Who does PCI DSS apply to

Non-compliance with PCI DSS can result in penalties, violations, and the loss of customer trust, which may be harder to recover.

To prevent these outcomes, itโ€™s crucial to determine whether your business is subject to PCI DSS requirements.

Everything about PCI DSS

Who does PCI DSS apply to?

PCI DSS applies to any business that accepts, processes, stores, or transmits cardholder data, as well as any organization that could affect the security of that data.

The standard classifies businesses into two main groups: merchants and service providers. Below, we explain the key differences between the two.

Questions?

Meet with Matt and book a free 15-min call below to
better understand how to implement PCI DSS compliance in your company

Everything about PCI DSS

PCI DSS for merchants

A merchant is any business that accepts payments via cards from one of the five major credit card networks: American Express, Visa, Mastercard, Discover, and JCB.

Compliance with PCI DSS varies based on your businessโ€™s PCI compliance level, which is determined by the volume of card transactions processed annually and specific requirements set by your acquiring bank.

Hereโ€™s a breakdown of the merchant compliance levels:

โ€ข Level 1: Merchants processing over 6 million card transactions per year
โ€ข Level 2: Merchants processing between 1 million and 6 million transactions per year
โ€ข Level 3: Merchants processing between 20,000 and 1 million transactions per year
โ€ข Level 4: Merchants processing fewer than 20,000 transactions per year

ย 

Everything about PCI DSS

PCI DSS for service providers

A service provider is directly involved with processing, storing, or transmitting cardholder data on behalf of a merchant. A company that provides services that control or could impact the security of cardholder data is also considered a service provider. Common examples of service providers include:
  • Payment processors
  • Managed point of sale (POS) providers
  • Transaction processors
  • Payment gateways
  • Web hosting companies
  • Third-party marketing firms
  • Vendors that perform POS maintenance
  • Vendors that offer managed network firewall solutions
  • There are two compliance levels for service providers, which are determined by the number of transactions they store, process, or transmit.
ย 
Level 1: Service providers that store, process, or transmit more than 300,000 credit card transactions annually Level 2: Service providers that store, process, or transmit fewer than 300,000 credit card transactions annually

There are two compliance levels for service providers, which are determined by the number of transactions they store, process, or transmit.

Level 1: Service providers that store, process, or transmit more than 300,000 credit card transactions annually
Level 2: Service providers that store, process, or transmit fewer than 300,000 credit card transactions annually.

Your service provider level helps dictate the reporting requirements you will need to prove compliance. For example, a Level 1 service provider will undergo annual audits conducted by a QSA to prove compliance, while a Level 2 service provider will complete an annual SAQ D.ย 

Get free advice from experts, in 72h or less

Ask us anything

Send us any question you have, weโ€™ll annonymize it and post an answer in 72h or less on our โ€œAsk us anythingโ€ page.