PCI DSS

PCI DSS (the Payment Card Industry Data Security Standard) is a contractually mandated standard for organizations that store, process, or transmit payment card data, requiring specific technical and organizational controls maintained by the PCI Security Standards Council.

What PCI DSS Requires

PCI DSS is organized around 12 top-level requirements covering areas like building and maintaining secure networks, protecting cardholder data, maintaining vulnerability management programs, implementing strong access control, monitoring and testing networks, and maintaining information security policy.

Compliance obligations scale with card transaction volume. Level 1 merchants (highest volume) require an annual on-site assessment by a Qualified Security Assessor. Smaller merchants may complete self-assessment questionnaires.

PCI DSS Enforcement

PCI DSS is enforced contractually rather than by law directly. Card brands (Visa, Mastercard, and others) require compliance from merchants and service providers as a condition of processing card payments. Non-compliance can produce fines, increased transaction fees, and loss of card processing privileges.

Following a breach, non-compliance with PCI DSS can also feature in litigation and regulatory action, since it goes to the reasonableness of security measures.

PCI DSS in Quantified Programs

PCI DSS-driven exposure for organizations handling card data typically appears in CRQ models as regulatory and contractual penalty potential attached to card data breach scenarios. Quantified programs model both direct fines and the broader operational consequences (loss of processing capability, forensic investigation costs).

Related Terms

Turn Cyber Risk Into Financial Exposure the Board Can Act On

Security leaders are being asked to defend budgets, prioritize controls, and report cyber risk in the same terms as every other enterprise risk. Kovrr's CRQ Platform models loss scenarios, benchmarks control performance, and gives the C-suite a defensible view of where cyber sits on the balance sheet.