PCI DSS
Know which PCI DSS requirements apply to you, close the gaps that matter, and validate compliance with QSAs alongside your team.
0
0 +
0 +
What is PCI DSS?
The Payment Card Industry Data Security Standard (PCI DSS) is the global security standard for protecting payment account data. It applies to any organization that stores, processes or transmits cardholder data, and to any entity that can affect the security of the cardholder data environment. Merchants, service providers, financial institutions, issuers, acquirers and technology providers all fall under it in different ways.
Is PCI DSS mandatory in Canada?
PCI DSS is not set by a Canadian regulator. It is enforced contractually through your acquiring bank and the card brands, and non-compliance is handled as an assessment debited through your processor rather than as a regulatory fine. Canadian Privacy Commissioners have also treated PCI DSS as an industry benchmark when assessing whether personal information was adequately safeguarded, so your PCI position can carry weight under privacy law as well as under your acquirer agreement.
A risk-based approach to PCI DSS compliance
A risk-based approach puts the effort where cardholder data sits and where the requirements genuinely apply. You get a clear picture of your obligations, the gaps standing between you and compliance, and a route through the assessment process. Integrity360's Qualified Security Assessors (QSAs) work with you at each stage, across PCI DSS v4.0.1.
PCI DSS compliance in three steps
PCI DSS Scope Analysis Review
Knowing which PCI DSS controls apply to your environment, and which systems need protecting, is where the work starts. Getting scope right before you change how Cardholder Data (CHD) is handled saves time, reduces cost and keeps effort on the systems that hold, process or transmit payment data.
PCI DSS Gap Analysis Review
Meeting all applicable PCI DSS requirements starts with knowing where your current environment falls short. The Gap Analysis Review gives you a realistic picture of security and compliance deficiencies, along with practical remediation options across products, solutions and service providers.
Once gaps are identified and remediation options mapped, the work effort becomes quantifiable and easier to plan. You get a prioritized roadmap that takes on the most significant gaps first, so the route to compliance is structured and costed.
PCI DSS Formal Assessment of Compliance
If you store, process or transmit payment card data as a merchant, service provider, issuer or acquirer, you are required to demonstrate PCI DSS compliance on a recurring basis, with the frequency and validation method set by your acquiring bank or payment brand. Integrity360's QSAs work alongside your team through that process and provide the independent validation your card brands and stakeholders need to see.
What changed in PCI DSS v4.0.1?
PCI DSS v4.0.1 is the current version of the standard. Of the 64 new requirements introduced in v4.0, 51 became mandatory on 31 March 2025, covering authentication, access control, vulnerability management, monitoring, security testing, e-commerce security and targeted risk analysis. Many of them describe activities carried out through the year, which changes what your evidence needs to look like when the assessment comes around.
Speak to an expert
Where you start depends on how much of your environment falls in scope and when your next validation is due. Talk to an advisor about the right first step for your payment environment.
Dublin: +353 01 293 4027
London: +44 20 3397 3414
Sofia: +359 2 491 0110
Cape Town: +27 08 606 25673
Johannesburg: +27 08 606 25673
PCI 3DS
PCI P2PE
Swift CSP Assessment
PCI DSS compliance FAQs
What is PCI DSS?
PCI DSS, or the Payment Card Industry Data Security Standard, is a global security standard designed to protect payment account data. It applies to organizations that store, process or transmit cardholder data, as well as entities that can affect the security of the cardholder data environment.
Who needs to comply with PCI DSS?
Organizations that store, process or transmit payment card data may be required to comply with PCI DSS. This can include merchants, service providers, financial institutions and technology providers. The exact validation requirements depend on factors such as the organization's role, transaction volumes and the requirements of the relevant acquiring bank or payment brand.
What is PCI DSS v4.0.1?
PCI DSS v4.0.1 is the current version of the PCI Data Security Standard. It includes requirements covering areas such as authentication, access control, vulnerability management, monitoring, security testing, e-commerce security and targeted risk analysis. Of the 64 new requirements introduced in v4.0, 51 became mandatory on 31 March 2025.
How do I know which PCI DSS requirements apply to my organization?
The requirements that apply depend on your payment environment, how cardholder data is handled and the systems, people and processes that can affect its security. A PCI DSS scoping exercise can help identify the cardholder data environment and determine which systems and controls fall within scope.
What is a PCI DSS Scope Analysis?
A PCI DSS Scope Analysis identifies where payment account data is stored, processed or transmitted and determines which systems, networks, people and processes fall within the cardholder data environment. Accurate scoping can help reduce unnecessary compliance complexity and confirm that relevant controls are properly assessed.
What is a PCI DSS Gap Assessment?
A PCI DSS Gap Assessment compares an organization's current security controls against applicable PCI DSS requirements. It identifies areas of non-compliance and provides recommendations to help prioritize remediation before a formal assessment or self-assessment is completed.
What is a PCI DSS formal assessment?
A formal PCI DSS assessment evaluates whether an organization meets the applicable requirements of the standard. Depending on the organization and its validation requirements, this may involve a Qualified Security Assessor completing a Report on Compliance or an eligible organization completing a Self-Assessment Questionnaire.
What is a Qualified Security Assessor (QSA)?
A Qualified Security Assessor, or QSA, is a security professional qualified through the PCI Security Standards Council to assess organizations against PCI DSS requirements. QSAs can support scoping, gap analysis, remediation planning and formal PCI DSS assessments.
What is a Report on Compliance (ROC)?
A Report on Compliance, or ROC, is a detailed assessment report used to document an organization's compliance with PCI DSS. It is typically completed by a Qualified Security Assessor where an assessor-led validation is required.
What is an Attestation of Compliance (AOC)?
An Attestation of Compliance, or AOC, is an official PCI SSC form used to confirm the result of a PCI DSS assessment. The appropriate AOC depends on the type of assessment completed, such as a Report on Compliance or Self-Assessment Questionnaire.
How often does PCI DSS compliance need to be assessed?
PCI DSS compliance is generally validated on a recurring basis, but the exact frequency and assessment method depend on the organization and requirements set by the relevant acquiring bank, payment brand or other compliance-accepting entity. Some security activities, such as vulnerability scanning, may also need to be performed more frequently.
What happens if an organization fails a PCI DSS assessment?
If gaps are identified during an assessment, the organization will normally need to remediate the relevant issues before compliance can be validated. The actions required will depend on the findings, the assessment type and any requirements set by the organization's acquiring bank or payment brand.
How does Integrity360 help with PCI DSS compliance?
Integrity360 conducts gap analyses, vulnerability scans, control testing, policy development and remediation guidance, and works alongside Qualified Security Assessors where an assessor-led validation is required.
