Compliance vs security
The classic gap:
- Target (2013): PCI compliant at time of breach.
- Equifax (2017): held multiple certifications.
- Various: certified entities breached.
PCI compliance does not predict breach absence.
Prescriptive ⇒ rigid
Twelve requirements + ~300 sub-requirements prescriptive:
- Cloud-native / modern-architecture implementations can struggle with literal compliance.
- Customized approach in v4 addresses but adds documentation overhead.
- Innovation can be blocked by literal requirement reading.
Scope minimization games
Heavy emphasis on minimizing CDE produces:
- Tokenization adopted primarily to reduce compliance scope.
- Outsourcing CHD-handling to specialist providers shifts compliance.
- Original security goal (protect CHD) sometimes lost in compliance optimization.
QSA variance
QSA firms vary:
- Some thorough, others lighter.
- QSA shopping detectable in some cases.
- Annual reassessment risk if switching.
Smaller merchant burden
Level 4 merchants with low volumes still face PCI DSS:
- SAQ A reasonable for fully outsourced.
- SAQ D burdens smaller in-house processing.
- Quarterly ASV scan cost for sites with limited revenue.
v4.0 transition complexity
v4 mandatory March 2025:
- v4.0 features (customized approach, expanded MFA, targeted risk analysis) substantial new work.
- Transition documentation burden.
- QSA capability ramp.
Counterpoint
- Industry mandate produces real cybersecurity uplift across payment ecosystem.
- Prescriptive requirements set defensible baseline.
- Tokenization / P2PE reduce attack surface substantively.
- v4.0 modernizations address legacy gaps.