The Payment Card Industry Data Security Standard (PCI-DSS) is a global standard that sets the security requirements for any business that stores, processes or transmits cardholder data. If you accept card payments — in-store, over the phone or online — PCI-DSS applies to you.
What it requires
PCI-DSS is organised around twelve requirements covering areas such as securing your network, protecting stored cardholder data, encrypting data in transit, managing access, monitoring and testing, and maintaining an information security policy. A central principle is to minimise the card data you handle — ideally never storing full card numbers, and never storing the security code (CVV).
How compliance is demonstrated
Most small and medium businesses demonstrate compliance through a Self-Assessment Questionnaire (SAQ). The specific SAQ depends on how you take payments — for example, businesses that outsource their entire online payment process to a compliant provider have a much simpler path than those that handle card data directly. Using a reputable, PCI-compliant payment gateway is the easiest way to reduce your scope.
Practical steps
- Use a compliant payment provider and avoid storing raw card data.
- Keep point-of-sale systems patched and separated from public Wi-Fi.
- Protect your eCommerce platform and plugins against skimming attacks.
- Complete the relevant SAQ for your payment channels.
CyberSafeCheck’s retail and finance assessments include PCI-DSS considerations alongside the broader security fundamentals. See also our guides to the Essential Eight and the Privacy Act.
Go deeper: read our requirement-by-requirement breakdown of PCI-DSS — what each part means in plain English, and the risk of leaving it unaddressed.
Assess your payment security
Take the free CyberSafeCheck assessment and see how your business measures up — instant score, compliance check and a prioritised action plan in about five minutes.