The Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards designed to ensure that all companies that accept, process, store, or transmit credit card information maintain a secure environment. PCI DSS was created by the major credit card brands (Visa, MasterCard, American Express, Discover, and JCB).
PCI DSS applies to any organization that handles cardholder data, regardless of size or transaction volume. Compliance is mandatory for all entities that store, process, or transmit cardholder data, and non-compliance can result in significant fines and loss of card processing privileges.
Establish firewall and router configuration standards to protect cardholder data.
Change vendor-supplied defaults and remove or disable unnecessary default accounts.
Encrypt stored cardholder data and use strong cryptography and security protocols.
Encrypt cardholder data transmission across open, public networks.
Deploy anti-virus software on all systems commonly affected by malware.
Develop and maintain secure systems and applications with security patches.
Limit access to cardholder data to only those who need it for business purposes.
Assign unique IDs to each person with computer access and implement strong authentication.
Restrict physical access to cardholder data and ensure proper disposal of media.
Track and monitor all access to network resources and cardholder data.
Regularly test security systems and processes including vulnerability scans and penetration testing.
Maintain a policy that addresses information security for all personnel.
Merchants processing 6M+ transactions annually
Merchants processing 1M-6M transactions annually
Merchants processing 20K-1M transactions annually
Merchants processing <20K transactions annually
Identify all systems, networks, and processes that store, process, or transmit cardholder data.
Assess current security controls against PCI DSS requirements and identify gaps.
Implement missing controls and address identified security gaps.
Conduct formal assessment using Self-Assessment Questionnaire (SAQ) or on-site assessment.
Submit Attestation of Compliance (AOC) and maintain ongoing compliance.
Get expert guidance on PCI DSS implementation and compliance.
Schedule Free Consultation