← New search

Other meanings of PCI Security Standards Council

Payment Security

PCI Security Standards Council

The PCI Security Standards Council (PCI SSC) is a global, independent body that develops and manages the Payment Card Industry Data Security Standard (PCI DSS), along with other standards for payment card security. Founded in 2006 by American Express, Discover, JCB, Mastercard, and Visa, the council defines technical and operational requirements to protect cardholder data and reduce fraud. Its work influences how merchants, financial institutions, and service providers secure payment transactions worldwide.

2006
Founded
Year the council was established
5
Founding brands
American Express, Discover, JCB, Mastercard, Visa
12
PCI DSS requirements
Core security requirements in the current standard
4.0
Latest PCI DSS version
Released in March 2022
1

History and governance

The PCI Security Standards Council was formed in 2006 to consolidate the fragmented security programs of the major card brands. Before its creation, Visa and Mastercard each ran separate data-security initiatives, creating confusion for merchants. The council's founding members—American Express, Discover, JCB, Mastercard, and Visa—remain its executive committee, but the organization operates independently, with a board of advisors elected from participating organizations.

The council's governance includes a Participating Organization program, allowing merchants, banks, and vendors to contribute to standard development. This multi-stakeholder approach ensures the standards reflect industry realities. The council also works with Qualified Security Assessors (QSAs) and Approved Scanning Vendors (ASVs) to validate compliance.

2

Core standards and frameworks

The council's flagship standard is the PCI Data Security Standard (PCI DSS), which outlines 12 requirements for securing cardholder data, including network security, encryption, access control, and monitoring. The current version, 4.0, introduced a more flexible approach to authentication and continuous compliance. Beyond PCI DSS, the council manages the PIN Transaction Security (PTS) standard for payment terminals and the Payment Application Data Security Standard (PA-DSS) for software vendors.

These standards are updated through a formal revision process that includes public comment periods and industry feedback. The council also publishes supplementary guidance on topics like tokenization, point-to-point encryption, and secure software development.

3

Compliance and validation

Compliance with PCI DSS is not a one-time event but an ongoing process. Merchants and service providers must assess their environments annually, using either self-assessment questionnaires (SAQs) for smaller entities or on-site audits by QSAs for larger ones. The council certifies these assessors, ensuring they have the expertise to evaluate security controls.

Non-compliance can lead to fines, increased transaction fees, or even the loss of the ability to accept card payments. However, the council itself does not enforce compliance; each card brand manages its own compliance programs. The council's role is to provide the standards and training, while the brands handle penalties and remediation.

4

Lesser-known aspects

Beyond the well-known PCI DSS, the council has developed specialized standards for emerging technologies. For instance, the Software Security Framework (SSF) replaces PA-DSS for modern software development, focusing on secure coding practices rather than specific applications. The council also issues guidance on securing contactless payments and mobile wallets, areas that are often overlooked.

Another niche area is the council's Qualified Integrator and Reseller (QIR) program, which certifies individuals who install and configure payment systems. This ensures that even the deployment phase is secure. The council also maintains a list of validated payment applications and PIN transaction devices, helping businesses choose compliant products.

Glossary

PCI DSS
Payment Card Industry Data Security Standard, a set of security requirements for protecting cardholder data.
QSA
Qualified Security Assessor, an organization certified by the PCI SSC to audit compliance.
SAQ
Self-Assessment Questionnaire, a validation tool for smaller merchants.
PTS
PIN Transaction Security, a standard for payment terminals.
PA-DSS
Payment Application Data Security Standard, a former standard for payment applications.

The PCI Security Standards Council is a separate entity from the PCI Security Standards Council LLC, which is the legal name of the organization.