
FINANCIAL SERVICES & COMPLIANCE PRACTICE
PCI DSS Compliance
Payment Data Protection, Certification and Compliance.
ABSTRACT
The Payment Card Industry Data Security Standard (PCI DSS) is the global security standard defined by the PCI Security Standards Council (founded by Visa, Mastercard, American Express, Discover and JCB) to protect cardholder data (CHD) and sensitive authentication data (SAD) wherever they are stored, processed or transmitted. It applies to every player in the payment chain, not only banks: merchants, service providers, processors, issuers and acquirers. PCI DSS was born as the industry response to escalating card fraud, when the five card brands unified their separate security programs into one global standard. The threat keeps growing: click rates on phishing attacks are up 54%, phishing drives 30 to 42% of global breaches, 68% of corporate breaches still involve the human factor, and the average breach costs USD 4.88M, taking 241 to 277 days to identify and contain. The current version, PCI DSS v4.0.1 (June 2024, sole active version since 1 January 2025), comprises 12 requirements across 6 control objectives: from network security and encryption to access control, monitoring and governance. Since 31 March 2025, all future-dated v4 requirements are fully mandatory.


WHO MUST COMPLY
Merchants
| LEVEL | CRITERIA (ANNUAL VOLUME) | VALIDATION | TYPICAL CLIENT SEGMENT |
|---|---|---|---|
| Level 1 | Over 6M transactions (any channel), or any merchant post-breach | External audit by a certified assessor, plus quarterly internal and external vulnerability scans by a certified scanning vendor | Large retail, e-commerce platforms, airlines, hospitality groups, GDO |
| Level 2 | 1M to 6M transactions | Annual self-assessment questionnaire (for Mastercard, validated by a certified assessor), plus quarterly external scans | Mid-size retail chains, established e-commerce |
| Level 3 | 20K to 1M e-commerce transactions | Annual self-assessment questionnaire, plus quarterly external scans | Growing online businesses, digital services |
| Level 4 | Under 20K e-commerce, or up to 1M total | Annual self-assessment questionnaire and scans, as required by the acquirer | SMEs, local retail, restaurants, hotels |
CRITERIA (ANNUAL VOLUME)
Over 6M transactions (any channel), or any merchant post-breach
VALIDATION
External audit by a certified assessor, plus quarterly internal and external vulnerability scans by a certified scanning vendor
TYPICAL CLIENT SEGMENT
Large retail, e-commerce platforms, airlines, hospitality groups, GDO
CRITERIA (ANNUAL VOLUME)
1M to 6M transactions
VALIDATION
Annual self-assessment questionnaire (for Mastercard, validated by a certified assessor), plus quarterly external scans
TYPICAL CLIENT SEGMENT
Mid-size retail chains, established e-commerce
CRITERIA (ANNUAL VOLUME)
20K to 1M e-commerce transactions
VALIDATION
Annual self-assessment questionnaire, plus quarterly external scans
TYPICAL CLIENT SEGMENT
Growing online businesses, digital services
CRITERIA (ANNUAL VOLUME)
Under 20K e-commerce, or up to 1M total
VALIDATION
Annual self-assessment questionnaire and scans, as required by the acquirer
TYPICAL CLIENT SEGMENT
SMEs, local retail, restaurants, hotels
Service Providers and Processors
| LEVEL | CRITERIA (ANNUAL VOLUME) | VALIDATION | TYPICAL CLIENT SEGMENT |
|---|---|---|---|
| Level 1 | Over 300K transactions, or any provider designated Level 1 by the card brands | External audit by a certified assessor, plus quarterly scans by a certified scanning vendor. Enables listing on the Visa Global Registry and Mastercard SDP list. | PSPs, gateways, processors, tokenization and hosting providers |
| Level 2 | Under 300K transactions | Annual self-assessment questionnaire, plus quarterly external scans | Fintech, IT providers with CDE access, smaller PSPs |
CRITERIA (ANNUAL VOLUME)
Over 300K transactions, or any provider designated Level 1 by the card brands
VALIDATION
External audit by a certified assessor, plus quarterly scans by a certified scanning vendor. Enables listing on the Visa Global Registry and Mastercard SDP list.
TYPICAL CLIENT SEGMENT
PSPs, gateways, processors, tokenization and hosting providers
CRITERIA (ANNUAL VOLUME)
Under 300K transactions
VALIDATION
Annual self-assessment questionnaire, plus quarterly external scans
TYPICAL CLIENT SEGMENT
Fintech, IT providers with CDE access, smaller PSPs
Issuers and Acquirers (Required)
Issuers
Card-issuing banks are direct members of the card schemes, so PCI DSS compliance is mandatory by membership: no volume-based levels apply. Validation follows each card brand's member rules, typically through an annual attestation of compliance supported by evidence available on request. Issuers must protect all stored account data, including sensitive data legitimately retained for issuing purposes, and may only engage service providers that are themselves PCI DSS compliant.
Acquirers
Acquiring banks are direct members of the card schemes and must be PCI DSS compliant by membership, with an additional layer of responsibility: they are accountable to the card brands for the compliance of their entire merchant portfolio. In practice, acquirers assign each merchant its compliance level, collect self-assessment questionnaires, external audit reports and attestations of compliance and report portfolio status to the card brands. Fines for non-compliant merchants are charged to the acquirer, who typically passes them on to the merchant.

THE FORFIRM SERVICE
Scope Identification
Definition of the Cardholder Data Environment (CDE), mapping of card data flows, segmentation review and scope-reduction opportunities to cut cost and effort.
Audit
Gap analysis against the 12 PCI DSS v4.0.1 requirements, prioritized remediation roadmap, and the formal on-site assessment.
ROC and PCI DSS Certification
Report on Compliance (ROC) and Attestation of Compliance (AOC), support with acquiring banks and card brands, annual renewal, quarterly ASV scans and continuous compliance monitoring.
WHY FORFIRM
Swiss-Based Delivery. FORFIRM is the first Swiss company authorized to perform, through its own Auditors, certifications in the PCIDSS domain. Offices in Lugano and Zürich.
Your data stays in Switzerland. Assessment materials and evidence handled locally, under Swiss confidentiality standards.
Proximity. Assessment activities conducted under Swiss confidentiality standards with local presence and multilingual support.
Swiss regulatory fluency. PCI DSS Certified Professionals.
Expertise across FINMA expectations, DORA and the Swiss financial ecosystem.
Consumer trust, less fraud. Certified payment security strengthens customer confidence and measurably reduces fraud exposure.

Book Your Assessment
First certification or renewal: schedule a meeting with our PCI DSS Professionals.
Book Your Assessment