Frameworks
PCI DSS — Payment Card Industry Data Security Standard
Twelve requirements, four levels, zero tolerance for stored card data mistakes.
Book a demoTouch cardholder data and PCI DSS applies — not as law, but as contract, enforced by the card brands through your acquirer with fines and, ultimately, the ability to stop you taking cards. Version 4.0 is now the operative standard, and its future-dated requirements are live.
Scope is the whole game
PCI compliance cost tracks the size of your cardholder data environment. The winning move is shrinking it: tokenization, hosted payment fields, and never storing PAN yourself can drop you to the shortest self-assessment questionnaires. The worst move is discovering card numbers in logs during an audit.
What v4.0 changed
Version 4.0 added a customized approach for meeting requirements, stronger multi-factor and password rules, targeted risk analyses, and e-commerce protections like payment-page script integrity monitoring. Requirements that were 'best practice until March 2025' are now mandatory.
How Compriska helps
Compriska tracks your twelve requirements as owned, evidenced controls, schedules quarterly obligations like scans and reviews, keeps your SAQ evidence organized, and cross-maps the substantial overlap with SOC 2 and ISO 27001 so nothing is done twice.
Frequently asked questions
Which SAQ level applies to us?
It depends on transaction volume and how card data flows through your systems. Fully outsourced payment flows (e.g., hosted checkout) qualify for the shortest SAQs — one of many reasons to keep card data out of your environment entirely.
Other frameworks
Automate PCI DSS with Compriska
See how cross-mapped controls, continuous evidence, and AI workflows change the cost of compliance.
Book a demo