Payment Card Industry Data Security Standard, version 4.0 — a contractual requirement imposed by the card networks, applicable worldwide.
Last updated — August 22, 2026
Any organization that stores, processes, or transmits payment cardholder data — online and physical merchants, payment service providers, hosting providers, and any third party with access to this data within the payment processing chain.
PCI DSS v4.0 organizes its requirements into 12 areas covering network security, cardholder data protection (encryption, tokenization), vulnerability management, access control, monitoring and regular testing, and a formalized information security policy. The applicable compliance route (self-assessment via an SAQ questionnaire, or audit by a QSA) depends on the transaction volume processed by the organization, as determined by the card networks.
Deadlines
There is no legal deadline: PCI DSS is a contractual requirement of the card networks (Visa, Mastercard, etc.) and acquirers, built into card-acceptance commercial agreements, with an ongoing compliance obligation and periodic reassessment (typically annual).
Sanctions
PCI DSS is not a law and carries no public regulatory fine. Non-compliance exposes the organization to contractual consequences set by acquirers and card networks, which can go as far as losing the ability to accept card payments; exact amounts and terms are set by the contract between the organization and its acquirer, not by a public scale.
Determining the cardholder data scope (scoping)
Gap assessment against the 12 PCI DSS v4.0 requirements
Scope reduction (network segmentation, tokenization)
Implementation of technical and organizational controls
Self-assessment (SAQ) or audit by a Qualified Security Assessor (QSA), depending on the applicable level
| Framework | Covered |
|---|---|
| iso-27001 | ✓ |
| soc-2 | ✓ |
Get the checklist by email.
No, it is a contractual requirement imposed by the payment card networks and acquirers, not a government law. It nonetheless applies in practice to any organization that wants to accept card payments.
The SAQ (Self-Assessment Questionnaire) is an in-house self-assessment for the lowest transaction volumes; above a threshold set by the card networks, a formal audit by an external Qualified Security Assessor (QSA) is required.
It reduces the applicable scope but does not fully exempt the organization, which remains responsible for the security of the points where it interacts with the payment flow (redirect page, iframe, terminal).
PCI DSS v4.0 notably strengthens multi-factor authentication and encryption-in-transit requirements, and introduces a customized approach that offers more flexibility in demonstrating compliance.