Getting Started with PCI DSS
The Payment Card Industry Data Security Standard (PCI DSS) is a set of security requirements for any organization that stores, processes, or transmits cardholder data. PCI DSS v4.0 is the current version, with the transition period from v3.2.1 completed on March 31, 2024. Additional future-dated requirements in v4.0 become mandatory on March 31, 2025. PCI DSS is maintained by the PCI Security Standards Council and enforced through the payment card brands (Visa, Mastercard, American Express, Discover, JCB). Compliance is validated through Self-Assessment Questionnaires (SAQs) or on-site assessments by a Qualified Security Assessor (QSA), depending on your transaction volume and merchant level. Matproof maps PCI DSS v4.0 requirements to controls, policies, and evidence workflows so you can prepare for your annual assessment.Activate PCI DSS under Settings - Frameworks - PCI DSS. Controls are pre-populated across all 12 requirements and their sub-requirements.
Am I in Scope?
PCI DSS applies to any entity that stores, processes, or transmits cardholder data or sensitive authentication data, including:- Merchants (online and physical)
- Payment processors and acquirers
- Issuers
- Service providers that handle cardholder data on behalf of other entities
The 12 PCI DSS Requirements
PCI DSS is organized into six goals and 12 requirements:PCI DSS v4.0 Key Changes
If you were compliant with v3.2.1, these are the most significant changes in v4.0:Recommended Implementation Plan
Merchant Levels
Merchant levels and validation requirements vary by card brand. The table above reflects Visa’s classification. Check with your acquiring bank for your specific obligations.
Next Steps
- Controls - working through PCI DSS requirement controls
- Evidence Collection - automated evidence from integrations
- Cloud Tests - vulnerability scanning and penetration testing evidence
- Vendor Risk - service provider compliance management