Blog Login
Compliance

PCI DSS Compliance for Fintechs: What You Need to Know

A

Anzar Dewani

2 hours ago

The Payment Card Industry Data Security Standard (PCI DSS) applies to any fintech that stores, processes, or transmits cardholder data. This guide explains the PCI DSS requirements, merchant levels, validation methods, and how to build a compliant card data security program.

PCI DSS Compliance for Fintechs: What You Need to Know

Any fintech that stores, processes, or transmits payment card data — whether accepting card payments, issuing cards, or providing payment processing infrastructure — is subject to the Payment Card Industry Data Security Standard (PCI DSS). PCI DSS is not a government regulation; it is a security standard established by the PCI Security Standards Council (PCI SSC), a body founded by the major card networks (Visa, Mastercard, American Express, Discover, and JCB). Compliance with PCI DSS is contractually required by card network rules and is enforced by acquiring banks.

What Is PCI DSS?

The Payment Card Industry Data Security Standard is a set of security requirements designed to protect cardholder data — the sensitive payment card information that must be secured to prevent fraud and data breaches. PCI DSS v4.0, the current version of the standard, was released by the PCI SSC and represents the most comprehensive update to the standard in years. The PCI SSC publishes PCI DSS documentation at pcisecuritystandards.org — fintechs should consult the official standard for complete requirements.

PCI DSS applies to any entity that stores, processes, or transmits cardholder data — including the primary account number (PAN), cardholder name, expiration date, and service code. The standard also covers sensitive authentication data (CVV/CVC codes, PIN data) which must not be stored after authorization.

Who Does PCI DSS Apply To?

PCI DSS applies to any organization that handles cardholder data, including:

  • Merchants: Any fintech that accepts card payments for goods or services
  • Service providers: Fintechs that process, store, or transmit cardholder data on behalf of merchants or issuers — including payment processors, gateways, and cloud providers that handle card data
  • Issuers: Fintechs that issue payment cards or manage card programs

The scope of PCI DSS compliance is determined by the cardholder data environment (CDE) — the systems, people, and processes that store, process, or transmit cardholder data, or that could impact the security of that data. Reducing the scope of the CDE (for example, by tokenizing card data and outsourcing payment processing) is a key strategy for minimizing PCI DSS compliance burden.

PCI DSS Merchant Levels

Card networks and acquiring banks assign merchants to one of four levels based on annual transaction volume. Each level has different validation requirements:

  • Level 1: Merchants processing more than 6 million card transactions annually — requires an annual on-site assessment by a Qualified Security Assessor (QSA) and quarterly network scans by an Approved Scanning Vendor (ASV)
  • Level 2: 1–6 million transactions annually — requires an annual Self-Assessment Questionnaire (SAQ) and quarterly ASV scans
  • Level 3: 20,000–1 million e-commerce transactions annually — requires an annual SAQ and quarterly ASV scans
  • Level 4: Fewer than 20,000 e-commerce transactions or up to 1 million total transactions annually — SAQ and ASV scans may be required at the acquiring bank's discretion

Service providers have their own level structure separate from merchants. Fintechs should confirm their level and validation requirements with their acquiring bank.

The 12 PCI DSS Requirements

PCI DSS v4.0 organizes its requirements around six goals, implemented through 12 core requirements:

  1. Install and maintain network security controls
  2. Apply secure configurations to all system components
  3. Protect stored account data
  4. Protect cardholder data with strong cryptography during transmission over open, public networks
  5. Protect all systems and networks from malicious software
  6. Develop and maintain secure systems and software
  7. Restrict access to system components and cardholder data by business need to know
  8. Identify users and authenticate access to system components
  9. Restrict physical access to cardholder data
  10. Log and monitor all access to system components and cardholder data
  11. Test security of systems and networks regularly
  12. Support information security with organizational policies and programs

How Fintechs Minimize PCI DSS Scope

The most effective strategy for reducing PCI DSS compliance burden is reducing cardholder data scope:

  • Tokenization: Replacing card numbers with tokens so that the fintech never handles the actual PAN. Tokens are useless to attackers even if compromised.
  • Point-to-point encryption (P2PE): Encrypting card data at the point of capture so it never traverses the fintech's systems in clear text
  • Outsourcing to PCI-compliant processors: Using a PCI-validated payment gateway or processor so that card data is handled by a compliant third party
  • Hosted payment pages: Redirecting card entry to a third-party hosted page so card data never touches the fintech's infrastructure

PCI DSS and Third-Party Service Providers

Fintechs must ensure that their service providers who handle cardholder data are also PCI DSS compliant. This requires maintaining a list of third parties with access to cardholder data, verifying their PCI compliance status annually, and including PCI DSS obligations in vendor contracts. The PCI SSC maintains a list of validated third-party service providers.

Frequently Asked Questions

Is PCI DSS a legal requirement?

PCI DSS is not a federal or state law — it is a contractual requirement imposed by card network rules and enforced by acquiring banks. However, several states have enacted laws that incorporate PCI DSS standards or provide liability protections for PCI-compliant merchants. Non-compliance can result in fines from card networks, increased transaction fees, and loss of the ability to accept card payments.

What is a QSA?

A Qualified Security Assessor is a company certified by the PCI SSC to conduct PCI DSS assessments. Level 1 merchants and service providers typically require an annual assessment by a QSA. The PCI SSC maintains a list of approved QSAs at pcisecuritystandards.org.

What is a Self-Assessment Questionnaire (SAQ)?

The SAQ is a self-validation tool for merchants and service providers who do not require a QSA assessment. Multiple SAQ types exist for different payment environments — the correct SAQ depends on how a fintech handles card data (card-present, card-not-present, fully outsourced, etc.).

What happens if a fintech suffers a data breach involving card data?

A data breach involving cardholder data triggers significant obligations — including notification to the acquiring bank and card networks, a forensic investigation, remediation, and potential fines from card networks. PCI DSS non-compliance at the time of a breach typically results in substantially higher fines than for a compliant entity.

 

This article is for educational purposes only and does not constitute legal or compliance advice. PCI DSS requirements are maintained by the PCI Security Standards Council and are subject to update. Consult a Qualified Security Assessor and legal counsel for guidance specific to your fintech.

 

Talk to the ComplyOne team to get started.

Share this article:

Related Articles