PCI DSS Explained: What It Actually Requires
Written by Myles Dacres
PCI DSS is the Payment Card Industry Data Security Standard, a set of security requirements for any organisation that stores, processes, or transmits cardholder data.
PCI DSS stands for the Payment Card Industry Data Security Standard. It’s a set of security requirements created by the major card schemes (Visa, Mastercard and the others) that applies to any organisation that stores, processes, or transmits cardholder data, regardless of size or sector.
Who PCI DSS actually applies to
If your organisation takes card payments in any form, in person, online, or over the phone, PCI DSS applies to you. That includes retailers, hospitality businesses, healthcare providers, charities taking donations by card, and any organisation using a third-party payment processor. Using a payment provider reduces some of your obligations, but it doesn’t remove them entirely, you still need to understand what that provider is doing on your behalf and confirm it’s compliant.
What the standard actually requires
PCI DSS is built around a set of control areas rather than a single checklist. In broad terms, organisations need to: build and maintain a secure network, protect stored cardholder data, encrypt data in transit, use and update anti-malware protection, restrict access to cardholder data on a need-to-know basis, monitor and test networks regularly, and maintain a formal information security policy. The specific technical requirements underneath each of these depend on how much card data your organisation handles and how you handle it.
The compliance levels
PCI DSS applies different levels of scrutiny depending on transaction volume. Smaller organisations typically complete a Self-Assessment Questionnaire (SAQ), a structured set of questions covering the relevant controls. Larger organisations, generally those processing millions of transactions a year, need an external assessment carried out by a Qualified Security Assessor (QSA). Which level and which SAQ type applies depends on exactly how your organisation takes payments, so this isn’t something to assume from general size alone.
Why PCI DSS matters beyond the requirement itself
PCI DSS compliance isn’t optional in the way some standards are. Card schemes and acquiring banks can apply fines for non-compliance, and in the event of a card data breach, an organisation that wasn’t compliant faces significantly more exposure, both financially and reputationally, than one that can demonstrate it met the standard. There’s also a genuine security argument underneath the compliance requirement, cardholder data is one of the most consistently targeted types of data, and the controls PCI DSS requires exist because they address real, common attack methods.
PCI DSS and UK GDPR are not the same thing
It’s worth being precise here. PCI DSS is a payment card industry standard, not a UK GDPR requirement. Cardholder data is personal data, so UK GDPR still applies to how you handle it, but meeting PCI DSS doesn’t automatically mean you’re meeting your UK GDPR obligations, and vice versa. Organisations that treat the two as interchangeable often end up with a security programme that satisfies one and quietly misses parts of the other.
Questions organisations usually ask about PCI DSS
Does using a payment processor like Stripe or Worldpay mean we’re already compliant? No, though it does reduce your workload considerably. A reputable processor handles a large share of the technical requirements, but your organisation still needs to complete the relevant SAQ, follow secure practices around how payment pages are built and hosted and confirm the processor’s own compliance rather than assuming it. Outsourcing the technology doesn’t outsource the responsibility.
What actually happens if we’re not compliant and suffer a breach? Consequences typically include fines from the card schemes or your acquiring bank, potential loss of the ability to process card payments at all, and considerably higher costs if a breach investigation finds you weren’t meeting the standard at the time. Compliance doesn’t prevent every breach, but it materially changes the financial and reputational outcome if one happens.
Do small organisations really need to worry about this? Yes, though the level of scrutiny scales with volume. Even a small organisation taking a modest number of card payments a year has an SAQ obligation, it’s simply a shorter, less intensive one than a large retailer would face. The requirement doesn’t have a size threshold below which it stops applying.
How long does becoming compliant usually take? This depends heavily on your current setup, but establishing scope, completing the right SAQ and closing any gaps typically takes a matter of weeks for a straightforward small or mid-sized organisation, longer if cardholder data touches more systems than expected once you actually map it out properly.
Getting started with PCI DSS compliance
The first practical step is usually establishing your actual scope, working out exactly where cardholder data enters, moves through and leaves your systems, since PCI DSS requirements apply specifically to that scope, not your whole IT estate. From there, the right SAQ type or assessment path becomes much clearer, along with which of the control areas above need real attention versus which are already covered.
If you’re not sure where your organisation sits with PCI DSS, or you know you need to get compliant and want it handled properly rather than guessed at, our PCI DSS service is built for exactly this.