← Reference · Home · Print this page

Finance · Payments

PCI DSS (Payment Card Data Security)

Reference entry · last updated 20260910

The Payment Card Industry Data Security Standard (PCI DSS) specifies technical and operational requirements for protecting payment account data. The PCI SSC document library lists version 4.0.1 as the current standard checked on 20260910.[1][2]

1. First principles: the data environment

Scope includes organizations that store, process, or transmit cardholder or sensitive authentication data, and those that can affect the security of the cardholder data environment. Outsourcing a payment function or implementing payment tokenization changes which systems handle the data; the remaining responsibilities still require assessment.[1]

2. Self-assessment eligibility

A self-assessment questionnaire (SAQ) applies to a defined payment environment. SAQ selection requires meeting all eligibility criteria. Hosted fields or an iframe alone do not establish SAQ A eligibility.[3]

3. Embedded payment forms

For embedded third-party payment forms, SAQ A requires merchants to confirm that their site is not susceptible to script attacks affecting their e-commerce systems. That specific criterion does not apply to redirect-based or fully outsourced payment flows. The FAQ explicitly leaves other eligibility criteria in force.[3]

4. Validation responsibility

Payment brands, acquirers, or other organizations that manage compliance programs determine validation requirements. The applicable questionnaire and evidence depend on the actual integration and program.[1]

5. See also

6. References

  1. PCI SSC. PCI Data Security Standard.
  2. PCI SSC. Document library: PCI DSS v4.0.1.
  3. PCI SSC. FAQ 1588: SAQ A eligibility criteria for scripts.