PCI DSS anchors

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

Primary documents

  • PCI DSS v4.0 (March 2022) + v4.0.1 (June 2024).
  • PCI DSS Self-Assessment Questionnaires (multiple SAQ types).
  • PCI DSS Glossary.
  • Reporting Templates (Report on Compliance, Attestation of Compliance).

All free from PCI SSC.

Operating body

  • PCI Security Standards Council (PCI SSC) โ€” founded 2006 by Visa, Mastercard, Amex, Discover, JCB.
  • Maintains PCI DSS plus PCI PIN Transaction Security, PCI P2PE, PCI 3DS, PCI Card Production, PCI Software Security Framework.

Validation roles

  • QSA (Qualified Security Assessor) โ€” council-approved firms for Level 1 assessments.
  • ASV (Approved Scanning Vendor) โ€” quarterly external scan providers.
  • PCIP (PCI Professional) โ€” individual credential.
  • ISA (Internal Security Assessor) โ€” internal personnel credential.

Adjacent PCI standards

  • PCI PIN โ€” PIN security.
  • PCI 3DS โ€” 3-D Secure.
  • PCI P2PE โ€” point-to-point encryption.
  • PCI SSF (Software Security Framework) โ€” secure software development for payment software.
  • PCI Card Production โ€” card manufacturing security.

Adjacent regulations

  • GDPR โ€” personal data overlap.
  • NIS2 โ€” financial sector partial overlap.
  • DORA โ€” financial services lex specialis for financial entities.

Reference resources

  • pcisecuritystandards.org โ€” PCI SSC hub.
  • List of QSAs / ASVs โ€” searchable directory.

See also