The Payment Card Industry Security Standards Council (PCI SSC)

The Payment Card Industry Security Standards Council (PCI SSC) is the body that develops and maintains the security standards governing how payment card data is handled. It was founded in 2006 by the five major card networks — Visa, Mastercard, American Express, Discover and JCB — to replace five separate and diverging programs with one common set of requirements.

The council writes the standards. It does not enforce them. That distinction causes more confusion than anything else about PCI, and it explains most of what follows.

Founded 2006, by the five major card networks
Principal standard PCI DSS — Payment Card Industry Data Security Standard
Current version PCI DSS v4.0.1; v4.0 retired 31 December 2024
Future-dated requirements Mandatory since 31 March 2025 — no further grace period
Who enforces The card networks and acquiring banks, through contract
Who assesses Qualified Security Assessors, and self-assessment at lower volumes

What the council produces

PCI DSS is the main standard, applying to any organization that stores, processes or transmits cardholder data. It is organized around twelve requirements covering network security, protection of stored data, vulnerability management, access control, monitoring and security policy.

The council also maintains standards for payment applications, PIN transaction security for hardware, point-to-point encryption, the software lifecycle, and 3-D Secure, plus the qualification programs for assessors and scanning vendors.

Validation depends on volume. Merchants fall into levels based on annual transaction count; the largest require an on-site assessment by a Qualified Security Assessor producing a Report on Compliance, while smaller merchants complete a self-assessment questionnaire matched to how they handle card data. A merchant who has fully outsourced payment handling answers a far shorter questionnaire than one operating its own storage.

What changed in version 4

Version 4 was the first structural revision in over a decade, and it introduced two shifts worth knowing.

Customized implementation. Alongside the prescriptive requirements, organizations may now meet a requirement’s objective by a different means, provided they document the approach and demonstrate it achieves the stated outcome. This suits mature security programs and raises the evidentiary burden considerably — it is not a lighter path.

Continuous rather than annual. Version 4 pushes toward security as a business-as-usual activity, with requirements around ongoing scoping, monitoring and targeted risk analyses rather than a once-a-year exercise.

On timing: v4.0 retired at the end of 2024, making v4.0.1 the only active version, and the future-dated requirements — the large set given an extended runway — became mandatory on 31 March 2025. Assessors are required to evaluate them, and there is no additional grace period.

Why it matters for identity verification

PCI DSS is a data protection standard, not a fraud prevention one, and keeping that boundary clear prevents a common and expensive category error.

The standard governs how cardholder data is stored, transmitted and access-controlled. It is silent on whether the person using a card is entitled to. A fully compliant merchant can be defrauded all day by clean fraud — the stolen card details are handled to the letter of the standard, and the transaction is still fraudulent. Compliance and fraud losses are independent variables.

The two connect in one direction only: PCI reduces the supply of stolen card data by making breaches harder, and the data that does escape is used in fraud that PCI has nothing to say about. Merchants who read their compliance status as fraud protection are reading a network security certification as an identity control.

There is one genuine overlap. Version 4’s requirements around scripts on payment pages were added in response to digital skimming — malicious JavaScript harvesting card details as they are typed into a checkout form. That is a case where the standard addresses an active fraud technique rather than only data at rest.

Who does what

Party Role
PCI SSC Writes and maintains the standards; qualifies assessors
Card networks Set compliance and validation requirements; levy fines
Acquiring banks Contractually require compliance of their merchants and pass fines down
Qualified Security Assessors Perform assessments and produce Reports on Compliance
Merchants and service providers Implement the controls and validate at the required level

The consequence: PCI is contractual, not statutory. The council cannot fine anyone. Penalties reach a merchant through its acquirer, which is why the immediate consequence of non-compliance is usually a commercial conversation rather than a regulatory one — though several jurisdictions now reference PCI in law or regulation, which blurs this at the edges.

What PCI compliance does not prove

It is not a guarantee against breach. Several of the largest card breaches involved organizations that had been validated as compliant. An assessment describes a point in time, and environments change between them.

It does not cover fraud. Nothing in the standard concerns whether a transaction is legitimate.

It does not extend beyond card data. Identity documents, biometric templates and personal data generally are governed by privacy law, not by PCI. An organization can be fully PCI compliant and badly exposed under GDPR or the CCPA.

Self-assessment is self-asserted. Most merchants validate by questionnaire. A completed SAQ records what the merchant states about itself, with no independent examination behind it.

Frequently asked questions

What is the difference between PCI SSC and PCI DSS?

PCI SSC is the organization; PCI DSS is the standard it publishes. The council writes and maintains the standard and qualifies assessors, while enforcement sits with the card networks and acquiring banks through their contracts with merchants.

Which version of PCI DSS applies now?

PCI DSS v4.0.1. Version 4.0 retired on 31 December 2024, and the future-dated requirements introduced in version 4 became mandatory on 31 March 2025, so assessments now evaluate the full set with no remaining transition allowance.

Who enforces PCI DSS?

The card networks and acquiring banks, contractually. The PCI SSC has no enforcement power and cannot impose penalties. Fines flow from the networks through acquirers to merchants, and the most serious consequence is loss of the ability to accept card payments.

Does PCI compliance prevent fraud?

No. It governs how card data is protected, not whether the person using a card is entitled to. A compliant merchant can still accept fraudulent transactions made with correctly stolen details, which is why card data security and fraud prevention need separate controls.

Related reading

  • Clean fraud — the fraud a fully compliant merchant still absorbs
  • Skimming — including the digital variant version 4 addresses
  • Credit card fraud — what the stolen data is eventually used for
  • Chargeback — how the resulting loss reaches the merchant

Discover Our Solutions

Exploring our solutions is just a click away. Try our products or have a chat with one of our experts to delve deeper into what we offer.

Report
Mapping the Rise of AI-Powered Identity Fraud

AI didn't just make fraud faster. It made it a system. We analyzed millions of identity interactions to map how identity attacks are evolving across regions, attack types, and sophistication levels — and what organizations need to rethink to keep pace.

See the Data