{"id":1136,"date":"2026-09-10T08:31:09","date_gmt":"2026-09-10T08:31:09","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1136"},"modified":"2026-09-10T08:31:09","modified_gmt":"2026-09-10T08:31:09","slug":"pci-dss","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/pci-dss\/","title":{"rendered":"PCI DSS"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: PCI DSS\n     Live osto.one glossary stylesheet. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">PCI DSS is the security standard that applies the moment your business touches payment card data, enforced by the card brands and your acquiring bank rather than by any law.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Compliance<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>PCI DSS is the Payment Card Industry Data Security Standard: twelve requirements covering how cardholder data is stored, transmitted and protected. How you validate depends on transaction volume, from a self-assessment questionnaire at the low end to an on-site assessment by a qualified assessor at the high end. Version 4.0.1 is the only active version, and every requirement in it has been mandatory since 31 March 2025.<\/p>\n<\/div>\n\n<p>The single most useful thing to understand early is that PCI DSS scope drives cost. What determines your effort is not the twelve requirements themselves but how much of your infrastructure sits inside the cardholder data environment.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#twelve\">The twelve PCI DSS requirements<\/a><\/li>\n    <li><a href=\"#v4\">What changed in PCI DSS version 4.x<\/a><\/li>\n    <li><a href=\"#levels\">Which PCI DSS level applies<\/a><\/li>\n    <li><a href=\"#scope\">PCI DSS scope is most of the work<\/a><\/li>\n    <li><a href=\"#osto\">How Osto maps PCI DSS controls<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"twelve\">The twelve PCI DSS requirements<\/h2>\n\n<p>The twelve PCI DSS requirements group into six goals. The grouping matters more than the numbering, because it shows where the work concentrates.<\/p>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Goal<\/th><th>Requirements<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Build and maintain a secure network<\/td><td>1. Network security controls &middot; 2. Secure configurations, no vendor defaults<\/td><\/tr>\n    <tr><td>Protect account data<\/td><td>3. Protect stored data &middot; 4. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/encryption-at-rest\/\">Encrypt<\/a> transmission across open networks<\/td><\/tr>\n    <tr><td>Maintain a vulnerability management programme<\/td><td>5. Protect against malicious software &middot; 6. Develop and maintain secure systems<\/td><\/tr>\n    <tr><td>Implement strong access control<\/td><td>7. Restrict access by business need &middot; 8. Identify users and authenticate access &middot; 9. Restrict physical access<\/td><\/tr>\n    <tr><td>Monitor and test networks<\/td><td>10. Log and monitor all access &middot; 11. Test security regularly<\/td><\/tr>\n    <tr><td>Maintain an information security policy<\/td><td>12. Support the programme with organisational policies<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>Requirement 8 is where <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iam\/\">identity and access management<\/a> lands, requirement 10 is <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">logging and monitoring<\/a>, and requirement 11 pulls in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-scanning\/\">scanning<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/penetration-testing\/\">penetration testing<\/a>. Requirement 12 is the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/grc\/\">governance<\/a> layer, including a tested <a href=\"https:\/\/www.osto.one\/resources\/glossary\/incident-response\/\">incident response<\/a> plan.<\/p>\n\n<h2 id=\"v4\" class=\"c-sage\">What changed in PCI DSS version 4.x<\/h2>\n\n<p>PCI DSS version 4.0 introduced 64 new or updated requirements. Thirteen applied immediately. The remaining 51 were designated future-dated best practices and became mandatory on 31 March 2025, which means any assessment from that date scores all of them as fully in scope with no grace period.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Change<\/th><th>What it means in practice<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">MFA<\/a> for all CDE access<\/td><td>Requirement 8.4.2 extends multi-factor authentication beyond administrators and remote users to every account entering the cardholder data environment<\/td><\/tr>\n    <tr><td>Payment page script inventory<\/td><td>Requirement 6.4.3 asks for an authorised inventory of every script running on a payment page, which fails on governance gaps more often than on technology<\/td><\/tr>\n    <tr><td>Payment page tamper detection<\/td><td>Requirement 11.6.1 requires detection of unauthorised changes to payment pages, aimed squarely at skimming attacks<\/td><\/tr>\n    <tr><td>Authenticated internal scanning<\/td><td>Internal <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-scanning\/\">vulnerability scans<\/a> must now run with credentials rather than unauthenticated<\/td><\/tr>\n    <tr><td>Targeted risk analysis<\/td><td>Several requirements let you set your own frequency, provided a documented risk analysis justifies it<\/td><\/tr>\n    <tr><td>Customised approach<\/td><td>You may meet a requirement&#8217;s objective with a different control, if you can evidence that it achieves the same outcome<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Check which version your last assessment used<\/p>\n  <p>PCI DSS 3.2.1 retired on 31 March 2024 and 4.0 retired on 31 December 2024, leaving 4.0.1 as the only active version. An organisation that validated in 2024 and treated the future-dated items as optional will fail its next assessment unless those controls are now in place. A successor version is in development, with no release date announced.<\/p>\n<\/div>\n\n<h2 id=\"levels\" class=\"c-sky\">Which PCI DSS level applies<\/h2>\n\n<p>PCI DSS levels are set by annual transaction volume per card brand, and the thresholds vary slightly between brands. The pattern below is the common shape.<\/p>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Level<\/th><th>Rough volume<\/th><th>How you validate<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Level 1<\/td><td>Over 6 million transactions a year<\/td><td>Annual Report on Compliance by a qualified security assessor, plus quarterly external scans by an approved vendor<\/td><\/tr>\n    <tr><td>Level 2<\/td><td>1 to 6 million<\/td><td>Self-assessment questionnaire, sometimes an assessor depending on the brand and acquirer<\/td><\/tr>\n    <tr><td>Level 3<\/td><td>20,000 to 1 million e-commerce<\/td><td>Self-assessment questionnaire plus quarterly external scans<\/td><\/tr>\n    <tr><td>Level 4<\/td><td>Below the level 3 thresholds<\/td><td>Self-assessment questionnaire, with requirements set by the acquirer<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>Which questionnaire you complete depends on how payments are handled. A merchant that fully outsources card entry to a hosted page answers far fewer questions than one that touches card data directly. Your acquirer confirms both the level and the questionnaire type, so ask them before assuming.<\/p>\n\n<h2 id=\"scope\" class=\"c-plum\">PCI DSS scope is most of the work<\/h2>\n\n<p>The PCI DSS cardholder data environment covers every system that stores, processes or transmits card data, plus anything connected to it that could affect its security. Shrinking that boundary is the highest-leverage decision available.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 190\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"How PCI DSS scope shrinks when card data never reaches your servers.\">\n  <rect x=\"12\" y=\"26\" width=\"356\" height=\"118\" rx=\"16\" fill=\"#f8f3f9\" stroke=\"#dcc6e2\" stroke-width=\"2\"\/>\n  <text x=\"190\" y=\"50\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#6b4576\">Card data touches your systems<\/text>\n  <rect x=\"30\" y=\"62\" width=\"150\" height=\"30\" rx=\"9\" fill=\"#dcc6e2\"\/>\n  <text x=\"105\" y=\"82\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Web servers<\/text>\n  <rect x=\"200\" y=\"62\" width=\"150\" height=\"30\" rx=\"9\" fill=\"#dcc6e2\"\/>\n  <text x=\"275\" y=\"82\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Application layer<\/text>\n  <rect x=\"30\" y=\"100\" width=\"150\" height=\"30\" rx=\"9\" fill=\"#dcc6e2\"\/>\n  <text x=\"105\" y=\"120\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Databases<\/text>\n  <rect x=\"200\" y=\"100\" width=\"150\" height=\"30\" rx=\"9\" fill=\"#dcc6e2\"\/>\n  <text x=\"275\" y=\"120\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Backups and logs<\/text>\n\n  <rect x=\"392\" y=\"26\" width=\"356\" height=\"118\" rx=\"16\" fill=\"#f2f8f5\" stroke=\"#c3ddce\" stroke-width=\"2\"\/>\n  <text x=\"570\" y=\"50\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#3a6f5d\">Hosted page and tokenisation<\/text>\n  <rect x=\"410\" y=\"62\" width=\"150\" height=\"30\" rx=\"9\" fill=\"#1c267a\"\/>\n  <text x=\"485\" y=\"82\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#ffffff\">Payment page<\/text>\n  <rect x=\"580\" y=\"62\" width=\"150\" height=\"30\" rx=\"9\" fill=\"#e3f0e9\"\/>\n  <text x=\"655\" y=\"82\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Out of scope<\/text>\n  <rect x=\"410\" y=\"100\" width=\"150\" height=\"30\" rx=\"9\" fill=\"#e3f0e9\"\/>\n  <text x=\"485\" y=\"120\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Out of scope<\/text>\n  <rect x=\"580\" y=\"100\" width=\"150\" height=\"30\" rx=\"9\" fill=\"#e3f0e9\"\/>\n  <text x=\"655\" y=\"120\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Out of scope<\/text>\n\n  <rect x=\"12\" y=\"152\" width=\"736\" height=\"32\" rx=\"11\" fill=\"#fbe9dc\"\/>\n  <text x=\"380\" y=\"173\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#a2603a\">The payment page stays in scope either way. Requirements 6.4.3 and 11.6.1 follow the page, not the card field.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>Technique<\/th><th>Effect on scope<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Hosted payment page or redirect<\/td><td>Card data never reaches your servers, which cuts scope more than any control you could deploy<\/td><\/tr>\n    <tr><td>Tokenisation<\/td><td>A token replaces the card number in your systems, so downstream databases fall out of scope<\/td><\/tr>\n    <tr><td>Point-to-point encryption<\/td><td>Card data is encrypted at the terminal, so intermediate systems cannot read it<\/td><\/tr>\n    <tr><td>Network segmentation<\/td><td>Isolates the environment so the rest of the estate is not dragged in<\/td><\/tr>\n    <tr><td>Storing card numbers<\/td><td>Expands scope sharply and is rarely necessary once tokenisation is in place<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>Note that outsourcing card capture reduces your scope without removing it. Payment page script controls still apply, because the page your customer sees is served by you even when the card field is not.<\/p>\n\n<h2 id=\"osto\">How Osto maps PCI DSS controls<\/h2>\n\n<p>PCI DSS overlaps heavily with what you already need for <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a>. Access control, logging, vulnerability management, secure configuration and incident response appear in all three, worded differently. Osto runs those controls once and maps the evidence across 200 or more frameworks, so the second and third standard cost a fraction of the first.<\/p>\n\n<p>On the technical side, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">web and API protection<\/a> covers requirement 6.6, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a> and scheduled scanning cover requirement 11, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">correlated logging<\/a> covers requirement 10, and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">MFA<\/a> enforced at the access gate covers the expanded requirement 8.4.2. Osto is not a qualified security assessor and does not issue a Report on Compliance. What it does is remove the gap between having a control and being able to prove it ran.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Platform walkthrough<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">One control set, every framework<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Access, logging, scanning and web protection run in one platform and map across 200 or more frameworks. Prove the same control to a card brand, an auditor and an enterprise buyer.<\/p>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 32px;border-radius:12px;margin:0;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Book a demo<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:18px 0 0;\">200+ frameworks mapped &middot; Evidence from your own stack &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is PCI DSS?<\/summary>\n  <p>The Payment Card Industry Data Security Standard: twelve requirements governing how organisations that store, process or transmit payment card data must protect it. It is maintained by the PCI Security Standards Council and enforced contractually by the card brands and acquiring banks.<\/p>\n<\/details>\n\n<details>\n  <summary>Is PCI DSS a legal requirement?<\/summary>\n  <p>Not in most jurisdictions. It is a contractual obligation that arrives through your merchant agreement or payment processor. The practical consequences of non-compliance are fines passed down by the acquirer, higher transaction costs, and liability after a breach.<\/p>\n<\/details>\n\n<details>\n  <summary>Which version of PCI DSS is current?<\/summary>\n  <p>Version 4.0.1. Version 3.2.1 retired on 31 March 2024 and version 4.0 retired on 31 December 2024. Every requirement in 4.0.1, including the 51 that were originally future-dated, has been mandatory since 31 March 2025.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the cardholder data environment?<\/summary>\n  <p>Every system that stores, processes or transmits cardholder data, along with any connected system that could affect its security. Defining and shrinking this boundary is the main lever on cost, because everything inside it must meet all applicable requirements.<\/p>\n<\/details>\n\n<details>\n  <summary>Does using a payment provider make us compliant?<\/summary>\n  <p>It reduces your PCI DSS obligations substantially but does not remove them. You still complete a self-assessment questionnaire, and the payment page script and tamper detection requirements can still apply, because the page is served by you even when the card field belongs to the provider.<\/p>\n<\/details>\n\n<details>\n  <summary>How does PCI DSS relate to SOC 2 and ISO 27001?<\/summary>\n  <p>They overlap heavily. PCI DSS, SOC 2 and ISO 27001 all cover access control, logging, vulnerability management and incident response, worded differently in each. Teams that map one control set across frameworks rather than running three separate programmes save most of the duplicated effort.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/grc\/\">GRC<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iam\/\">IAM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">MFA<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/incident-response\/\">Incident Response<\/a><\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>PCI DSS is the security standard that applies the moment your business touches payment card data, enforced by the card\u2026<\/p>\n","protected":false},"author":8,"featured_media":1137,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[143,540,539],"class_list":["post-1136","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-pci-dss","tag-pci-dss-4-0","tag-pci-dss-requirements"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1136","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1136"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1136\/revisions"}],"predecessor-version":[{"id":1138,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1136\/revisions\/1138"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1137"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1136"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1136"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1136"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}