← Glossary

PCI DSS

The contractual security standard for organizations handling payment card data, maintained by the PCI Security Standards Council, with 12 requirement areas.

Updated

PCI DSS (Payment Card Industry Data Security Standard) is the contractual security standard for organizations that store, process or transmit payment card data, maintained by the PCI Security Standards Council. It is enforced through the card networks and acquirers rather than by law, with 12 requirement areas covering everything from network segmentation to security testing.

Key facts:

  • Applicability follows the card data: even small merchants have obligations, scaled through assessment levels from self-assessment questionnaires to on-site QSA audits.
  • PCI DSS v4.x tightened requirements on authentication, targeted risk analysis and anti-phishing measures (verify version specifics at pcisecuritystandards.org).
  • The most effective PCI strategy is scope reduction: keeping card data out of systems, including mailboxes, shrinks what the standard touches.

Email's role in card security

Card data does not belong in email, but attackers do not care about scope diagrams: phishing is a standard route to the credentials and systems that reach cardholder data environments, which is why current versions of the standard explicitly address phishing protection and security awareness. And every pasted card number in a support mailbox silently expands PCI scope. Social engineering against payment teams is a persistent adjacent risk.

Where email security fits, honestly

Sentaro supports the anti-phishing requirements and protects the credentials that gate cardholder data environments, with detection and evidence for the incident response requirements. Segmentation, scans, questionnaires and the assessment itself remain yours, as does keeping card data out of mailboxes in the first place. Vendors also carrying SOC 2 or ISO 27001 often reuse the same control evidence across all three.

This page is general guidance, not legal advice.

Questions we get asked.

What is PCI DSS in simple terms?

The card industry's security standard: any organization handling payment card data must meet its requirements, enforced through contracts with banks and card networks.

Is PCI DSS a law?

No, it is contractual, but non-compliance can mean fines from acquirers, higher fees or losing the ability to process cards, and breaches bring liability.

Does PCI DSS require phishing protection?

Current versions include explicit anti-phishing expectations alongside awareness training, reflecting that phishing is a primary route into cardholder data environments (verify wording against the current standard).

How do we reduce PCI scope?

Keep card data out of as many systems as possible: tokenization, hosted payment pages, and policies plus monitoring that keep card numbers out of email and chat.

Stop reading about it. Watch it get blocked.

Free for one account. Four minutes to connect.