Services
Small business
Enterprise solutions
Acquirer & Service Provider solutions
Find out what you need to become PCI compliant
talk to a specialistPath to cybersecurity and compliance
01
Determine your security or compliance framework
PCI DSS, HIPAA, GDPR, HITRUST, CIS Controls, Network Consulting
02
03
04
05
06
07
08
09
![A business owner discusses PCI compliance with her associates](https://cdn.prod.website-files.com/672118d386a0ee61ef1d8ee1/6786db1aee97a040cb20c842_pci-testimonial.png)
We believe that it takes great people to deliver a great product
Everyone's needs are different
We have the tools to help you reach compliance and increase data security.
Resources
The following are related resources that we have prepared for you. Find more answers to your questions in our Learning Center.
PCI DSS Compliance FAQs
What is PCI Compliance?
PCI stands for the Payment Card Industry. In 2006, major payment card brands Visa, MasterCard, American Express, Discover Financial Services, and JCB International established the Payment Card Industry Data Security Standard (PCI DSS). The PCI DSS helps merchants prevent consumer payment card data theft.
Compliance with the PCI DSS or “PCI DSS compliance,” is required for all businesses that process, store, or transmit payment card data. Merchants must complete a PCI DSS compliance form annually. Becoming PCI compliant helps prevent data breaches.
How Do I Get PCI Compliant?
To get PCI compliant, you will need to first determine which self-assessment questionnaire (SAQ) you should follow. Depending on your SAQ, you will need to implement a set of requirements and controls as outlined in the PCI data security standard.
SecurityMetrics assists small to large businesses identify and implement their PCI requirements. Request a quote above for help.
What is an SAQ for PCI Validation?
SAQ stands for self-assessment questionnaire. Depending on an organization’s card transaction volume and the types of transactions it performs, it may be able to use an SAQ to self-evaluate its compliance with the PCI Data Security Standard.
SAQs contain questions about card data security. SAQs range in size from 22 questions (SAQ A) to 329 questions (SAQ D).
What Happens If You Are Not PCI Compliant?
While every organization needs varying policies, training, and documents, there are a few itemized response lists that most organizations should include in their incident response plan, such as:
- Emergency contact/communications list
- System backup and recovery processes list
- Forensic analysis list
- Jump bag list
- Security policy review list
Check out this helpful handout here that goes into more detail about what should be included in your incident response plan.