Skip to content

47-Day Certificates Are Coming. Are You Ready?

Act Now →

What Is PCI DSS and How Do You Become Compliant?

What-is-PCI-DSS-How-do-you-become-compliant-with-PCI-DSS

The Payment Card Industry Data Security Standard (PCI DSS) is a set of security requirements, maintained by the PCI Security Standards Council, that any organization storing, processing, or transmitting cardholder data must follow to protect against theft and fraud.

PCI DSS is a global security standard, currently at version 4.0.1, that requires organizations handling cardholder data to maintain firewalls, encrypt data in transit, restrict access on a need-to-know basis, and test security systems regularly. It applies wherever card data is stored, processed, or transmitted, including in the cloud.

Key Takeaways

  • PCI DSS was formed in 2004 by major card brands and is now maintained by the PCI Security Standards Council.
  • PCI DSS version 4.0.1 is the current baseline; it strengthens requirements around authentication, encryption, and continuous monitoring compared to version 3.2.1.
  • PCI DSS applies to any environment, including cloud infrastructure, where cardholder data is stored, processed, or transmitted.
  • Compliance requires validating both the Cloud Service Provider’s infrastructure and the client’s usage of that environment when card data touches the cloud.
  • The standard’s twelve original requirement areas remain the operational backbone of a PCI DSS assessment today.

What are the core PCI DSS requirements?

Maintain a policy that addresses information security for all personnel.

Install and maintain a firewall configuration to protect cardholder data.

Do not use vendor-supplied defaults for system passwords and other security parameters.

Protect stored cardholder data.

Encrypt transmission of cardholder data across open, public networks.

Use and regularly update anti-virus software or programs.

Develop and maintain secure systems and applications.

Restrict access to cardholder data on a business need-to-know basis.

Assign a unique ID to each person with computer access.

Restrict physical access to cardholder data.

Track and monitor all access to network resources and cardholder data.

Regularly test security systems and processes.

Enterprise PKI Services

Get complete end-to-end consultation support for all your PKI requirements!

How does PCI DSS apply to cloud environments?

When cardholder data is stored, processed, or transmitted in a cloud environment, PCI DSS applies to that environment directly. An assessment then needs to validate two things: the Cloud Service Provider’s own infrastructure controls, and how the client configures and uses that environment, since a misconfigured client setup can undermine an otherwise-compliant CSP.

How Encryption Consulting Helps

Encryption Consulting’s Compliance Advisory Services and Cloud Data Protection Services help organizations encrypt cardholder data at rest and in transit, manage the keys behind that encryption, and validate cloud configurations against PCI DSS 4.0.1’s current requirements. Backed by ISO/IEC 27001:2022 and SOC 2 certified practices.

Frequently Asked Questions

What version of PCI DSS is currently in effect?

PCI DSS version 4.0.1 is the current baseline organizations are assessed against. It builds on version 3.2.1 with stronger requirements around authentication, encryption, and continuous security monitoring.

Does PCI DSS apply if I use a cloud provider to process payments?

Yes. PCI DSS applies to any environment where cardholder data is stored, processed, or transmitted, including cloud infrastructure. An assessment covers both the Cloud Service Provider’s controls and the client’s configuration and use of that environment.

Who created PCI DSS?

PCI DSS was formed in 2004 by major payment card brands and is maintained today by the PCI Security Standards Council, an independent body responsible for developing, evolving, and promoting the standard.

What is the difference between PCI DSS requirement 3 and requirement 4?

Requirement 3 covers protecting stored cardholder data, primarily through encryption and truncation at rest. Requirement 4 covers encrypting cardholder data as it moves across open, public networks, primarily through TLS.

Encrypt and Protect Cardholder Data

Take the next step
Encryption Consulting helps you encrypt cardholder data at rest and in transit and manage the keys PCI DSS 4.0.1 requires you to protect. Simplify your compliance path with Compliance Advisory Services.