How it works
PCI DSS (Payment Card Industry Data Security Standard) is maintained by the PCI Security Standards Council, founded by Visa, Mastercard, American Express, Discover and JCB. It covers network security, encryption, access control, logging and regular testing. Large merchants and payment companies are assessed by auditors every year, while smaller merchants fill in a self-assessment questionnaire (SAQ).
The simplest way to comply is never to see card numbers. With a hosted checkout, a redirect, or card fields that load from the gateway inside an iframe (Stripe Elements, Razorpay Checkout), card data goes straight to the gateway, and the site usually qualifies for the shortest questionnaire, SAQ A. A home-made card form that posts to your own server pulls that whole server into scope.
India goes further: since October 2022, RBI rules have barred merchants from storing card numbers at all. Saved cards work through network tokens, stand-in numbers issued by the card networks that only work for that merchant.
Related terms
More in Payments
Rules and paperwork