PCI DSS compliance

Payments fundamentals

To help prevent fraud and to protect cardholder data, the card brands created the Payment Card Industry Data Security Standard (PCI DSS). PCI DSS is a set of security requirements that affects all businesses that store, process, or transmit cardholder data. 

PCI DSS requires you to:

  • Build and maintain secure systems.
  • Protect cardholder data.
  • Protect your systems from malware.
  • Control who can access cardholder data and systems.
  • Monitor and test your systems regularly.
  • Set and maintain clear security rules for your business.

Benefits of PCI compliance

When you comply with PCI DSS, you:

  • Reduce the risk of data breaches.
  • Protect your customers’ cardholder data.
  • Protect your business’s reputation.
  • Avoid non-compliance fees.

Consequences of PCI non-compliance

If you don't comply with PCI DSS, you increase the risk of:

  • Cardholder data breaches
  • Financial losses due to fraud incidents
  • Damage to your business’s reputation
  • Restrictions on your ability to process card payments
  • Non-compliance fees

Note: Payroc charges a non-compliance fee for every month that you don’t comply. For more information about the fee, go to PCI compliance fees

 

How to comply with PCI DSS

We automatically provide you with access to SecureTrust’s PCI Manager, which guides you through the steps you need to take to achieve and maintain PCI DSS compliance. 

You can use the PCI Manager to complete Self-Assessment Questionnaires (SAQs) and run vulnerability scans and penetration tests on your network. 

For more information about how to use the PCI Manager, go to SecureTrust PCI Manager