Menu

Last updated: August 2026

PCI-DSS Standard

PCI-DSS (Payment Card Industry Data Security Standard) is a mandatory set of security requirements for any organization that processes, stores, or transmits credit card data, enforced by Visa, Mastercard, and the other major card brands.

The 12 requirements

PCI-DSS organizes its requirements into six control objectives:

  • Build and maintain a secure network — firewalls, no vendor-default passwords
  • Protect cardholder data — encryption at rest and in transit, restricted storage
  • Maintain a vulnerability management program — antivirus, secure software development
  • Implement strong access control — restrict data access by business need-to-know, unique IDs, physical access restrictions
  • Regularly monitor and test networks — track and monitor all access, regular security testing
  • Maintain an information security policy — documented, enforced organization-wide policy

Compliance levels

LevelTransaction volumeRequirement
Level 16M+ transactions/yearAnnual on-site audit by a Qualified Security Assessor (QSA)
Level 21M–6M transactions/yearAnnual self-assessment questionnaire (SAQ)
Level 320K–1M transactions/yearAnnual SAQ, quarterly network scan
Level 4Under 20K transactions/yearAnnual SAQ (requirements vary by acquiring bank)

Why it matters for fintech development

Any application handling card payments must be built to PCI-DSS standards from day one — retrofitting compliance after launch is expensive and risky. Code Ninety builds fintech and payment systems to PCI-DSS standards as a baseline architectural requirement, not an afterthought bolted on before a compliance audit.

Working with Code Ninety

Code Ninety handles cloud modernization for financial services compliance under PCI-DSS controls. See the payment platform case study for a PCI-DSS regulated build.

Related terms