home / guides / pci-dss

Sector and contracting · PCI Security Standards Council

PCI DSS for card payments

The industry security standard for any organization that stores, processes, or transmits payment card data.

Who this applies to

Merchants and service providers that accept or handle payment cards.

What to know

  • The standard is set by the PCI Security Standards Council. Card brands and acquiring banks enforce it through your merchant agreement.
  • Your validation path depends on how you take payments and how many transactions you process.
  • Reducing scope is the best control. Using a hosted payment page or tokenization keeps card data out of your systems.

What to do

  • Map exactly where card data enters, moves, and rests in your environment.
  • Reduce scope before you try to meet every requirement.
  • Ask your acquiring bank which validation path applies to you.

Sources

Reviewed October 2026.