PCI DSS

The contractual security standard for organizations handling payment card data, maintained by the PCI Security Standards Council, with 12 requirement areas.

PCI DSS (Payment Card Industry Data Security Standard) is the contractual security standard for organizations that store, process or transmit payment card data, maintained by the PCI Security Standards Council. It is enforced through the card networks and acquirers rather than by law, with 12 requirement areas covering everything from network segmentation to security testing.

Key facts:

Email's role in card security

Card data does not belong in email, but attackers do not care about scope diagrams: phishing is a standard route to the credentials and systems that reach cardholder data environments, which is why current versions of the standard explicitly address phishing protection and security awareness. And every pasted card number in a support mailbox silently expands PCI scope. Social engineering against payment teams is a persistent adjacent risk.

Where email security fits, honestly

Sentaro supports the anti-phishing requirements and protects the credentials that gate cardholder data environments, with detection and evidence for the incident response requirements. Segmentation, scans, questionnaires and the assessment itself remain yours, as does keeping card data out of mailboxes in the first place. Vendors also carrying SOC 2 or ISO 27001 often reuse the same control evidence across all three.

This page is general guidance, not legal advice.

Frequently asked questions

What is PCI DSS in simple terms?

The card industry's security standard: any organization handling payment card data must meet its requirements, enforced through contracts with banks and card networks.

Is PCI DSS a law?

No, it is contractual, but non-compliance can mean fines from acquirers, higher fees or losing the ability to process cards, and breaches bring liability.

Does PCI DSS require phishing protection?

Current versions include explicit anti-phishing expectations alongside awareness training, reflecting that phishing is a primary route into cardholder data environments (verify wording against the current standard).

How do we reduce PCI scope?

Keep card data out of as many systems as possible: tokenization, hosted payment pages, and policies plus monitoring that keep card numbers out of email and chat.