<img alt="" src="https://secure.perk0mean.com/172683.png" style="display:none;">
Skip to content
English
  • There are no suggestions because the search field is empty.

What are the PCI DSS requirements?

Find out how to validate PCI DSS compliance and protect payment account data

PCI DSS applies to organisations that store, process or transmit payment account data, and to organisations whose systems could affect the security of that data. Your validation requirements depend on how you accept payments, your payment environment and any requirements set by Cashflows or the card brands.

How do I validate PCI DSS compliance?

1. Determine which Self-Assessment Questionnaire (SAQ) or assessment method applies to your payment environment.

2. Complete the applicable SAQ or assessment in full.

3. Complete an external vulnerability scan using a PCI SSC Approved Scanning Vendor (ASV) if your applicable validation requirements require one.

4. Complete the relevant Attestation of Compliance (AOC).

5. Submit the required validation documents using the process provided by Cashflows or VikingCloud.

6. Revalidate your compliance at the required frequency and whenever your payment environment changes significantly.

Important: Your merchant level does not determine the correct SAQ by itself. The correct SAQ depends on your payment channels, technology and how account data is handled. Contact VikingCloud or the Cashflows PCI team if you are unsure.

 

The 12 PCI DSS requirements

  1. 1. Install and maintain network security controls.
  2. 2. Apply secure configurations to all system components.
  3. 3. Protect stored account data.
  4. 4. Protect cardholder data with strong cryptography during transmission over open, public networks.
  5. 5. Protect all systems and networks from malicious software.
  6. 6. Develop and maintain secure systems and software.
  7. 7. Restrict access to system components and cardholder data by business need to know.
  8. 8. Identify users and authenticate access to system components.
  9. 9. Restrict physical access to cardholder data.
  10. 10. Log and monitor all access to system components and cardholder data.
  11. 11. Test security systems and processes regularly.
  12. 12. Support information security with organisational policies and programmes.

More information

Refer to the current PCI DSS v4.0.1 standard, the PCI DSS Quick Reference Guide and the official PCI Security Standards Council document library.

Sources checked

    • PCI Security Standards Council document library: PCI DSS v4.0.1 and the current Quick Reference Guide.
    • PCI Security Standards Council guidance on Approved Scanning Vendors and external vulnerability scans.
    • PCI Security Standards Council guidance confirming that the applicable SAQ depends on the merchant payment environment and eligibility criteria.