← Reference · Home · Print this page
Finance · Payments
PCI DSS (Payment Card Data Security)
Reference entry · last updated 20260910
The Payment Card Industry Data Security Standard (PCI DSS) specifies technical and operational requirements for protecting payment account data. The PCI SSC document library lists version 4.0.1 as the current standard checked on 20260910.[1][2]
1. First principles: the data environment
Scope includes organizations that store, process, or transmit cardholder or sensitive authentication data, and those that can affect the security of the cardholder data environment. Outsourcing a payment function or implementing payment tokenization changes which systems handle the data; the remaining responsibilities still require assessment.[1]
2. Self-assessment eligibility
A self-assessment questionnaire (SAQ) applies to a defined payment environment. SAQ selection requires meeting all eligibility criteria. Hosted fields or an iframe alone do not establish SAQ A eligibility.[3]
3. Embedded payment forms
For embedded third-party payment forms, SAQ A requires merchants to confirm that their site is not susceptible to script attacks affecting their e-commerce systems. That specific criterion does not apply to redirect-based or fully outsourced payment flows. The FAQ explicitly leaves other eligibility criteria in force.[3]
4. Validation responsibility
Payment brands, acquirers, or other organizations that manage compliance programs determine validation requirements. The applicable questionnaire and evidence depend on the actual integration and program.[1]
5. See also
- Online Payments
- Payment Tokenization
- Payment Gateway
- Payment Service Providers (Merchant Payments)
- EMV 3-D Secure (Online Card Authentication)