AntCrow
(Glossary · Commerce)

PCI DSS

PCI DSS is the security standard governing how organisations that handle payment card data must protect it.

In full

The Payment Card Industry Data Security Standard is a set of requirements developed by the major card networks covering how cardholder data must be stored, processed, and transmitted. It applies to any organisation touching card data, with the depth of validation scaling to transaction volume. For most businesses the practical approach is to reduce scope rather than meet the full standard: by using a hosted payment page or a tokenised field provided by the gateway, card details never reach your server, and the compliance burden falls dramatically. It is a contractual obligation imposed by the card networks rather than legislation.

Why it matters

Handling raw card data on your own infrastructure creates an obligation and a liability that almost no small or medium business should accept when the alternative is a hosted field.

Reviewed by AntCrowLast reviewed