Compliance

PCI DSS

PCI DSS is the security standard from the card organisations for anyone who stores, processes, or transmits card data.

The Payment Card Industry Data Security Standard (PCI DSS) defines security requirements for everyone who stores, processes, or transmits card data. It is published by the PCI Security Standards Council, which includes the major card organisations.

How it works

The current version 4.0.1 includes twelve main requirements. These include network security, protecting stored cardholder data, access control, logging, and regular testing. The scope of the assessment depends on the transaction volume. Large merchants are assessed by an external auditor, while smaller ones complete a self-assessment questionnaire. The scope is a crucial factor. It covers all systems that come into contact with card data.

For example, a Swiss online retailer stores card numbers in its own database. This brings the database, web server, and many adjacent systems into scope. The retailer then switches to a payment provider that receives the card data directly. The scope reduces significantly, and the requirements become much simpler.

What to look out for

  • Reduce the scope by not storing any card data yourself.
  • Segment systems with card data from the rest of the network.
  • Log access to these systems and analyse the logs regularly.
  • Note the requirements introduced with version 4.0 that have been mandatory since 31 March 2025, such as protecting payment pages against manipulated scripts.

Relevance for Swiss companies

PCI DSS applies to everyone who accepts or processes card payments, including in Switzerland. This affects merchants, hotels, online shops, payment service providers, and banks. The obligation comes from contracts with acquirers and card organisations, not from law.

Relevance for the SOC

PCI DSS requires daily review of security-relevant logs and a response to alerts. Requirements also cover log retention for at least twelve months. Three months of data must be immediately available. A SOC can perform these tasks and provide the necessary evidence.

Typical mistakes

The scope is often larger than assumed because card data appears in logs, emails, or tickets. Another mistake is a flat network, where almost everything falls into scope.

How we implement it

We monitor systems within the PCI scope and provide evidence for log analysis and incident handling. Compliance with the standard remains your responsibility.

How ANOMAL implements this