Your Guide to PCI Compliance






SecurityMetrics' PCI Guide Helps You:
Stay up to date with new trends and changes like PCI DSS Version 4.0.
Get a better understanding of your PCI responsibility and the 12 Requirements of PCI Compliance.
Learn how to prepare for a breach and create an incident response plan.
Questions about compliance?
Frequently Asked Questions
What is PCI Compliance?
PCI stands for the Payment Card Industry. In 2006, major payment card brands Visa, MasterCard, American Express, Discover Financial Services, and JCB International established the Payment Card Industry Data Security Standard (PCI DSS). The PCI DSS helps merchants prevent consumer payment card data theft.
Compliance with the PCI DSS, or "PCI DSS compliance," is required for all businesses that process, store, or transmit payment card data. Merchants must complete a PCI DSS compliance form annually. Becoming PCI compliant helps protect your company from data breaches.
How Do I Get PCI Compliant?
To get PCI compliant, you will need to first determine which self-assessment questionnaire (SAQ) you should follow. Depending on your SAQ, you will need to implement a set of requirements and controls as outlined in the PCI Data Security Standard.
SecurityMetrics assists small to large businesses identify and implement their PCI requirements. For more help, request to speak with a PCI expert here.
What is an SAQ for PCI Validation?
SAQ stands for self-assessment questionnaire. Depending on an organization's card transaction volume and the types of transactions it performs, it may be able to use an SAQ to self-evaluate its compliance with the PCI Data Security Standard.
SAQs contain questions about card data security. SAQs range in size from 21 questions (SAQ P2PE) to 267 questions (SAQ D-Service Provider).
Does my payment solution make me PCI compliant?
No. PCI compliance is more than the technology you use to process payments. Validating compliance shows that your business handles payment card data safely in all scenarios.
No matter what solution you choose to process payments—whether online or in person—you will still need to validate compliance, even if you use point-to-point encryption. In short, the responsibility is on you to validate that your business handles payment data safely by following the PCI standard.
Don't take our word
for it, take theirs
★★★★★
"Expert Team and Outstanding Customer Service"
- Arturo A.
★★★★★
"I could not have completed my PCI Compliance without SecurityMetrics”
- Kacey G.
★★★★★
"Great customer support"
- Kim H.
★★★★★
"Worth it for the peace of mind alone"
- Brandon I.
