✳ Payment industry · PCI DSS

PCI DSS: payment data baseline, not a Council certificate

An educational overview of the Payment Card Industry Data Security Standard: payment account data, brand and acquirer validation, and the e-skimming information supplement. Not a coverage determination.

Payment industry · PCI DSSProgram explainerLast reviewed

What category this is

PCI DSS, the Payment Card Industry Data Security Standard, is an industry standard. It is not a U.S. statute. The PCI Security Standards Council says PCI DSS provides a baseline of technical and operational requirements designed to protect payment account data, and that it was developed to encourage consistent data security measures globally.

The Council develops and maintains the standard. It also qualifies assessors (Qualified Security Assessors, QSAs) and scanning vendors (Approved Scanning Vendors, ASVs). That role is not the same sentence as a certificate that a merchant has met the standard.

Edition pin: PCI DSS v4.0.1

The current edition to name is PCI DSS v4.0.1, Requirements and Testing Procedures, published June 2024. The Council's PCI Perspectives post of 11 June 2024 calls v4.0.1 a limited revision of v4.0: corrections and clarifications, with no additional or deleted requirements.

The same post says PCI DSS v4.0 will be retired on 31 December 2024. After that date, v4.0.1 is the only active version of the standard supported by the Council. The standard and the Summary of Changes from v4.0 to v4.0.1 are in the PCI SSC Document Library. This page does not treat a later request for comments as a newly published edition.

Who the standard commonly frames

The Council's intended audience is entities that store, process, or transmit cardholder data (CHD) and/or sensitive authentication data (SAD), or that could impact the security of the cardholder data environment (CDE). That includes merchants, processors, acquirers, issuers, and service providers.

Read that as roles around payment data. It is not "anyone with a website." Whether a named business is in scope is a question for the acquirer and the payment brand program, using the actual payment architecture, not a slogan on a checkout vendor's homepage.

Validation runs through brands and acquirers

Compliance programs, who must validate, reporting, and consequences are managed by payment brands and acquirers. The Council's e-skimming supplement announcement says the Council does not enforce compliance or determine whether specific implementations are compliant, and that entities should collaborate with the organizations managing their compliance programs, such as acquirers or payment brands.

A blog badge that says "PCI certified" is not that program. Talk to your acquirer. Do not treat a marketplace seal as validation, and do not describe Atlas as the issuer of an Attestation of Compliance.

Draw the payment flow before you claim scope

Applicability and the assessment path depend on how payment data actually moves: a redirect, an iframe, a direct post, and who hosts the scripts on the page around the payment fields. The Retail industry path already treats PCI DSS as an industry standard whose scope follows that architecture. Outsourcing one component does not explain the whole customer journey.

The habit is to draw the flow and mark who hosts the payment-page scripts before anyone says "out of scope." This page does not pick an assessment form, and it does not assign a named merchant to one.

E-skimming guidance is a supplement, not the standard

On 10 March 2025 the Council announced an information supplement, Payment Page Security and Preventing E-Skimming, guidance for PCI DSS Requirements 6.4.3 and 11.6.1. It is aimed at e-commerce and at pages that can affect payment security through embedded iframes. The announcement describes authorized scripts, integrity checks, monitoring, and security-impacting HTTP headers.

The Council's line, which this page repeats, is that the supplement provides supplemental guidance and does not add, extend, replace, or supersede requirements in any PCI SSC standard. It is literacy for those two requirements. It is not a second DSS.

Rewrite the certificate sentence

Retire "we are PCI certified by the SSC." A more careful sentence names the edition and the program owners: validation is a payment-brand and acquirer program, and the active Council-supported edition after 31 December 2024 is PCI DSS v4.0.1 (June 2024).

Payment account data and personal data are different questions. When a control serves security and also creates a privacy tension, use the privacy-versus-security lesson for that boundary. Do not look there for a PCI dump. Do not paste card data into Atlas.

Claims to retire

PCI SSC issues a PCI certificate that proves we are compliant.

The Council maintains the standard and qualifies QSAs and ASVs. Compliance programs are managed by payment brands and acquirers. A Council blog is not an Attestation of Compliance.

If we never store the PAN on our servers, PCI DSS cannot apply, and we can ignore payment-page script controls.

The intended audience includes entities that could impact the security of the cardholder data environment, not only entities that store cardholder data. A page that embeds a payment frame can still affect that environment. Draw the flow before you claim the page is out of scope.

The e-skimming information supplement replaces or adds mandatory requirements beyond DSS.

The Council says the supplement does not add, extend, replace, or supersede requirements in any PCI SSC standard. Requirements 6.4.3 and 11.6.1 live in the DSS. The supplement is guidance for them.

Passing an ASV scan alone is full PCI DSS validation.

An Approved Scanning Vendor performs external vulnerability scanning for the applicable scanning requirement. One scan report is not the whole standard, and it is not the brand or acquirer validation program.

A SOC 2 or ISO 27001 report means PCI is done.

Those reports are about the system and criteria they describe. They are not PCI DSS v4.0.1, and they do not replace brand or acquirer validation.

CHECK THE CATEGORY

Rewrite "we are PCI certified by the SSC" for a fictional retailer. Which sentence matches this page?

Glossary and nearby pages

Use the agency page in the sources for the authoritative text. This page has no figure.

Find your next idea.

Tip: press / to open search. Escape closes this window.