Skip to content
Ready to get started, Let's Go! Talk to Sales

Glossary

PCI DSS

PCI DSS (Payment Card Industry Data Security Standard) is the security standard, maintained by the PCI Security Standards Council, that every organization storing, processing, or transmitting cardholder data must follow.

PCI DSS applies to everyone in the card payment chain: merchants, processors, gateways, and service providers. The standard covers twelve requirement areas, from network segmentation and encryption to access control, logging, and security testing. It is not a law, but the card networks enforce it through acquirers, and non-compliance after a breach carries fines and can end a company’s ability to process cards.

Levels and validation

Validation requirements scale with transaction volume. Merchant Level 1 (generally over six million card transactions a year, or any entity a network designates) requires an annual on-site assessment by a Qualified Security Assessor producing a Report on Compliance. Lower levels validate through self-assessment questionnaires (SAQs). Service providers, including processors and payment facilitators, have their own two-level scheme; Service Provider Level 1 is the strictest tier, requiring the full annual QSA assessment. Version 4.x of the standard, current since 2024, added requirements around authentication, eCommerce script integrity, and targeted risk analysis.

Why it matters

For most software companies, the goal is scope reduction: architect the payment flow so card data never touches your systems, and your PCI burden collapses from a full audit to a short questionnaire. Tokenization at the point of capture, hosted payment fields, and processor-side vaulting are the standard tools. When evaluating a provider, confirm its own validation level (ask for the Attestation of Compliance) and ask exactly which SAQ your integration pattern will leave you with.

QorPay is a PCI DSS Level 1 certified direct processor, and QorCommerce’s tokenization and hosted capture options are designed to keep partner platforms at the minimal end of PCI scope.

In the docs: PCI DSS compliance guide ↗