PCI DSS Controversies

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

Compliance vs security

The classic gap:

  • Target (2013): PCI compliant at time of breach.
  • Equifax (2017): held multiple certifications.
  • Various: certified entities breached.

PCI compliance does not predict breach absence.

Prescriptive ⇒ rigid

Twelve requirements + ~300 sub-requirements prescriptive:

  • Cloud-native / modern-architecture implementations can struggle with literal compliance.
  • Customized approach in v4 addresses but adds documentation overhead.
  • Innovation can be blocked by literal requirement reading.

Scope minimization games

Heavy emphasis on minimizing CDE produces:

  • Tokenization adopted primarily to reduce compliance scope.
  • Outsourcing CHD-handling to specialist providers shifts compliance.
  • Original security goal (protect CHD) sometimes lost in compliance optimization.

QSA variance

QSA firms vary:

  • Some thorough, others lighter.
  • QSA shopping detectable in some cases.
  • Annual reassessment risk if switching.

Smaller merchant burden

Level 4 merchants with low volumes still face PCI DSS:

  • SAQ A reasonable for fully outsourced.
  • SAQ D burdens smaller in-house processing.
  • Quarterly ASV scan cost for sites with limited revenue.

v4.0 transition complexity

v4 mandatory March 2025:

  • v4.0 features (customized approach, expanded MFA, targeted risk analysis) substantial new work.
  • Transition documentation burden.
  • QSA capability ramp.

Counterpoint

  • Industry mandate produces real cybersecurity uplift across payment ecosystem.
  • Prescriptive requirements set defensible baseline.
  • Tokenization / P2PE reduce attack surface substantively.
  • v4.0 modernizations address legacy gaps.

See also