PCI DSS position

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

What it does well

  • Prescriptive controls — clear implementation guidance.
  • Industry mandate — backed by card schemes; real enforcement.
  • Continuous improvement via version revisions.
  • v4.0 customized approach adds flexibility.
  • Mature QSA ecosystem.

What it does poorly

  • Prescriptive ⇒ rigid. Innovations can be blocked by literal requirement reading.
  • Compliance vs security classical gap — Target / Equifax-style breaches.
  • Smaller merchant burden disproportionate.
  • Quarterly scanning treadmill.
  • Scope reduction games — minimize CHD environment.

Evidence

  • Mandatory for all merchants accepting card payments.
  • v4.0 mandatory March 2025.
  • Continuous compliance emphasis.

Personal calibration

  • For payment-processing client work: PCI DSS vocabulary load-bearing.
  • For non-payment-processing: limited applicability.

See also