Skip to Content

What are Payment Card Industry Data Security Standards?

PCI DSS (Payment Card Industry Data Security Standard) is a global standard that provides a set of technical and operational requirements to ensure all businesses, regardless of size, that handle credit card information maintain a secure environment. It was created by the five major card schemes; American Express, JCB, Visa, MasterCard and Discover Financial Services to protect payment data and reduce card data fraud.

pci-dss-banner

PCI DSS Compliance

Being compliant with PCI DSS means that a business is doing their very best to keep their customers' valuable information safe and secure and out of the hands of people who could use that data in a fraudulent way. A key part of this is ensuring that the cardholder data environment (CDE) is properly segmented and protected.

Any merchant with a merchant ID that accepts payment cards must follow PCI-compliance regulations to protect themselves against data breaches. The requirements range from establishing data security policies for their business and employees to removing card data from their processing system and payment terminals. 

Qualified Security Assessors (QSAs) and Internal Security Assessors (ISAs) have a critical role in helping organizations achieve and maintain PCI DSS compliance.

pci-dss-compliance

What are the requirements for PCI DSS compliance? 

There are 12 main requirements in the PCI DSS, spread across six core principles. 

What is PCI DSS v4.0?

Global payment security forum PCI SSC released the PCI DSS Version 4.0 in 2022. The development of PCI DSS v4.0 was driven by industry feedback and aims to protect payment data from increasingly sophisticated cyber-attacks.

PCI DSS v4.0 release has four main goals.

PCI DSS v4.0 implementation timeline

PCI DSS v3.2.1 was retired on March 31 2024. All organizations now need to meet the PCI v4 standards (with the exception of some future-dated new requirements which have until March 31 2025).  

pci-dss-v4-at-glance
assess-device-configurations-against-pci

How Nipper InfraSight and Nipper OmniSight can help with PCI DSS compliance?

For more information about how Nipper solutions can support PCI DSS compliance visit our solutions page. 

Continuously viewing and managing PCI DSS compliance

PCI DSS v4.0 recommends abandoning sampling and regularly assessing network infrastructure (routers, switches and firewalls) to ensure organizations gain increased security from continuous compliance.

Ian Robinson, Chief Architect at Titania talks through why this is important and how Nipper OmniSight enables the shift from ad-hoc, sampled assessments to continuous compliance assurance for the Enterprise.

With a short product demo, Ian shows how this can enable network owners to increase the coverage and cadence of network infrastructure assessments, prioritize remediation of non-compliances, & shut down real-world threats.  

Please note: we evolved our brand architecture to create clearer product naming and a more consistent way to navigate our Nipper solutions family. Nipper is now Nipper InfraSight. Nipper Resilence/Enterprise is now Nipper OmniSight.

Talk to an expert

Explore which solution is right for your organization and discuss next steps.