PCI DSS compliance.
In plain English
PCI DSS is the Payment Card Industry Data Security Standard, a set of security requirements written by the major card networks for anyone who stores, processes, or transmits cardholder data. It covers network security, encryption of stored and transmitted data, access controls, vulnerability management, logging, and regular testing. It is enforced by contract through acquirers and networks rather than by statute. Validation effort scales with volume, so a small merchant completes a self-assessment questionnaire while the largest face an on-site audit by a qualified assessor.
01Why it matters
The cost of compliance is built into what merchants pay to accept cards, and a business that fails the standard and then suffers a breach can face fines, forensic costs, and the loss of its ability to take cards at all.
02The math, step by step
Say a mid-sized merchant spends 4,000 dollars a year on scanning and assessment. A breach exposing 50,000 records brings forensic investigation, customer notification, and card network fines that run far above that annual figure, which is the arithmetic that makes the yearly spend look cheap.
Illustrative example. The amounts here are hypothetical, chosen to show how the math works, not real quoted rates or figures.
03What this is NOT
PCI DSS is not government regulation. It is a private standard enforced through contracts with the card networks and acquirers. Some states reference it inside their own statutes, but the standard itself is written and revised by the card industry.
04Receipts
Every figure on this page is sourced to a primary document. Tap to open the original.
Plain-English answers from our glossary. Receipts included. Never advice.
Educational tool. Answers come only from ClearMoneySchool's published glossary and are not advice. Why we never give advice