Framework · Last verified
PCI DSS
PCI DSS is PCI SSC's data security standard for payment account data; v4.0.1 is the only active version, and no compliance certificate is recognized. Assessment runs through PCI SSC-qualified programs: a QSA assessment documented in a Report on Compliance, or a Self-Assessment Questionnaire, each attested in an Attestation of Compliance. Who must validate is decided by payment brands and acquirers.
- Class
- Framework
- Owner
- PCI Security Standards Council (PCI SSC)
- Public register
- Verified working
- Last verified
What it is
The owner's standard page describes it in two sentences this record carries verbatim: "PCI DSS was developed to encourage and enhance payment card account data security and facilitate the broad adoption of consistent data security measures globally." and "PCI DSS provides a baseline of technical and operational requirements designed to protect payment account data."
The current version is v4.0.1 — the owner's document library lists it as the only non-archived edition, and the owner's own blog states: "PCI DSS v4.0 will be retired on 31 December 2024. After that point, PCI DSS v4.0.1 will be the only active version of the standard supported by PCI SSC." The same post describes v4.0.1 as limited to "corrections to formatting and typographical errors" with "no additional or deleted requirements".
What it protects is defined in the owner's glossary: "Account data consists of cardholder data and/or sensitive authentication data." and "At a minimum, cardholder data consists of the full PAN."
The intended audience, from the standard page: "Entities that store, process, or transmit cardholder data (CHD) and/or sensitive authentication data (SAD) or could impact the security of the cardholder data environment (CDE)."
There is a widely-sold artefact this record deliberately does not treat as part of the program: third-party "compliance certificates". The owner's FAQ answers the question directly — such certificates "are not authorized or validated by PCI SSC, and their use is not acceptable for evidencing compliance" — and a 2 September 2025 owner blog post repeats that PCI SSC "does not endorse the use or issuance of compliance certificates". The recognized outputs are the ROC, SAQ and AOC.
A count of the standard's requirements is not carried on this record: the owner's current quick-reference documents for v4.x could not be opened for this round, and the archived guide that could be opened predates v4 — so no requirement list is asserted here.
Who owns it
PCI Security Standards Council, LLC — its about page states: "The Council was founded in 2006 by American Express, Discover, JCB International, MasterCard and Visa Inc." Its contact page gives 401 Edgewater Place, Suite 600, Wakefield, MA, USA.
The Council separates its role from enforcement, verbatim: "The Council's role is to develop and maintain standards. We do not monitor the implementation of standards."
Who assesses it
The owner defines the assessor roles itself. QSAs, from its assessor directory: "Qualified Security Assessor (QSA) companies are independent security organizations that have been qualified by the PCI Security Standards Council to validate an entity's adherence to PCI DSS." A QSA assessment is documented in a Report on Compliance (ROC); self-assessment uses a Self-Assessment Questionnaire (SAQ); both are attested on an Attestation of Compliance (AOC) — "the official PCI SSC form for merchants and service providers to attest to the results of a PCI DSS assessment".
External vulnerability scanning has its own qualified role: an Approved Scanning Vendor (ASV) — a "Company approved by the PCI SSC to conduct external vulnerability scanning services".
Who asks for it
Buyer-driven. PCI SSC itself imposes no obligation. Its own words: whether an entity must comply or validate compliance "is at the discretion of organizations that manage compliance programs, such as a payment brand, acquirer, or other entity" — a contractual layer, not a statute. No statutory anchor was verified for this record.
The owner's own sentence, carried by every PCI record in this library: whether an entity is required to comply or validate compliance "is at the discretion of organizations that manage compliance programs, such as a payment brand, acquirer, or other entity."
Sources
- PCI SSC — PCI DSS standard page (scheme owner) ↗ — accessed
- PCI SSC — About Us (founding, role of the Council) ↗ — accessed
- PCI SSC blog — Just Published: PCI DSS v4.0.1 (version status) ↗ — accessed
- PCI SSC FAQ 1220 — compliance certificates are not recognized ↗ — accessed
- PCI SSC — Glossary (SAQ, ROC, AOC, ASV, account data definitions) ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.