Skip to content
Aashna Jain

What is PCI DSS compliance?

3 min readFor buildersTrust and risk

The cheapest way to comply is to arrange never to touch the data at all.

Who wrote it and why that matters

PCI DSS was not created by a government. It was created by the card networks jointly, because card fraud was their problem and merchants were the weak point.

That origin explains its character. It is enforced through contracts rather than statutes, penalties flow through your acquirer rather than a regulator, and the ultimate sanction is not a fine but losing your ability to process cards. For most businesses, that is a more frightening consequence than any fine.

What it actually requires

Twelve broad requirements, covering firewalls, encryption of card data in transit and at rest, access control so only people who need card data can reach it, monitoring and logging, and regular testing.

None of it is exotic. It is a formalised version of what a competent security team would do anyway. The burden is not the ideas; it is the documentation and the annual evidence.

The levels, and the shortcut everyone takes

Compliance obligations scale with volume. The largest merchants, generally those processing over six million card transactions a year, face annual on-site assessment by a qualified assessor. Smaller merchants may self-assess with a questionnaire.

But here is the practical reality that matters more than the levels: the cheapest way to comply is to never touch card data at all. If card details are captured directly by your payment provider's hosted fields or redirect, and the data never enters your servers, your compliance scope collapses to a short questionnaire.

Which is why nearly every modern checkout uses provider-hosted card fields. It is not primarily a user-experience decision. It is a scope-reduction decision.

The safest way to comply with rules about storing gold is to run a business that never has any gold on the premises.
The entire compliance industry is arranged around the ambition of never seeing a card number, which is a strange thing for a card industry to want.

Where you meet it

Invisibly, as a customer. Directly, if you build anything that takes payments, where your provider will ask which self-assessment questionnaire applies to you before you go live.

Get the next one in your inbox.

New fundamentals and one memo every two weeks.

Or subscribe on Substack ↗