PCI Compliance Checklist: A Step-by-Step Guide to Meeting 12 Requirements
Last updated:23 January 2025

Recently, many customers have experienced frustration of being contacted by their banks or financial institutions with the disheartening news that their credit card information has been compromised. Credit card fraud continues to be a recurring issue, posing significant challenges for businesses.
So how do you actually know the online providers storing your card details are protecting them?
That question is why, in 2006, Visa, Mastercard, American Express, Discover, and JCB set up the Payment Card Industry Security Standards Council (PCI SSC). Its job is to manage the security standards for any company that handles credit card data.
Before that, each card brand ran its own security program. The requirements mostly overlapped, so the five merged them into a single policy: the PCI Data Security Standard (PCI DSS).
Understanding and meeting PCI DSS is hard work. If your business handles card data, complying with its 300+ security controls may be mandatory. The PCI Council's official documentation runs to more than 1,800 pages. Over 300 of them cover just the forms you use to validate compliance. Reading all of it would take you more than 72 hours.
Done wrong, compliance turns slow and expensive, eating time and budget. This guide walks you through validating and maintaining PCI compliance, one step at a time.
Key takeaways
- PCI compliance is mandatory for any business that handles payment card data.
- Its main goal is to protect that data and keep customer trust.
- Falling short can cost $5,000 to $500,000 per incident, plus monthly fines and even losing the ability to accept cards.

What Is PCI Compliance?

PCI DSS is the global security standard for any organization that stores, processes, or transmits cardholder data and sensitive authentication data. Its goal is a baseline of consumer protection that cuts fraud and data breaches across the whole payment chain.
Size does not matter here. If your organization accepts or processes payment cards, PCI DSS applies to you.
Join our upcoming webinar to get practical guidance before your next audit

PCI compliance means following the technical and operational standards that protect cardholder data during payment transactions. Preventing fraud and breaches is a shared effort: businesses have to stay alert, follow PCI DSS, and keep their data-security practices consistent.
The latest version, 4.0.1, adds flexibility by tying technology more closely to business processes. Firewalls and antivirus still matter, but so does understanding how those controls fit the way your business actually runs. Version 4.0.1 revisits several technical areas to keep cardholder data secure:
- authentication and password guidance;
- advanced system monitoring;
- multi-factor authentication.

PCI DSS v4.0.1 vs. PCI DSS v4.0
PCI SSC released v4.0.1 to act on feedback and clarify requirements from v4.0, which came out in March 2022. It fixes minor errors and sharpens the guidance. No requirements were added or removed.
To keep the standard in step with the industry, PCI SSC ran a feedback period from December 2023 to January 2024. If you took part, the summary is in the PCI SSC portal.
Key changes
- Requirement 3: Updated applicability for issuers and companies using cryptographic hashes.
- Requirement 6: Clarified 30-day patching for critical vulnerabilities and added notes on payment page script management.
- Requirement 8: Specified MFA exceptions for phishing-resistant authentication.
- Requirement 12: Updated guidance on customer and third-party service provider relationships.
Both versions stayed active until December 31, 2024. Since then, only v4.0.1 applies. The new requirements it clarifies became mandatory on March 31, 2025. The update itself added nothing new; it only sharpens what was already there.

How Often Should You Update PCI Compliance?
PCI compliance is ongoing work rather than a one-off. How often you revalidate depends on a couple of things, mainly your required compliance level and how many card transactions you process a year. Here is how the cadence changes across merchant levels:

The more transactions you handle, the stricter your requirements get, especially around security vulnerabilities. The four merchant levels hold every organization to clear standards while accounting for its own risk profile and infrastructure.
Who Is Obliged to Be PCI Compliant?

Any organization that handles credit card transactions or processes cardholder data needs to be PCI compliant. That covers several types of players:
- Merchants carry the most direct obligation. Any business that accepts card payments has to meet PCI DSS, whatever its size or industry, from retail stores and e-commerce sites to restaurants, hotels, and service providers.
- Service providers handle cardholder data on a merchant's behalf, whether they process, store, or transmit it. Think payment processors, web hosts, cloud providers, and software vendors.
- The banks that issue cards to customers fall under PCI too. They protect the cardholder data they hold and make sure the merchants accepting their cards meet PCI DSS.
- Acquiring banks, also called acquirers or acquiring processors, these are the financial institutions that set up and maintain merchant accounts.
- Payment card brands: Visa, Mastercard, American Express, Discover, and JCB are the ones enforcing PCI. They set the PCI DSS rules and require their merchants and service providers to follow them.
- Cardholders. They are not bound by PCI directly, but they still matter. Protecting your card details, paying through secure methods, and reporting anything suspicious all help keep the system safe.
Benefits of PCI DSS Compliance
Meeting the PCI standards can feel overwhelming, especially for a smaller company. The payoff is real, though, and the cost of not complying tends to show up over the long run.

- Building partnerships: Compliance lets you work with payment processors, which is what you need to run an online marketplace or launch your own payment card. It also raises your standing with acquirers and card brands, and that trust matters when partners are deciding whether to work with you.
- Easier compliance elsewhere: PCI DSS overlaps with frameworks like GDPR and HIPAA. Get PCI right and you are already part of the way to meeting those, which saves work later.

- Lower breach risk: Meeting the standards keeps your systems capable of protecting payment card data. Fewer incidents means more customer trust, and trust is what keeps people coming back.
- Stronger customer trust: Following PCI shows customers you take securing their data seriously.
What Happens If You Are Not Compliant?

For most businesses, taking cards is the nessesity. But fraud, identity theft, and breaches keep rising, which is exactly why the payment environment has to stay secure. When a company is found non-compliant with PCI DSS, the penalties get steep, from fines to losing the right to accept cards at all. They include:
- Losing card acceptance. If you can no longer take card payments, the hit lands on revenue, market share, and reputation at once. To get permission back, a non-compliant organization has to pass a PCI reassessment by an external Qualified Security Assessor (QSA).
- Mandatory forensic exam. When a breach is suspected, merchants can be put through a costly forensic examination. The bill scales with size. Level 2 merchants (1–6 million transactions a year) face $20,000 to $50,000; Level 1 merchants (6+ million) can pay upward of $120,000.
- Liability for fraud. After a breach, the company is on the hook for fraudulent charges, which opens the door to lawsuits and further losses.

Examples of data breaches
In the first half of 2020 alone, 36 billion records were exposed in data breaches. That scale tells us how serious the threat is.
In 2021, Next Level Apparel (NLA) was hit by a phishing attack. The attackers got into its database and exposed sensitive data, including Social Security and credit card numbers. NLA responded by adding security controls and tightening its email protections.
Neiman Marcus was breached the same year, and this one was big: 4.6 million customer accounts. Names, contact details, card numbers, usernames, passwords, even virtual gift cards were exposed. The company forced a password reset across the affected accounts.
During the 2021 Black Friday Cyber Monday shopping weekend, cybercriminals exploited a known vulnerability in the popular e-commerce platform Magento. Targeting approximately 4,151 self-hosted Magento stores, the hackers gained unauthorized access to personal and payment information.
Fortunately, the UK's National Cyber Security Centre's Active Cyber Defense program identified the security breach and urged merchants to apply stringent security patches to protect their customers.
The question should not be whether PCI DSS compliance is mandatory (it is) but rather why any business would risk the consequences of not implementing it.
How Much Are PCI Non-Compliance Fines?
Non-compliance fines for PCI-DSS can have significant financial ramifications, with penalties ranging from $5,000 to as high as $500,000 per PCI data security incident, especially in the case of massive data breaches.

When merchants enter into contracts with payment processors, they agree to be subject to fines for non-compliance with PCI DSS. The fines can vary based on the payment processor and are typically higher for companies with a higher volume of transactions. While pinpointing a typical fine amount is challenging, IS Partners provides some ranges.
Fines are assessed every month for the duration of non-compliance, and the monthly charge increases for more extended periods. For example, a company might face a $5,000 monthly fine for three months of non-compliance, but the fine could escalate to $50,000 per month if the non-compliance persists for seven months. Moreover, individual fines ranging from $50 to $90 can be imposed for each customer affected by a data breach.
These "fines" are not akin to government or traffic violations; rather, they are penalties outlined in contractual agreements between merchants, payment processors, and card brands.
Furthermore, regulations dictate that all individuals whose data has potentially been exposed to a breach must be notified in writing. This ensures they are alert for fraudulent activity on their accounts. There is no possibility of concealing this breach of trust from those affected.
How to Become PCI Compliant

The PCI Standards Council provides a transparent three-step process to ensure PCI compliance:
Step 1: Assess
PCI compliance starts with a thorough assessment. You map the cardholder data you hold, the IT assets that touch it, and the business processes tied to card processing. That map is what lets you find the weak spots and plan how to protect them.
Start by documenting every system and process that stores, processes, or transmits cardholder data. That includes the payment systems and anything connected to them, since a weakness in a neighboring system can still put card data at risk.
You also need vulnerability scans and penetration testing, run both internally and externally, to surface security weaknesses inside the PCI DSS scope.
Penetration testing for Coach Solutions web application

Step 2: Remediate
Remediation is where you fix what the assessment found. Start with the high-risk vulnerabilities, since they put cardholder data in the most danger. Once those are closed, work down to the lower-risk ones.
The work varies: patching software, updating firewalls, rotating passwords, sometimes rethinking a business process. And it never really stops, because new vulnerabilities show up all the time.
Step 3: Report
The last phase is reporting. You compile a report and submit it to your acquiring bank and the major card brands for validation. Which report you file depends on your size and how many transactions you process a year.
A smaller business can usually file a Self-Assessment Questionnaire (SAQ). Larger enterprises may face an onsite audit from a Qualified Security Assessor (QSA) or Internal Security Assessor (ISA). Either way, reporting is more than proof of compliance. It is a chance to look hard at your security practices and find what to improve.
PCI Compliance Checklist: 12 Requirements
Here is the step-by-step process for meeting all 12 requirements.

Step 1: Install and maintain a firewall
A firewall is your network's first line of defense, keeping cardholder data in and unauthorized access out. Requirement 1 is about maintaining that firewall properly.
This involves
- configuring rules and criteria to control incoming and outgoing network access,
- documenting processes,
- regularly reviewing configuration rules and flowcharts.
That means configuring firewalls and routers carefully and setting strict rules for what traffic is allowed.
Step 2: Eliminate default settings
Hackers can easily exploit vendor-supplied defaults for devices like firewalls and routers. PCI DSS Requirement 2 hardens the network by changing default passwords, usernames, and administration accounts. This reduces the risk of unauthorized access and strengthens overall network security.
Step 3: Protect stored cardholder data
PCI DSS Requirement 3 aims to minimize risks associated with storing sensitive data. Implementing security mechanisms such as encryption, truncation, masking, and hashing ensures that the data remains unreadable and unusable even if hackers gain access. Practices like strong encryption, minimizing unnecessary data storage, and following data retention and destruction policies help protect cardholder data. Utilizing a card data discovery tool helps identify unencrypted primary account numbers (PAN).

Learn how we built macro-investing app with its own token and reward system

Step 4: Encrypt payment data transmission
Data sent over open, unencrypted public networks is easy for attackers to intercept. Requirement 4 is about encrypting that traffic so sensitive data stays out of reach.
Turning off weak keys and using strong protocols like TLS 1.2 or higher improves security. PCI DSS v4.0 and v4.0.1 add specific guidance on multi-factor authentication (MFA).
Step 5: Regularly update anti-virus software
Malware is a direct threat to cardholder data. Requirement 5 calls for up-to-date anti-virus that can catch and remove the full range, from viruses and worms to Trojans, bots, and ransomware. Keep the software current, hold onto your audit logs, and watch how malware is changing.

Step 6: Develop and maintain secure systems and applications
Start with a risk assessment to identify and rank the risks tied to the technology you deploy. Once that is done, you can roll out the equipment and software that handle payment card data safely.
Patch promptly, too: databases, point-of-sale terminals, operating systems. And track vulnerabilities through trustworthy sources like Microsoft Security Bulletins and Cisco Security Advisories.
Step 7: Restrict cardholder data access
Requirement 7 is about controlling who can reach payment card data, by role and permission. Limit access to the people who genuinely need it to do their jobs. You also need documented access-control policies that spell out who gets in, based on job function, seniority, and reason for access.
Step 8: Assign a unique ID
Everyone with computer access to cardholder data should have their own ID and password. Requirement 8 also covers managing those credentials properly, from adding new users to cutting off access the moment someone leaves.
User IDs and passwords have to meet set rules for length and complexity, which keeps unauthorized users out. Multi-factor authentication (MFA) adds another layer on top.

PCI password requirements:
- Passwords must be at least seven characters long.
- They must include a combination of numbers and letters.
- Users must change passwords every 90 days.
- The new password must differ from the previous four passwords.
- For new users or password resets, unique passwords must be generated and changed after first use.
- The lockout duration for a user's account after failed attempts is 30 minutes or until a system administrator resets it.
- Vendor-supplied defaults are prohibited.
- Passwords must be encrypted during transmission and storage.
Step 9: Restrict physical access to cardholder data
Physical security counts as much as the digital kind. Requirement 9 covers protecting cardholder data where it physically lives: servers, data centers, computer rooms.
- Access to these areas must be tightly controlled through badge readers and key-controlled locks.
- Monitoring with security mechanisms, including video cameras, further enhances protection.
- Implementing automatic server locking and timeout systems ensures secure login screens when not in use.
- Access logs and recordings should be retained for at least 90 days, and portable media with cardholder data must be securely stored and disposed of when no longer needed.
Step 10: Track and monitor network access
Organizations must keep detailed logs of network and cardholder data access for effective troubleshooting and forensic investigation in case of a breach. PCI DSS Requirement 10 focuses on maintaining logs to track activities related to cardholder data, including individual access, invalid access attempts, access to audit logs, and other transactions.
Security Information and Event Monitoring (SIEM) tools help track system activity and identify suspicious behavior. Network activity logs must be maintained for at least one year and time-synchronized for proper analysis.
Learn how we built macro-investing app with its own token and reward system

Step 11: Regularly test security systems and processes
Securing the system is only the start. You have to keep finding and fixing weaknesses before someone else does. Requirement 11 covers vulnerability scanning, penetration testing, and checking for rogue wireless access points and devices.
Quarterly vulnerability scans catch and clear issues as they appear. Annual penetration tests go further, simulating real attacks to expose weaknesses, especially after any significant change to the system.

Step 12: Establish an information security policy
The final step towards PCI compliance involves creating and maintaining a comprehensive information security policy across the organization. This policy should
- cover all employees, management, and relevant third parties.
- include security awareness training programs, regular policy reviews, risk assessment processes, incident response programs, and technology usage policies to foster a culture of data security throughout the organization.
Achieving PCI Compliance: Tips and Best Practices

PCI requires both digital and physical barriers around cardholder data. That can mean authentication protocols and strong password policies on the digital side, and locked servers and secured cabinets on the physical side. Two controls matter most: restricting who can reach the data, and encrypting it in transit.
Write a clear incident response process that lays out how you detect, contain, and recover from an incident. When a breach hits, a plan you have already rehearsed is what lets you respond fast.
Protect the data the way you would protect your own devices: strong passwords, software kept up to date (point-of-sale terminals especially), and no keeping paper receipts you do not need. Then train your staff on why cardholder data matters and how to spot a suspicious link.
Conclusion
Meeting the PCI standards protects your organization from steep penalties and the business you would lose in a breach. It is also part of the contracts you signed with the card networks.
PCI DSS compliance is hard, and it takes continuous effort and reassessment. Validation usually happens once a year, but the work of staying compliant runs all year long.
As your company grows, your compliance obligations grow with it. Move into a new market, open a physical store, or launch a support center, and you may bring new payment-card data into scope, which means revalidating before it becomes a problem.
Finding the gaps in your current compliance is only the start. To close them, it helps to work with experienced PCI compliance specialists, who bring practical guidance and FinTech software development services to get your organization to PCI DSS v4.0 and v4.0.1 compliance.
FAQ

Start by assessing your security controls against the PCI DSS requirements. That means identifying where cardholder data lives, checking for vulnerabilities, and putting the right controls in place.
Then you validate: depending on how many card transactions you process, that is either a Self-Assessment Questionnaire (SAQ) or an onsite audit by a Qualified Security Assessor (QSA). Once you have passed assessment and validation, you receive your PCI compliance certificate.
What PCI compliance costs depends on a few things: how big and complex your business is, how many card transactions you process, and how much of your environment touches cardholder data.
PCI compliance is not written into law, and no government enforces it. It is contractual: it comes from the agreements you sign with your merchant or payment service providers and with the card networks like Visa and Mastercard.













