Cookies & Privacy

We use cookies to keep the site working, understand how it is used and improve your experience. You can accept all or choose which ones to enable.Cookie Policy.

FINANCIAL SERVICES & COMPLIANCE PRACTICE

PCI DSS Compliance

Payment Data Protection, Certification and Compliance.

ABSTRACT

The Payment Card Industry Data Security Standard (PCI DSS) is the global security standard defined by the PCI Security Standards Council (founded by Visa, Mastercard, American Express, Discover and JCB) to protect cardholder data (CHD) and sensitive authentication data (SAD) wherever they are stored, processed or transmitted. It applies to every player in the payment chain, not only banks: merchants, service providers, processors, issuers and acquirers. PCI DSS was born as the industry response to escalating card fraud, when the five card brands unified their separate security programs into one global standard. The threat keeps growing: click rates on phishing attacks are up 54%, phishing drives 30 to 42% of global breaches, 68% of corporate breaches still involve the human factor, and the average breach costs USD 4.88M, taking 241 to 277 days to identify and contain. The current version, PCI DSS v4.0.1 (June 2024, sole active version since 1 January 2025), comprises 12 requirements across 6 control objectives: from network security and encryption to access control, monitoring and governance. Since 31 March 2025, all future-dated v4 requirements are fully mandatory.

PCI DSS Certified

WHO MUST COMPLY

Merchants

Level 1

CRITERIA (ANNUAL VOLUME)

Over 6M transactions (any channel), or any merchant post-breach

VALIDATION

External audit by a certified assessor, plus quarterly internal and external vulnerability scans by a certified scanning vendor

TYPICAL CLIENT SEGMENT

Large retail, e-commerce platforms, airlines, hospitality groups, GDO

Level 2

CRITERIA (ANNUAL VOLUME)

1M to 6M transactions

VALIDATION

Annual self-assessment questionnaire (for Mastercard, validated by a certified assessor), plus quarterly external scans

TYPICAL CLIENT SEGMENT

Mid-size retail chains, established e-commerce

Level 3

CRITERIA (ANNUAL VOLUME)

20K to 1M e-commerce transactions

VALIDATION

Annual self-assessment questionnaire, plus quarterly external scans

TYPICAL CLIENT SEGMENT

Growing online businesses, digital services

Level 4

CRITERIA (ANNUAL VOLUME)

Under 20K e-commerce, or up to 1M total

VALIDATION

Annual self-assessment questionnaire and scans, as required by the acquirer

TYPICAL CLIENT SEGMENT

SMEs, local retail, restaurants, hotels

Service Providers and Processors

Level 1

CRITERIA (ANNUAL VOLUME)

Over 300K transactions, or any provider designated Level 1 by the card brands

VALIDATION

External audit by a certified assessor, plus quarterly scans by a certified scanning vendor. Enables listing on the Visa Global Registry and Mastercard SDP list.

TYPICAL CLIENT SEGMENT

PSPs, gateways, processors, tokenization and hosting providers

Level 2

CRITERIA (ANNUAL VOLUME)

Under 300K transactions

VALIDATION

Annual self-assessment questionnaire, plus quarterly external scans

TYPICAL CLIENT SEGMENT

Fintech, IT providers with CDE access, smaller PSPs

Issuers and Acquirers (Required)

Issuers

Card-issuing banks are direct members of the card schemes, so PCI DSS compliance is mandatory by membership: no volume-based levels apply. Validation follows each card brand's member rules, typically through an annual attestation of compliance supported by evidence available on request. Issuers must protect all stored account data, including sensitive data legitimately retained for issuing purposes, and may only engage service providers that are themselves PCI DSS compliant.

Acquirers

Acquiring banks are direct members of the card schemes and must be PCI DSS compliant by membership, with an additional layer of responsibility: they are accountable to the card brands for the compliance of their entire merchant portfolio. In practice, acquirers assign each merchant its compliance level, collect self-assessment questionnaires, external audit reports and attestations of compliance and report portfolio status to the card brands. Fines for non-compliant merchants are charged to the acquirer, who typically passes them on to the merchant.

THE FORFIRM SERVICE

1

Scope Identification

Definition of the Cardholder Data Environment (CDE), mapping of card data flows, segmentation review and scope-reduction opportunities to cut cost and effort.

2

Audit

Gap analysis against the 12 PCI DSS v4.0.1 requirements, prioritized remediation roadmap, and the formal on-site assessment.

3

ROC and PCI DSS Certification

Report on Compliance (ROC) and Attestation of Compliance (AOC), support with acquiring banks and card brands, annual renewal, quarterly ASV scans and continuous compliance monitoring.

WHY FORFIRM

Swiss-Based Delivery. FORFIRM is the first Swiss company authorized to perform, through its own Auditors, certifications in the PCIDSS domain. Offices in Lugano and Zürich.

Your data stays in Switzerland. Assessment materials and evidence handled locally, under Swiss confidentiality standards.

Proximity. Assessment activities conducted under Swiss confidentiality standards with local presence and multilingual support.

Swiss regulatory fluency. PCI DSS Certified Professionals.

Expertise across FINMA expectations, DORA and the Swiss financial ecosystem.

Consumer trust, less fraud. Certified payment security strengthens customer confidence and measurably reduces fraud exposure.

Book Your Assessment

First certification or renewal: schedule a meeting with our PCI DSS Professionals.

Book Your Assessment