First launched in 2006, the Payment Card Industry Data Security Standard (PCI DSS) has become the leading set of security standards for maintaining a secure environment for all companies—regardless of size or number of transactions—that accept, process, store, or transmit credit card information.
The ongoing pursuit of PCI compliance is supported by required annual assessments, and for good reason: One study found that only about a third of companies are still compliant one year after their initial validation. And non-compliant merchants run a higher risk of breach, audit, fines, and damage to brand reputation. Compliance must be an ongoing endeavor; focusing solely on the annual assessment may create a false sense of security.
PCI compliance is the beginning of security, not the end. Download this free ebook to learn more about:
- How PCI DSS compliance standards are evolving alongside changes in technology
- Key priorities and goals for PCI DSS 4.0 that companies will need to adhere to by 2024
- Considerations for building ongoing PCI DSS compliance capabilities
What PCI DSS Covers
Launched in September 2006, the Payment Card Industry Data Security Standard applies to every organization that accepts, processes, stores or transmits payment card information, regardless of size or transaction volume. It is administered by the PCI Security Standards Council, an independent body created by Visa, MasterCard, American Express, Discover and JCB.
The Four Merchant Levels
Merchants are assigned a level by transaction volume over twelve months, and the validation required rises with it. Level 1, above six million card transactions a year, requires an annual Report on Compliance from a Qualified Security Assessor or Internal Security Assessor, quarterly network scans by an Approved Scanning Vendor, and an Attestation of Compliance.
Levels 2, 3 and 4 use a self-assessment questionnaire with quarterly scans and an attestation. A merchant that suffers a breach involving compromised account data can be moved to a higher level with stricter validation.
Compliance Decays After Validation
Annual assessment is required at every level, and the reason shows up in the data: one study found only about a third of companies were still compliant a year after their initial validation.
Non-compliant merchants carry a higher risk of breach, audit, fines and brand damage. The useful framing is the one the standard’s own practitioners use: PCI compliance is the beginning of security, not the end.
Reducing Scope Is the Cheapest Improvement Available
An audit examines any device, component, network or application that stores, processes or transmits cardholder data. The size of that set determines what the assessment costs and how long it takes.
Scope can be reduced before the audit rather than after it. Redaction removes data irreversibly, masking and encryption protect it reversibly, and cardholder data treated in any of those ways can fall outside what has to be assessed. Applying that protection before the data reaches a system is what keeps the system out of scope in the first place.
Storing Card Data Raises the Bar
Organizations that do not store card data generally find compliance easier, for the obvious reason. Those that must store it, for recurring billing or similar, face a much higher self-assessment threshold and may need a Qualified Security Assessor to verify controls regardless of merchant level.
Building Ongoing Capability Instead of an Annual Exercise
The organizations that stay compliant treat discovery and protection as continuous. Card data appears in new places between assessments, through a new report, a partner extract or a test environment refreshed from production, and a control that only runs before an audit will not find it.
Continuous discovery, with protection applied automatically when cardholder data is located, keeps the scope stable rather than letting it grow quietly for eleven months of the year.

