You can't take payments without it
Handling cards without PCI compliance risks fines, higher processing fees, and losing the ability to accept payments at all. Non-negotiable if money moves through you.
Protecting cardholder data, end to end.
PCI DSS is the security standard for organisations that store, process or transmit payment-card data. Version 4.0.1 modernises requirements with more flexibility (the customised approach) and a stronger focus on continuous security rather than annual point-in-time checks.
The standard
PCI DSS v4.0.1 — Payment Card Industry Data Security Standard
Who needs it
Merchants and service providers of every size that handle cardholder data — with validation scope tied to transaction volume and the way you process payments.
12
Requirements tracked
The basics
PCI DSS is the security standard for anyone who stores, processes or transmits payment-card data. It isn't a law but a contractual requirement from the card brands — and the moment a card number touches your systems, it applies to you.
Version 4.0.1 modernised the standard: it adds flexibility through a 'customised approach' (meet the objective your own way, and evidence it), and shifts the emphasis from an annual point-in-time check to security you maintain continuously.
Why it matters
Handling cards without PCI compliance risks fines, higher processing fees, and losing the ability to accept payments at all. Non-negotiable if money moves through you.
Good PCI practice — segmentation, tokenisation — reduces both the data you hold and the blast radius if you're ever breached.
Banks, processors and enterprise customers all sleep better knowing you're PCI compliant. It's table stakes for fintech and commerce.
Organised under six goals, from secure networks to access control and monitoring.
v4.0 lets you meet an objective with alternative controls, evidenced accordingly.
Many requirements are now business-as-usual activities, not annual events.
Segmentation and tokenisation shrink the cardholder-data environment you must secure.
PCI's 12 requirements sprawl across your whole environment, and v4.0.1's move to continuous, business-as-usual activities means the old 'cram before the annual assessment' approach quietly falls apart.
Do it once, reuse it everywhere. Evidence you collect for PCI DSSis automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.
See exactly how Compliance One maps PCI DSS to your environment in a 30-minute walkthrough — and how much of it we handle for you.