Skip to main content

PCI-DSS Compliance

Last Updated: 2025-02-17 Status: Complete

The Payment Card Industry Data Security Standard (PCI-DSS) establishes requirements for protecting cardholder data. For PayFac platforms, PCI compliance is mandatory—typically at the most stringent Level 1 Service Provider requirements.

Quick Reference

ItemStatus (2026)
Current VersionPCI DSS v4.0.1
Future-Dated RequirementsAll mandatory (March 31, 2025)
Level 1 Service Provider> 300,000 transactions/year
Level 1 Merchant> 6 million transactions/year
All v4.0 Requirements Now Mandatory

As of March 31, 2025, all 51 "future-dated" requirements in PCI DSS v4.0 became mandatory. Organizations must be fully compliant with all v4.0.1 requirements.

What is PCI-DSS?

PCI-DSS is a security standard created by the Payment Card Industry Security Standards Council (PCI SSC), founded by Visa, Mastercard, American Express, Discover, and JCB.

Why PayFacs Are Level 1

PayFac platforms are typically classified as Level 1 Service Providers because:

FactorImpact
Transaction volumeUsually > 300,000/year
Data handlingProcess/transmit cardholder data
Sub-merchant responsibilityManage multiple merchants
Risk profileHigh-value target for attackers

Section Contents

Requirements

  • The 12 PCI-DSS requirements overview
  • Key v4.0 changes
  • Service provider-specific requirements

Scope Management

  • Cardholder Data Environment (CDE)
  • Scope reduction strategies
  • Network segmentation

Tokenization

  • Token strategies
  • Point-to-Point Encryption (P2PE)
  • Scope reduction through tokenization

Quiz

  • Self-assessment questions

Compliance Levels

Merchant Levels

LevelAnnual TransactionsValidation
1> 6 millionAnnual ROC by QSA, quarterly ASV scans
21-6 millionAnnual SAQ, quarterly ASV scans
320,000-1 million (e-commerce)Annual SAQ, quarterly ASV scans
4< 20,000 e-commerce OR < 1 millionAnnual SAQ, quarterly ASV scans
Automatic Level 1

Any merchant that has experienced a data breach automatically becomes Level 1 regardless of transaction volume.

Service Provider Levels

LevelAnnual TransactionsValidation
1> 300,000Annual ROC by QSA, quarterly ASV scans
2< 300,000Annual SAQ D-SP, quarterly ASV scans

Key Compliance Documents

DocumentPurposeWho Provides
ROCReport on Compliance - detailed assessmentQSA
AOCAttestation of Compliance - summaryQSA or organization
SAQSelf-Assessment QuestionnaireOrganization
ASV ReportVulnerability scan resultsASV

The 12 PCI-DSS Requirements

#RequirementCategory
1Install and maintain network security controlsBuild secure network
2Apply secure configurations to all system componentsBuild secure network
3Protect stored account dataProtect cardholder data
4Protect cardholder data with strong cryptographyProtect cardholder data
5Protect all systems against malwareMaintain vulnerability program
6Develop and maintain secure systemsMaintain vulnerability program
7Restrict access to cardholder data by business needStrong access control
8Identify users and authenticate accessStrong access control
9Restrict physical access to cardholder dataStrong access control
10Log and monitor all access to system componentsMonitor and test networks
11Test security of systems and networks regularlyMonitor and test networks
12Support information security with policiesMaintain security policy

Key v4.0 Changes (Now Mandatory)

RequirementChangeImpact
8.3.6Password minimum 12 charactersUpdate password policies
8.4.2MFA for ALL CDE accessNot just admin access
6.4.3Web page scripts inventoryTrack all JavaScript
11.6.1Detect script tamperingMonitor for changes
12.3.1Targeted risk analysisCustom security frequencies

PayFac PCI Responsibilities

Sub-Merchant Compliance Monitoring

RequirementImplementation
SAQ completionAnnual attestation required
Compliance statusTrack in merchant database
Non-complianceRemediation timeline or termination
TrainingSecurity awareness materials

Scope Reduction Strategy

Reducing PCI scope lowers compliance burden and risk:

Learn more: Scope Management

Compliance Timeline

Annual Requirements

FrequencyActivity
QuarterlyASV vulnerability scans
QuarterlyInternal vulnerability scans
AnnuallyPenetration testing
AnnuallyROC assessment (Level 1)
AnnuallyPolicy review and update
AnnuallySecurity awareness training

Key Dates

DateEvent
March 31, 2024v3.2.1 retired, v4.0 mandatory (with future-dated requirements optional)
June 2024v4.0.1 released (minor clarifications)
March 31, 2025All v4.0 future-dated requirements NOW MANDATORY
Current Status (2026)

All PCI DSS v4.0.1 requirements are now mandatory. The future-dated requirements (e.g., 6.4.3 script management, 11.6.1 change detection) that were optional until March 2025 are now required for all assessments.

Ecosystem Context:

References

Share: