The Payment Card Industry Data Security Standard (PCI-DSS) applies to any business that stores, processes or transmits cardholder data. It’s organised around twelve requirements. This breakdown explains each in plain English and the risk of ignoring it. For a shorter overview, see our PCI-DSS guide.
How to read this breakdown:
In black — what the requirement asks for, in plain summary.
In blue — what it actually means for your business.
In red — the risk if you leave it unaddressed.
1. Maintain network security controls
The requirement: Use firewalls and network controls to protect the systems that handle cardholder data.
What it means: Shield and segment your payment systems so they aren’t sitting on the same open network as everything else.
Risk if ignored: A flat, unprotected network lets an attacker who gets in anywhere reach your card data directly.
2. Apply secure configurations
The requirement: Harden all systems and change vendor defaults — default passwords, sample accounts and unnecessary services.
What it means: No out-of-the-box passwords or needless features left switched on.
Risk if ignored: Default credentials are the very first thing attackers try, and on misconfigured systems they still work alarmingly often.
3. Protect stored account data
The requirement: Store as little cardholder data as possible, render anything you must keep unreadable (e.g. encryption or truncation), and never store sensitive authentication data such as the CVV after a payment is authorised.
What it means: Keep the minimum, encrypted — and never the security code.
Risk if ignored: Stored, unencrypted card data is the jackpot attackers hunt for, and the most damaging and expensive kind of breach.
4. Encrypt data in transit
The requirement: Use strong cryptography (such as TLS) whenever cardholder data travels across open, public networks.
What it means: Card data moving over the internet must be encrypted end to end.
Risk if ignored: Unencrypted card data can be intercepted in transit and immediately used for fraud.
5. Protect against malware
The requirement: Deploy and keep up to date anti-malware protection on systems at risk of infection.
What it means: Keep endpoints and servers protected and current.
Risk if ignored: Malware — including card ‘skimmers’ — silently harvests card numbers from infected point-of-sale and web systems.
6. Develop and maintain secure systems
The requirement: Patch vulnerabilities promptly and build security into how you develop and change software.
What it means: Fix known flaws quickly and write/configure code securely.
Risk if ignored: Unpatched systems and insecure web code (like injection flaws) are among the leading causes of card-data breaches.
7. Restrict access by need to know
The requirement: Limit access to cardholder data to only the people whose role genuinely requires it.
What it means: Apply least privilege — not everyone needs to see card data.
Risk if ignored: Broad access means any single compromised account can reach all of your card data at once.
8. Identify and authenticate access
The requirement: Give every user a unique ID and require strong authentication, including multi-factor authentication into the cardholder data environment.
What it means: Unique logins for everyone, plus MFA.
Risk if ignored: Shared or weakly protected logins make a breach easy to pull off and almost impossible to trace.
9. Restrict physical access
The requirement: Physically protect the systems, devices and media that store or process cardholder data.
What it means: Lock down payment terminals, server areas and any paper records.
Risk if ignored: A tampered card terminal or a stolen device leaks card data no matter how strong your digital controls are.
10. Log and monitor all access
The requirement: Log access to systems and cardholder data, and actively monitor those logs.
What it means: Keep an audit trail — and actually review it.
Risk if ignored: Without logs you can’t detect a breach or reconstruct what happened, which is how attackers stay undetected for months.
11. Test security regularly
The requirement: Regularly scan for vulnerabilities and carry out penetration testing.
What it means: Proactively hunt for weaknesses before attackers find them.
Risk if ignored: Unknown vulnerabilities pile up over time and eventually get exploited — and you find out the hard way.
12. Maintain a security policy and program
The requirement: Keep security policies and an ongoing program that makes everyone responsible for protecting cardholder data.
What it means: Governance, training and clear accountability that keep the other controls alive.
Risk if ignored: Without a living policy and program, controls decay and staff simply don’t know their responsibilities.
Reducing your scope
Most small and medium businesses demonstrate compliance through a Self-Assessment Questionnaire (SAQ), and the simplest path is to use a reputable, PCI-compliant payment provider so that you never handle raw card data directly — dramatically shrinking what you’re responsible for.
Check your payment and data security posture — free, in about five minutes.