Who this applies to
Merchants and service providers that accept or handle payment cards.
What to know
- The standard is set by the PCI Security Standards Council. Card brands and acquiring banks enforce it through your merchant agreement.
- Your validation path depends on how you take payments and how many transactions you process.
- Reducing scope is the best control. Using a hosted payment page or tokenization keeps card data out of your systems.
What to do
- Map exactly where card data enters, moves, and rests in your environment.
- Reduce scope before you try to meet every requirement.
- Ask your acquiring bank which validation path applies to you.
This guide is a plain-language summary for general information. It is not legal advice and it does not replace the official source. Requirements change, so check the linked source before you act.