Skip to main content

Getting Started with PCI DSS

The Payment Card Industry Data Security Standard (PCI DSS) is a set of security requirements for any organization that stores, processes, or transmits cardholder data. PCI DSS v4.0 is the current version, with the transition period from v3.2.1 completed on March 31, 2024. Additional future-dated requirements in v4.0 become mandatory on March 31, 2025. PCI DSS is maintained by the PCI Security Standards Council and enforced through the payment card brands (Visa, Mastercard, American Express, Discover, JCB). Compliance is validated through Self-Assessment Questionnaires (SAQs) or on-site assessments by a Qualified Security Assessor (QSA), depending on your transaction volume and merchant level. Matproof maps PCI DSS v4.0 requirements to controls, policies, and evidence workflows so you can prepare for your annual assessment.
Activate PCI DSS under Settings - Frameworks - PCI DSS. Controls are pre-populated across all 12 requirements and their sub-requirements.

Am I in Scope?

PCI DSS applies to any entity that stores, processes, or transmits cardholder data or sensitive authentication data, including:
  • Merchants (online and physical)
  • Payment processors and acquirers
  • Issuers
  • Service providers that handle cardholder data on behalf of other entities
Reduce your scope by minimizing where cardholder data is stored and processed. Using a PCI-compliant payment processor (like Stripe or Adyen) that tokenizes card data can significantly reduce the number of applicable requirements.

The 12 PCI DSS Requirements

PCI DSS is organized into six goals and 12 requirements:

PCI DSS v4.0 Key Changes

If you were compliant with v3.2.1, these are the most significant changes in v4.0:

Merchant Levels

Merchant levels and validation requirements vary by card brand. The table above reflects Visa’s classification. Check with your acquiring bank for your specific obligations.

Next Steps