What is PCI DSS?
Also: PCI DSS 4.0, PCI DSS v4.0.1
The Payment Card Industry Data Security Standard, the scheme-mandated framework for handling cardholder data.
The Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards mandated by the card schemes (Visa, Mastercard, American Express, Discover, and JCB) for all entities that store, process, or transmit cardholder data.
Its purpose is to reduce card fraud by enforcing a consistent security framework across the payment ecosystem.
Compliance is validated through annual assessments conducted by Qualified Security Assessors (QSAs) for larger merchants, or through Self-Assessment Questionnaires (SAQs) for smaller entities, with specific reporting levels determined by transaction volume and exposure.
For a merchant, PCI DSS compliance necessitates implementing technical and operational controls across their systems that handle sensitive payment card information, such as point-of-sale terminals or e-commerce platforms.
Non-compliance can lead to significant fines levied by acquirers, which are then passed down from the card schemes, or even the loss of card processing privileges following a data breach.
A common mistake is to assume that outsourcing payment processing entirely absolves a merchant of all PCI DSS responsibilities; while some scope may be reduced, merchants typically retain responsibility for their own network security and the security of their payment application.
Worked example
A merchant reviews a €500 transaction where PCI DSS is the deciding factor. The merchant checks geography, payment type, customer status, and exemption criteria before deciding which compliance treatment applies.
The operational cost is modelled at non-compliance exposure that can exceed the processing margin on the sale, and the relevant action must complete at Checkout or onboarding.
Step 1 is to capture the original request data, including amount, currency, issuer country, MID, and response or status code. Step 2 is to apply the merchant's rule set, for example whether to retry, challenge, refund, release goods, or hold for review.
Step 3 is to reconcile the result against acquirer reporting so finance can see the cash impact. If the rule improves the outcome by even 50 basis points on 2,000 similar monthly transactions, the merchant protects roughly 10 extra orders from avoidable failure or loss.
Scheme notes
This is not wholly scheme-specific, because regulatory obligations come from legislation, regulators, and local payment-system rules rather than Visa or Mastercard alone. Scheme rules still matter operationally because they define message fields, liability allocation, evidence standards, and monitoring consequences.
UK and EEA treatment can diverge after Brexit, and domestic schemes or bank-transfer rails may apply separate rulebooks. Merchants should treat scheme compliance and legal compliance as overlapping controls, not substitutes.
Why it matters for merchants
Commercially, this affects compliance cost, payment acceptance, refund and dispute obligations, and the risk of regulatory or scheme enforcement.
For a merchant processing £500,000 per month, a 25 basis point movement is worth £1,250 before secondary effects such as disputes, reserves, support tickets, or failed delivery costs.
The impact is larger in high-risk, subscription, travel, digital-goods, and cross-border models because issuer decisions and scheme monitoring can compound quickly.
Cardflo can help by combining acquiring access, MID routing, orchestration rules, KYB review, and chargeback tooling where relevant, so the merchant is not dependent on one processor interpretation or one fixed transaction path.
Frequently asked
What are the consequences of non-compliance with PCI DSS?
Failure to maintain compliance can result in substantial monthly fines from the card schemes, often passed down through the acquirer. In the event of a data breach, non-compliant entities may face increased transaction fees, legal liabilities, and the potential revocation of their merchant account (MID).
How does version 4.0 change the compliance landscape for merchants?
PCI DSS v4.0 introduces more stringent requirements around multi-factor authentication (MFA) and more frequent testing of security controls. It also shifts toward a risk-based approach, allowing organisations more flexibility in how they demonstrate they have met specific security objectives through a customised validation approach.
Which data should a merchant store for PCI DSS?
Store the transaction ID, MID, acquirer, amount, currency, issuer country, card scheme, response or status code, timestamp, and any 3DS, exemption, refund, or dispute reference. For card transactions, keep authorisation and Clearing identifiers because settlement or chargeback questions may arrive 30 to 120 days later.
For regulated flows, keep customer consent and evidence records for at least the period required by local law or scheme rules. Good records reduce investigation time from hours to minutes when acquirer reporting does not match the order system.
How often should PCI DSS be reviewed?
High-volume merchants should review exception rates weekly and trend the main metric monthly by scheme, acquirer, issuer country, MCC, and payment method. A movement of 20 to 50 basis points can be material if the merchant processes thousands of orders.
Finance should reconcile the cash impact at settlement level, while risk or payment operations should analyse the root cause. Reviewing only blended totals hides problems that appear on a single BIN range, region, or MID.
What threshold usually triggers action on PCI DSS?
The threshold depends on the category, but merchants should investigate any sudden change above 10% relative movement or 25 basis points absolute movement. For disputes and fraud, scheme thresholds such as 0.9% under Visa monitoring or 1.5% under Mastercard ECM can create immediate escalation risk.
For settlement or pricing items, even 5 to 15 basis points can justify routing or contract review. The key is to set thresholds before month-end, not after a processor invoice or scheme notice arrives.
Can PCI DSS differ between acquirers?
Yes. Acquirers can map response codes differently, apply different risk rules, support different data fields, and settle on different cycles.
One acquirer may return a generic decline while another exposes issuer advice that allows a safe retry. Fee treatment can also vary by contract, especially for cross-border, FX, premium cards, and alternative payment methods.
This is why merchants using orchestration should compare performance by acquirer and scheme rather than relying on a single blended approval or cost figure.
What is the first remediation step when PCI DSS creates losses?
Start with a 30-day sample and split it by scheme, issuer country, card product, payment method, MID, and response or dispute code. Quantify the value at risk in cash terms, not just percentage points.
Then decide whether the fix is operational, such as better evidence or customer communication, technical, such as richer data or 3DS indicators, or commercial, such as a different acquirer route.
Recheck the same metric after one full settlement or dispute cycle to confirm the change worked.
See how PCI DSS plays out in practice
Industries and regions where this term drives real acquiring, routing, or dispute decisions.
Related terms
Replacing sensitive card data with a non-sensitive surrogate value that can be stored and reused without PCI scope.
A PCI DSS compliant store of tokenised card credentials that lets a merchant charge a card again without holding the PAN.
PSD2 requirement that customer-initiated electronic payments in the EEA and UK be authenticated with two of: knowledge, possession, inherence.
Regulated identity-verification of the merchant (KYB) and, where relevant, the merchant's customers (KYC).
Related guides.
Ready to improve your payments setup?
Tell us about your business. We'll match you with the right acquiring partners and the right route, typically inside a week.