{"id":10298,"date":"2025-08-06T17:39:48","date_gmt":"2025-08-06T15:39:48","guid":{"rendered":"https:\/\/paynopain.com\/glosario\/pci-dss\/"},"modified":"2026-01-27T13:20:08","modified_gmt":"2026-01-27T12:20:08","slug":"pci-dss","status":"publish","type":"glosario","link":"https:\/\/paynopain.com\/en\/glossary\/pci-dss\/","title":{"rendered":"PCI DSS"},"content":{"rendered":"<h2 data-start=\"301\" data-end=\"337\"><span class=\"ez-toc-section\" id=\"What_is_the_PCI_DSS_standard\"><\/span><strong data-start=\"304\" data-end=\"337\">What is the PCI DSS standard?<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p data-start=\"339\" data-end=\"568\">The <strong data-start=\"343\" data-end=\"401\">Payment Card Industry Data Security Standard (PCI DSS)<\/strong> is a s<strong>ecurity standard<\/strong> designed to protect cardholder data, as well as other sensitive authentication information, during its processing, storage and\/or transmission.<\/p>\n<p data-start=\"570\" data-end=\"840\">The current version of the standard is <strong data-start=\"609\" data-end=\"624\">PCI DSS 4.0<\/strong>, p<strong>ublished in March 2022<\/strong>. Compliance is mandatory for all companies that accept, process or transmit card data. Failing to comply can lead to significant penalties or even the loss of payment-processing permissions.<\/p>\n<h2 data-start=\"842\" data-end=\"874\"><span class=\"ez-toc-section\" id=\"Background_before_PCI_DSS\"><\/span><strong data-start=\"845\" data-end=\"874\">Background before PCI DSS<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p data-start=\"876\" data-end=\"1083\">Before the first version of PCI DSS existed, each card brand had its <strong>own security programme<\/strong>. Each programme defined its own security controls, compliance reporting processes and penalties for non-compliance.<\/p>\n<p data-start=\"1085\" data-end=\"1285\">This meant that businesses handling cards from multiple brands had to comply with several different security programmes at once, resulting in <strong>duplication, inconsistencies and overlapping requirements<\/strong>.<\/p>\n<h2 data-start=\"1287\" data-end=\"1329\"><span class=\"ez-toc-section\" id=\"Requirements_to_comply_with_PCI_DSS\"><\/span><strong data-start=\"1290\" data-end=\"1329\">Requirements to comply with PCI DSS<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p data-start=\"1331\" data-end=\"1518\">With the introduction of PCI DSS, <strong>all requirements were unified under a single security standard<\/strong>. These are the essential controls for protecting sensitive card data and preventing fraud:<\/p>\n<ol data-start=\"1520\" data-end=\"1855\">\n<li data-start=\"1520\" data-end=\"1571\">\n<p data-start=\"1522\" data-end=\"1571\">Use of firewalls to prevent unauthorised access<\/p>\n<\/li>\n<li data-start=\"1572\" data-end=\"1617\">\n<p data-start=\"1574\" data-end=\"1617\">Data encryption to ensure confidentiality<\/p>\n<\/li>\n<li data-start=\"1618\" data-end=\"1680\">\n<p data-start=\"1620\" data-end=\"1680\">Access controls to restrict access to authorised personnel<\/p>\n<\/li>\n<li data-start=\"1681\" data-end=\"1733\">\n<p data-start=\"1683\" data-end=\"1733\">Network monitoring to detect suspicious activity<\/p>\n<\/li>\n<li data-start=\"1734\" data-end=\"1782\">\n<p data-start=\"1736\" data-end=\"1782\">Security testing to identify vulnerabilities<\/p>\n<\/li>\n<li data-start=\"1783\" data-end=\"1855\">\n<p data-start=\"1785\" data-end=\"1855\">Password management policies to ensure strong and secure credentials<\/p>\n<\/li>\n<\/ol>\n<p data-start=\"1857\" data-end=\"2030\">Together, these elements form a comprehensive framework that protects against threats such as data theft and fraud, ensuring customer data security and compliance with PSD2.<\/p>\n<h2 data-start=\"2032\" data-end=\"2064\"><span class=\"ez-toc-section\" id=\"PCI_DSS_compliance_levels\"><\/span><strong data-start=\"2035\" data-end=\"2064\">PCI DSS compliance levels<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p data-start=\"2066\" data-end=\"2143\">PCI DSS defines four levels of compliance based on annual transaction volume:<\/p>\n<ul data-start=\"2145\" data-end=\"2337\">\n<li data-start=\"2145\" data-end=\"2194\">\n<p data-start=\"2147\" data-end=\"2194\"><strong data-start=\"2147\" data-end=\"2159\">Level 1:<\/strong> more than 6 million transactions<\/p>\n<\/li>\n<li data-start=\"2195\" data-end=\"2239\">\n<p data-start=\"2197\" data-end=\"2239\"><strong data-start=\"2197\" data-end=\"2209\">Level 2:<\/strong> 1 to 6 million transactions<\/p>\n<\/li>\n<li data-start=\"2240\" data-end=\"2289\">\n<p data-start=\"2242\" data-end=\"2289\"><strong data-start=\"2242\" data-end=\"2254\">Level 3:<\/strong> 20,000 to 1 million transactions<\/p>\n<\/li>\n<li data-start=\"2290\" data-end=\"2337\">\n<p data-start=\"2292\" data-end=\"2337\"><strong data-start=\"2292\" data-end=\"2304\">Level 4:<\/strong> fewer than 20,000 transactions<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"2339\" data-end=\"2371\">Levels 2, 3 and 4 must complete:<\/p>\n<ul data-start=\"2373\" data-end=\"2547\">\n<li data-start=\"2373\" data-end=\"2420\">\n<p data-start=\"2375\" data-end=\"2420\">The SAQ (Self-Assessment Questionnaire)<\/p>\n<\/li>\n<li data-start=\"2421\" data-end=\"2504\">\n<p data-start=\"2423\" data-end=\"2504\">A quarterly network scan performed by an ASV (Approved Scanning Vendor)<\/p>\n<\/li>\n<li data-start=\"2505\" data-end=\"2547\">\n<p data-start=\"2507\" data-end=\"2547\">An AOC (Attestation of Compliance)<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"2549\" data-end=\"2732\">Level 1 entities face stricter controls and longer audit processes. They must also submit an annual ROC (Report on Compliance) prepared by a QSA (Qualified Security Assessor).<\/p>\n<h2 data-start=\"2734\" data-end=\"2762\"><span class=\"ez-toc-section\" id=\"PaynoPain_and_PCI_DSS\"><\/span><strong data-start=\"2737\" data-end=\"2762\">PaynoPain and PCI DSS<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p data-start=\"2764\" data-end=\"3159\">At <a href=\"https:\/\/paynopain.com\/en\/\"><strong data-start=\"2767\" data-end=\"2780\">PaynoPain<\/strong><\/a>, as a payment solutions provider, we have spent more than 15 years ensuring full compliance with <strong data-start=\"2878\" data-end=\"2897\">PCI DSS Level 1<\/strong>, one of the highest security standards in the industry. We are also certified under <strong data-start=\"2982\" data-end=\"2995\">ISO 27001<\/strong>, which ensures the implementation of an Information Security Management System (ISMS) that protects the confidentiality, integrity and availability of information.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>What is the PCI DSS standard?<\/p>\n<p>The Payment Card Industry Data Security Standard (PCI DSS) is a security standard designed to protect cardholder data and other sensitive authentication information during processing, storage and\/or transmission.<\/p>\n","protected":false},"featured_media":9062,"template":"","meta":{"_acf_changed":false},"class_list":["post-10298","glosario","type-glosario","status-publish","has-post-thumbnail","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>PCI DSS - PaynoPain<\/title>\n<meta name=\"description\" content=\"PCI-DSS is the Payment Card Industry Data Security Standard. We explain all the details about how to stay compliant.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/paynopain.com\/en\/glossary\/pci-dss\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"PCI DSS - PaynoPain\" \/>\n<meta property=\"og:description\" content=\"PCI-DSS is the Payment Card Industry Data Security Standard. We explain all the details about how to stay compliant.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/paynopain.com\/en\/glossary\/pci-dss\/\" \/>\n<meta property=\"og:site_name\" content=\"PaynoPain\" \/>\n<meta property=\"article:modified_time\" content=\"2026-01-27T12:20:08+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/paynopain.com\\\/en\\\/glossary\\\/pci-dss\\\/\",\"url\":\"https:\\\/\\\/paynopain.com\\\/en\\\/glossary\\\/pci-dss\\\/\",\"name\":\"PCI DSS - PaynoPain\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/paynopain.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/paynopain.com\\\/en\\\/glossary\\\/pci-dss\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/paynopain.com\\\/en\\\/glossary\\\/pci-dss\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/paynopain.com\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/28-1.svg\",\"datePublished\":\"2025-08-06T15:39:48+00:00\",\"dateModified\":\"2026-01-27T12:20:08+00:00\",\"description\":\"PCI-DSS is the Payment Card Industry Data Security Standard. We explain all the details about how to stay compliant.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/paynopain.com\\\/en\\\/glossary\\\/pci-dss\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/paynopain.com\\\/en\\\/glossary\\\/pci-dss\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/paynopain.com\\\/en\\\/glossary\\\/pci-dss\\\/#primaryimage\",\"url\":\"https:\\\/\\\/paynopain.com\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/28-1.svg\",\"contentUrl\":\"https:\\\/\\\/paynopain.com\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/28-1.svg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/paynopain.com\\\/en\\\/glossary\\\/pci-dss\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Portada\",\"item\":\"https:\\\/\\\/paynopain.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"PCI DSS\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/paynopain.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/paynopain.com\\\/en\\\/\",\"name\":\"PaynoPain\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/paynopain.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"PCI DSS - PaynoPain","description":"PCI-DSS is the Payment Card Industry Data Security Standard. We explain all the details about how to stay compliant.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/paynopain.com\/en\/glossary\/pci-dss\/","og_locale":"en_US","og_type":"article","og_title":"PCI DSS - PaynoPain","og_description":"PCI-DSS is the Payment Card Industry Data Security Standard. We explain all the details about how to stay compliant.","og_url":"https:\/\/paynopain.com\/en\/glossary\/pci-dss\/","og_site_name":"PaynoPain","article_modified_time":"2026-01-27T12:20:08+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/paynopain.com\/en\/glossary\/pci-dss\/","url":"https:\/\/paynopain.com\/en\/glossary\/pci-dss\/","name":"PCI DSS - PaynoPain","isPartOf":{"@id":"https:\/\/paynopain.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/paynopain.com\/en\/glossary\/pci-dss\/#primaryimage"},"image":{"@id":"https:\/\/paynopain.com\/en\/glossary\/pci-dss\/#primaryimage"},"thumbnailUrl":"https:\/\/paynopain.com\/wp-content\/uploads\/2025\/10\/28-1.svg","datePublished":"2025-08-06T15:39:48+00:00","dateModified":"2026-01-27T12:20:08+00:00","description":"PCI-DSS is the Payment Card Industry Data Security Standard. We explain all the details about how to stay compliant.","breadcrumb":{"@id":"https:\/\/paynopain.com\/en\/glossary\/pci-dss\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/paynopain.com\/en\/glossary\/pci-dss\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/paynopain.com\/en\/glossary\/pci-dss\/#primaryimage","url":"https:\/\/paynopain.com\/wp-content\/uploads\/2025\/10\/28-1.svg","contentUrl":"https:\/\/paynopain.com\/wp-content\/uploads\/2025\/10\/28-1.svg"},{"@type":"BreadcrumbList","@id":"https:\/\/paynopain.com\/en\/glossary\/pci-dss\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Portada","item":"https:\/\/paynopain.com\/en\/"},{"@type":"ListItem","position":2,"name":"PCI DSS"}]},{"@type":"WebSite","@id":"https:\/\/paynopain.com\/en\/#website","url":"https:\/\/paynopain.com\/en\/","name":"PaynoPain","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/paynopain.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/paynopain.com\/en\/wp-json\/wp\/v2\/glosario\/10298","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/paynopain.com\/en\/wp-json\/wp\/v2\/glosario"}],"about":[{"href":"https:\/\/paynopain.com\/en\/wp-json\/wp\/v2\/types\/glosario"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/paynopain.com\/en\/wp-json\/wp\/v2\/media\/9062"}],"wp:attachment":[{"href":"https:\/\/paynopain.com\/en\/wp-json\/wp\/v2\/media?parent=10298"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}