December 7, 2023

To whom does PCI DSS Apply?

Created by the PCI Security Standards Council (PCI-SSC), the Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards meant to protect payment transaction systems from security issues and breaches.

By
Full name
Share this post
https://www.hicomply.com/hub/pci-dss-to-whom-does-pci-dss-apply
A woman smiles while using a tablet, surrounded by digital notifications and a data chart.

{{snapshot}}

Who PCI DSS applies to

  • Anyone handling cardholder data — any business that stores, transmits, or processes it, including merchants, issuers, acquirers, and processors.
  • It applies if you accept credit, debit, or prepayment cards in any way, regardless of whether you store the data.
  • It protects sensitive data including CVV, Card Number, and PAN, so cloud-based firms using third-party payment vendors must ensure those vendors are compliant too.

{{/snapshot}}

What does PCI DSS apply to?

These standards apply to a great number of businesses and organisations involved in processing cardholder data, and there are consequences if your company is found to be non-compliant.

Who does PCI DSS apply to?

PCI DSS compliance is mandatory for any business or organisation responsible for storing, transmitting, or processing any cardholder data. This covers a wide range of different entities and industries, so it’s important to make sure that your organisation remains compliant with the requirements.

Most businesses involved are merchants, issuers, acquirers, and processors. Essentially, PCI DSS applies to you if you accept credit, debit, or prepayment cards in any way, regardless of whether you store the data.

Equally, if your company collects sensitive authentication data that falls under data retention requirements, you will also need to be PCI DSS compliant. The PCI DSS protects cardholder data including CVV, Card Number, PAN, and other pieces of vulnerable information that a hacker could gain access to.

If your company is cloud-based and uses third-party vendors to outsource payment card processing, it’s important to ensure that both the payment process and the third parties are aware of the PCI DSS compliance requirements. It’s worth noting that, when applied properly, this process does reduce the risk of a breach.

{{snapshot}}

Compliance is mandatory

  • PCI DSS compliance is required by contract, usually imposed by the credit card companies as a condition of doing business.
  • It is non-negotiable and applies whether you are a small business or a large enterprise handling card data.
  • Companies found non-compliant may face PCI DSS fines and penalties.

{{/snapshot}}

Is PCI DSS compliance mandatory?

It doesn’t matter whether your business is an enterprise or a big organisation – if you handle card data in your processes, you are required by contract to be PCI DSS compliant. The contract is usually provided by credit card businesses that require compliance to reach an agreement. This is non-negotiable, and if your company is found non-compliant, then you may face one of the PCI DSS fines and penalties.

What does PCI DSS apply to merchants?

If your business accepts credit cards from one of the core five credit card companies – American Express, Visa, Mastercard, Discover, and JCB – then you are considered a merchant.

Based on the number of card transactions your business has in any given year, your company will be given a ‘level’ by the PCI that determines the specific requirements you will have to follow according to your bank. The levels are as follows:

Merchant levelAnnual card transactions
Level 1Over 6 million
Level 21 million to 6 million
Level 320,000 to 1 million
Level 4Fewer than 20,000

{{snapshot}}

Service providers in scope

  • Third parties that process, store, or transmit cardholder data for a merchant must also follow PCI DSS.
  • This includes web hosting firms, payment processors and gateways, POS providers, transaction processors, and managed firewall vendors.
  • Providers are split into two levels: Level 1 handles over 300,000 transactions a year, Level 2 fewer than 300,000.

{{/snapshot}}

What does PCI DSS apply to service providers?

PCI DSS also applies to service providers who act as third parties to process, store, or transmit sensitive cardholder data for a merchant. Any company involved in the handling or control of the data needs to follow PCI DSS requirements to ensure the security surrounding customer’s data is watertight during the whole process.

Service providers include:

  • Web hosting companies
  • Third-party marketing companies
  • Payment processors and gateways
  • Point of sale (POS) providers
  • Transaction processors
  • Vendors that perform POS maintenance or offer managed network firewall solutions.

As with merchants, service providers are separated into different ‘levels’ based on the number of transactions they are involved in. These levels determine which requirements the provider needs to follow to remain compliant.

  • Level 1 covers service providers storing, processing, or transmitting over 300,000 credit card transactions a year.
  • Level 2 covers service providers storing, processing, or transmitting fewer than 300,000 credit card transactions a year.

{{snapshot}}

What Hicomply recommends

Scope is the first thing to get right with PCI DSS: map exactly where cardholder data flows across your merchants and service providers before you start collecting evidence, because the levels above set very different requirements. We find teams stay audit-ready when they treat PCI alongside their wider PCI DSS programme rather than as a one-off. A platform tour shows how a single ISMS keeps that scope and evidence current, and our free compliance tools help you get started.

{{/snapshot}}

Stay in the know on PCI DSS compliance with Hicomply

If your company or organization needs to receive PCI DSS certification, it can be daunting to know where to start and keep track. The road to compliance is long and can be overwhelming, which is why Hicomply has aimed to streamline the process.

Our full-service ISMS platform keeps all the documentation your business needs in one place, making organisation a breeze. Contact us now for more information.

Risk Management
Compliance Reporting
Policy Management
Incident Management
Audits and Assessments

Ready to Take Control of Your Privacy Compliance?

See how Hicomply can accelerate your path to CAF compliance in a 15-minute demo.

Risk Management

Identify, assess, and mitigate security risks with an integrated risk register.Hicomply’s automated risk management software maps controls across ISO 27001, SOC 2, and NIST frameworks — helping teams track risk treatment plans, assign ownership, and monitor real-time compliance status. Build a resilient ISMS that reduces audit findings and demonstrates continuous improvement.

Compliance Reporting

Generate instant, audit-ready compliance reports across multiple frameworks — from ISO 27001 and SOC 2 to GDPR, DORA, and NHS DSPT.Automated evidence collection and built-in dashboards provide a single source of truth for your compliance posture, saving weeks of manual work during audits.

Policy Management

Centralise, version, and publish all your information security policies in one place.Hicomply automates approvals, reminders, and distribution, ensuring your ISMS documentation stays current and aligned with frameworks like ISO 42001 and NIST CSF.Say goodbye to outdated PDFs — manage policies dynamically and maintain full traceability.

Incident Management

Capture, investigate, and resolve security incidents with structured workflows and automated evidence trails.Hicomply integrates with ticketing tools like Jira, Zendesk, and Azure DevOps to streamline incident response and link findings to risk and control updates — a key step for SOC 2 Type II readiness.

Audits and Assessments

Simplify internal and external audit preparation with built-in audit templates and automated task assignments.
Hicomply’s audit management platform aligns with ISO 27001, ISO 9001, and ISO 14001, giving teams a clear overview of control effectiveness, audit evidence, and corrective actions — all from one dashboard.

Getting Started
IT and Services
Enterprise