12
PCI DSS requirements
256-bit
Data encryption
4
Merchant levels covered
24-48h
Approval turnaround
PCI DSS Requirements

The 12 PCI DSS requirements, made simple

PCI DSS is built on twelve core requirements grouped into six security goals. Here is the full checklist in plain language, so you always know what cardholder data security looks like.

01

Install firewalls

Build and maintain a secure network with properly configured firewalls protecting cardholder data.

02

No vendor defaults

Replace vendor-supplied passwords and default security settings before any system goes live.

03

Protect stored data

Protect stored cardholder data with tokenization, truncation and strong encryption keys.

04

Encrypt in transit

Encrypt cardholder data with TLS whenever it travels across open or public networks.

05

Anti-malware

Use and regularly update anti-virus and anti-malware software on all in-scope systems.

06

Secure systems

Develop and maintain secure systems and applications, and patch known vulnerabilities promptly.

07

Restrict access

Restrict access to cardholder data on a strict business need-to-know basis.

08

Unique IDs

Assign a unique ID to everyone with system access and enforce multi-factor authentication.

09

Physical access

Restrict physical access to cardholder data, media, devices and payment terminals.

10

Track & monitor

Track and monitor all access to network resources and cardholder data with audit logs.

11

Test security

Regularly test security systems and processes with vulnerability scans and penetration tests.

12

Security policy

Maintain an information security policy that addresses staff, vendors and ongoing responsibilities.

We map these PCI DSS requirements to your exact setup so nothing on the checklist gets missed.

Merchant Levels

Which PCI merchant level are you?

Your PCI compliance obligations scale with the number of card transactions you process each year. We help you confirm your level and meet the right validation requirements for it.

Level 1
6M+transactions / year

The highest-volume merchants. Requires an annual on-site assessment by a Qualified Security Assessor plus quarterly network scans.

Level 2
1M - 6Mtransactions / year

Mid-to-large merchants. Typically validate with an annual Self-Assessment Questionnaire and quarterly scans by an approved scanning vendor.

Level 3
20K - 1MeCommerce / year

Growing eCommerce merchants. Validate with the appropriate SAQ and quarterly external vulnerability scans.

Level 4
Up to 20KeCommerce / year

Smaller and newer merchants. Validate with a Self-Assessment Questionnaire and scans where required by your acquirer.

How We Help

How we keep you PCI compliant

From your first assessment to ongoing monitoring, our team handles the heavy lifting so secure payment processing stays simple year after year.

1

Scope & assess

We review how you accept and store payments to define your PCI scope and the right SAQ for your business.

2

Secure the data

We deploy tokenization and end-to-end encryption that keep raw cardholder data out of your environment.

3

Validate & file

We guide you through completing the questionnaire and any required scans, then file your validation.

4

Monitor & renew

We keep monitoring controls active and prompt you ahead of renewals so you never fall out of compliance.

SAQ Types

Understanding the SAQ types

A Self-Assessment Questionnaire (SAQ) validates your PCI compliance. The right SAQ depends on how you accept payments - we match you to it so you only answer what applies.

A

SAQ A

Card-not-present merchants who fully outsource cardholder data handling to a compliant third party.

A-EP

SAQ A-EP

eCommerce merchants that partially outsource payment pages but still affect transaction security.

B

SAQ B

Merchants using standalone, dial-out terminals or imprint machines with no electronic storage.

B-IP

SAQ B-IP

Merchants using standalone, IP-connected payment terminals with no electronic cardholder data storage.

C-VT

SAQ C-VT

Merchants who key transactions one at a time into a web-based virtual terminal on an isolated device.

D

SAQ D

All other merchants and service providers that store, process or transmit cardholder data directly.

Security Benefits

Why PCI compliant payment processing pays off

Compliance is more than a checkbox. It protects your customers, shields your business from breach costs and fines, and builds the trust that keeps buyers coming back.

Cardholder data security

Tokenization and encryption replace sensitive card numbers with useless tokens, so a breach has nothing worth stealing.

Avoid fines & penalties

Staying compliant helps you avoid non-compliance fees, higher reserves and the heavy costs that follow a data breach.

Data encryption built in

End-to-end encryption protects every transaction in transit, keeping raw cardholder data out of your systems entirely.

Keep your merchant account

Compliance is a condition of accepting cards. We keep your validation current so processing never gets interrupted.

Continuous monitoring

Ongoing scanning and monitoring catch new vulnerabilities early, so secure payment processing stays that way.

Customer trust

Shoppers complete more purchases when they know their card details are handled by a PCI compliant business.

Security you can prove

PCI DSS compliance backed by encryption, tokenization and monitoring that protect every cardholder transaction.

12/12
PCI DSS requirements covered
256-bit
End-to-end encryption
0
Raw card data stored
24/7
Compliance monitoring
FAQ

PCI compliance questions answered

Common questions about PCI DSS compliance, SAQs and cardholder data security.

What is PCI compliance?

PCI compliance means meeting the Payment Card Industry Data Security Standard (PCI DSS), a set of security requirements created by the major card brands. Any business that stores, processes or transmits cardholder data must comply. It protects your customers and is a condition of keeping your merchant account.

Do small businesses really need to be PCI compliant?

Yes. PCI DSS compliance applies to every business that accepts card payments, regardless of size or transaction volume. Smaller merchants usually validate with a simpler Self-Assessment Questionnaire rather than a full on-site audit, and we help you complete the right one.

What is an SAQ?

An SAQ is a Self-Assessment Questionnaire used to validate PCI compliance. There are several types based on how you accept payments, such as SAQ A for fully outsourced eCommerce or SAQ D for merchants that handle cardholder data directly. We match you to the correct SAQ so you only answer what applies to your setup.

How do tokenization and encryption keep cardholder data secure?

Encryption scrambles card data while it travels across networks so it cannot be read in transit. Tokenization replaces the actual card number with a random token that has no value if stolen. Together they keep raw cardholder data out of your systems, which shrinks your PCI scope and reduces breach risk.

What happens if my business is not PCI compliant?

Non-compliance can lead to monthly fees, higher transaction costs and larger penalties if a breach occurs. You may also lose the ability to accept cards. Staying PCI compliant with ongoing monitoring helps you avoid these costs and keep secure payment processing running smoothly.

How long does it take to become PCI compliant?

Many merchants complete their initial validation within days once their setup is reviewed. We scope your environment, deploy tokenization and encryption, guide you through the questionnaire and any required scans, and get your merchant account approved in as little as 24 to 48 hours.

Get PCI compliant with confidence

Protect cardholder data, satisfy PCI DSS requirements and keep accepting payments securely. Our specialists handle the checklist with you from start to finish.