
Whatever the size of your business, you must ensure that it is compliant with the Payment Card Industry Data Security Standard (PCI DSS) and that your compliance practices are validated yearly.
The PCI standards are at the core of the global payment system, so putting those in place is crucial for your organisation. To help you achieve regulatory compliance, let’s explore what PCI compliance is and what key requirements you need to match.
What is PCI Compliance?
Developed by the PCI Standards Council (SSC) it is applied and enforced by payment card companies to maintain the security and integrity of card transactions. Generally speaking, the term compliance is relevant to both the technical and overall operational standards that every business must follow in order to protect a cardholder’s credit card data when processing transactions.
Who is Affected by PSI DSS?
Absolutely any business, company or organisation – regardless of size – that accepts, processes, stores or transmits cardholder data and information falls under the jurisdiction of PCI DSS.
PCI SSC Data Security Standards – An Overview
The PCI Security Standards Council detail necessary guidelines, tools and frameworks as well as support materials to ensure that companies maintain around-the-clock security of cardholder information. A key objective of the PCI DSS is the development of security protocols that protect payment card data by way of prevention, detection and reaction to any breaches in security.
12 PCI DDS Compliance Requirements You Must Implement
According to the PCI Compliance Standards, there are 12 crucial requirements you must complete to protect the cardholder data of your paying customers. They are:
- Install/maintain firewalls to protect cardholder data
- Never use the default, out-of-box passwords for systems and other security parameters
- Ensure constant protection of stored cardholder data
- Encrypt all transmissions of cardholder data across any public networks
- Use, maintain and regularly update security software such as anti-virus or malware programs
- Develop/maintain secure systems, platforms and applications
- Ensure restriction on access to cardholder data by need-to-know criteria
- Create and assign unique IDs to all persons with computer and systems access
- Restrict physical access to cardholder data
- Track/monitor access to cardholder data and network resources
- Test security systems and processes on a regular basis
- Maintain a policy that prioritises information security and document all hardware, software and staff with access
The 12 PCI Requirements – In Depth
Now that we have an overview of the PCI DSS requirements, let’s take a more in-depth look at the steps you need to take to protect credit card data and achieve compliance with the industry standards.
- Install/Maintain Firewalls to Protect Cardholder Data
Your company should install strong firewall protection, as they serve to block access to your network and data from unknown entities – such as malicious actors – who have no legitimate reason to access your network.
As the first line of defence, firewalls are required under the compliance guidelines as they are effective in preventing unauthorised access and actors of bad faith, such as hackers.
- Never Use Default, Out-of-Box Passwords for Systems and Other Security Parameters
Proper password etiquette and good practise should be implemented, in other words, default passwords should be immediately replaced, especially in a business that processes card payment information. All password-protected systems, both hardware and software, should have strong passwords and those should be updated regularly.
Compliance in this area is simple: keep an up-to-date list of software and devices which require passwords – such as routers and POS systems – and schedule regular password refresh dates and procedures.
- Ensure Constant Protection of Stored Cardholder Data
The PCI DSS compliance protocol also stipulated that cardholder data must be kept protected at all times and encrypted by certain algorithms, requiring encryption keys.
To be compliant, you must also undergo regular maintenance of your systems, as well as perform primary account number (PAN) scans to confirm that no unencrypted data remains.
- Encrypt All Transmissions of Cardholder Data Across Public Networks
If cardholder data is to be sent across ordinary channels, said data must be encrypted, even if sent to known addresses, with customer account numbers never being sent to unknown locations.
- Use, Maintain and Regularly Update Security Software
To maintain compliance, it is essential that you use advanced cybersecurity protection, including anti-virus software across all devices that communicate with and/or store primary account numbers. You should also keep an eye on upcoming software updates and ensure they are implemented as soon as the rollouts are released.
- Develop/Maintain Secure Systems, Platforms and Applications
Updates are important for all software on systems that interact with cardholder data, not just your security software. Every relevant system across the business must also be updated regularly, as vulnerabilities are constantly discovered and patched in new releases. Delaying the updates means that your customers’ payment data is potentially exposed to attacks by malicious actors.
- Ensure Restriction on Access to Cardholder Data by Need-to-Know Criteria
Cardholder data is sensitive information, and access to said data should be on a need-to-know basis only. Any party who has no need to access such information should not have access, this includes staff and third parties.
All genuine parties who require such data as a function of their employment/role should have the proper documentation noted and updated regularly.
- Create and Assign Unique IDs to All Persons with Computer and Systems Access
All employees would have unique IDs for access to company systems, including those members who do require access to cardholder data.
- Restrict Physical Access to Cardholder Data
All cardholder data is to be stored in physical form and kept in a secure location. All data – whether physically written/typed or digital (and kept on physical storage) – is to be locked within a secure holding. Access to this location should be severely restricted and if the data is accessed, a log should be maintained to ensure compliance.
- Track/Monitor Access to Cardholder Data and Network Resources
Any activity involving primary account numbers and/or cardholder data must be logged. Improper record-keeping is one of the easiest compliance breaches to fall foul of, simply due to time and budget constraints or poor training. Modern software systems can simplify this process significantly and also increase accuracy.
- Test Security Systems and Processes on a Regular Basis
Hardware and software can break down, malfunction or become obsolete over time, or simply fall short of performance expectations. Such instances can be limited via regular testing, maintenance and systems scans.
- Maintain a Policy that Prioritises Information Security
All hardware, software and employees that have access to your systems will need to be documented for your company to demonstrate compliance. Accurate logging of access to cardholder data should also be documented.
Ways in which sensitive information moves throughout the company, its storage locations and how said data is used and processed after the point of the transaction should be documented, also.
The Benefits of Complying with PCI
In an interconnected world, security compliance is becoming increasingly important. However big or small your company is, you must ensure that you are complying with PCI – regardless of how much of a task that may appear.
PCI SSC has made clear that there are a number of tangible benefits of complying with PCI, particularly in comparison to the negative, long-term consequences of failing to comply. Some of the benefits are:
- Improves company reputation with payment brands – necessary for any business that wishes to grow
- Complying with PCI means you are more likely to comply with other compliance regulations
- PCI compliance can lead to innovations of your internal IT infrastructure
- Peace of mind that your systems are secure
- Customers know that they can trust your company with their sensitive information, whilst you are aware that you have consumer confidence in your brand
- Contribute to the learning and overall development of PCI standards
Failure and Non-Compliance of PCI – The Difficulties
Failing to comply with PCI can result in catastrophic consequences for your business, customers and the industry as a whole. You should not take for granted your position in the market and customer confidence by failing to ensure your compliance with PCI.
Some outcomes resulting from non-compliance with PCI include:
- Damage to your company reputation and loss of business
- The tangible threat of lawsuits, fines, insurance claims and government intervention
- Markable loss of sales, business relationships, marketplace presence, market share as well as loss of share price, if publicly traded
- Financial impacts on your customers, partners and financial bodies
FAQ
What is PCI Compliance?
The Payment Card Industry Data Security Standard (PCI DSS), which was established in 2006, was created by a collection of the major payment card brands (including MasterCard, Visa and American Express).
A business that processes, stores or transmits any payment card data is required to comply with PCI and implement any necessary frameworks and safeguards to prevent the theft of cardholder data. Your internal (and external) practices and processing of card payments will determine the specific PCI DSS which apply to your business.
When was PCI compliance introduced?
PCI guidelines were first introduced and mandated back in 2006 to ensure that merchants do their best to safeguard all sensitive information and data relating to payment.
What if I only process a few card payments a year? Do I still need to be PCI compliant?
Yes, absolutely. There is no minimum threshold of card transactions required for your business to fall under PCI, therefore you must implement PCI DSS like any other business.
Who needs to be PCI compliant?
Any business that processes, transmits or stores payment card information is required to comply with PCI DSS.
Am I required to be PCI compliant by law?
No, the UK government does not regulate PCI. Be aware that when signing the contract with your payment card service provider, you agreed to follow their terms and conditions, therefore agreeing to comply with PCI DSS.
Who created the PCI?
The PCI was initially founded by Visa, MasterCard, American Express, JCB International and Discovery Financial Services.
Whether you require advice on PCI compliance, card terminal systems, card payment systems, point-of-sale systems or any other retail payment systems, AptPay is a call away.

