How to comply with PCI DSS

PCI DSS is the leading security standard for safeguarding cardholder data from breaches, but its strict requirements can make certification feel overwhelming, especially for first-timers.

Where do you start? What policies and controls are necessary? And if an audit is required, how can you be sure youโ€™re ready?

By understanding the PCI certification process, you can better prepare for a successful audit or self-assessment. To help, weโ€™ll break down each step of the process below.

PCI DSS compliance process overview:

Steps

Process Description

Step 1

Identify the level of compliance needs

PCI DSS has varying levels depending on the organization size, number of transactions, and customer size.

Step 2

Complete a readiness assessment

After implementing controls, undergo a readiness assessment with a company specialised in PCI DSS

Step 3

Complete an SAQ or RoC

A Self assessment Questionnaire or Report on Compliance is required – depending on your level of compliance

Step 4

Maintain Certification

To maintain compliance, complete SAQ or RoC annually.

Questions?

Meet with Matt and book a free 15-min call below to
better understand how to implement PCI DSS compliance in your company

More details:

Organization Size
2. Annual Credit Card Transactions
3. Requirements from Customers or Acquiring Banks

The first step toward certification is identifying your required compliance level.

Typically, the entity requesting your complianceโ€”whether customers, acquiring banks, or credit card companiesโ€”will specify if you need to complete a Report on Compliance (RoC) or a Self-Assessment Questionnaire (SAQ).

If no specific request is made, use these guidelines to determine your compliance level.

Step 1: Are you a merchant or a service provider?

โ€ข Merchants accept card payments in exchange for goods or services, like e-commerce businesses.
โ€ข Service Providers process payments on behalf of other companies.

Step 2: Determine your annual transaction volume.

For merchants:

โ€ข Level 1: Over 6 million transactions
โ€ข Level 2: 1-6 million transactions
โ€ข Level 3: 20,000 - 1 million transactions
โ€ข Level 4: Fewer than 20,000 transactions

For service providers:

โ€ข Level 1: Over 300,000 transactions
โ€ข Level 2: Fewer than 300,000 transactions

Organizations at Merchant Level 1 and Service Provider Level 1 must complete a PCI-RoC. If you do not meet these criteria, an SAQ is required.

The SAQ consists of two main components:

1. A set of self-guided questions assessing your compliance level.
2. An Attestation of Compliance (AoC), in which you confirm your qualification and completion of the SAQ.

In some cases, depending on your compliance level, a Qualified Security Assessor (QSA) firm may be needed to attest to your SAQ results.

To prepare for an assessment, ensure that all necessary policies, procedures, and controls are established and consistently followed throughout the audit period. Additionally, youโ€™ll need to conduct an ASV scan and a penetration test.

At this stage, many organizations choose to complete a readiness assessment with a Qualified Security Assessor (QSA) or with Benchmarked. This PCI DSS expert will evaluate whether your scope, controls, and processes are audit-ready.

If you are a Level 1 Merchant or Service Provider, youโ€™re required to complete an annual Report on Compliance (RoC). This is an external audit performed by a QSA. The QSA will review your policies, processes, controls, and evidence to decide if you meet PCI DSS requirements.

If you do not need a Report on Compliance (RoC), youโ€™ll fill out an SAQ. This questionnaire covers each requirement, the expected testing, and asks if the control is:

In place
In place with a compensating control (Compensating controls may be considered when an entity cannot meet a requirement explicitly as stated, due to legitimate technical or documented business constraints, but has sufficiently mitigated the risk associated with the requirement through implementation of other controls.)
Not in place
N/A
Not tested

Both the RoC and AoC are valid for one year. To maintain certification, youโ€™ll need to complete an RoC or SAQ and AoC annually.

Here are some other periodic tasks youโ€™ll need to plan on throughout the year to maintain your PCI certification:

  • Daily tasks: Review logs and any alerts to identify anomalies or suspicious activity.
  • Weekly tasks: File integrity monitoring scans (with critical file comparisons) must be run at least weekly.
  • Monthly tasks: Install any vendor-supplied security patches to keep system components and software protected from known vulnerabilities.
  • Quarterly tasks: Review user access, scan for unauthorized wireless networks, and verify that data outside of the retention period has been deleted. You will also need to conduct vulnerability scans with an Approved Scanning Vendor (ASV).
  • Biannual tasks: Review firewall and router configurations.
  • Annual tasks: Review and re-approve policies, required employees to acknowledge the Information Security Policy, and conduct a risk assessment and pen test. Secure code training for developers and security awareness training for employees should also be completed.