Frameworks

PCI DSS — Payment Card Industry Data Security Standard

Twelve requirements, four levels, zero tolerance for stored card data mistakes.

Book a demo

Touch cardholder data and PCI DSS applies — not as law, but as contract, enforced by the card brands through your acquirer with fines and, ultimately, the ability to stop you taking cards. Version 4.0 is now the operative standard, and its future-dated requirements are live.

Scope is the whole game

PCI compliance cost tracks the size of your cardholder data environment. The winning move is shrinking it: tokenization, hosted payment fields, and never storing PAN yourself can drop you to the shortest self-assessment questionnaires. The worst move is discovering card numbers in logs during an audit.

What v4.0 changed

Version 4.0 added a customized approach for meeting requirements, stronger multi-factor and password rules, targeted risk analyses, and e-commerce protections like payment-page script integrity monitoring. Requirements that were 'best practice until March 2025' are now mandatory.

How Compriska helps

Compriska tracks your twelve requirements as owned, evidenced controls, schedules quarterly obligations like scans and reviews, keeps your SAQ evidence organized, and cross-maps the substantial overlap with SOC 2 and ISO 27001 so nothing is done twice.

Frequently asked questions

Which SAQ level applies to us?

It depends on transaction volume and how card data flows through your systems. Fully outsourced payment flows (e.g., hosted checkout) qualify for the shortest SAQs — one of many reasons to keep card data out of your environment entirely.

Other frameworks

Automate PCI DSS with Compriska

See how cross-mapped controls, continuous evidence, and AI workflows change the cost of compliance.

Book a demo