audit in commerce becomes routine.