Skip to main content
PCI DSS (Payment Card Industry Data Security Standard) is a global security standard for organizations that handle credit card data. It is managed by the PCI Security Standards Council and applies to any entity that stores, processes, or transmits cardholder data.
DSALTA supports both PCI DSS 3.2.1 and PCI DSS 4.0.1. Version 4.0.1 is the current standard, with version 3.2.1 being phased out.

Who needs PCI DSS?

Payment processors

Any organization that accepts, processes, stores, or transmits credit card information.

E-commerce & SaaS

Online businesses, subscription platforms, and any software that touches payment data directly or through third-party integrations.

12 PCI DSS requirements

PCI DSS 3.2.1 vs 4.0.1

How DSALTA helps

  • Controls mapped to all 12 PCI DSS requirements
  • Automated evidence collection for network and access controls
  • Policy templates for PCI-required documentation
  • Vendor risk management for payment service providers
  • Dual version support — manage both 3.2.1 and 4.0.1 simultaneously during transition

Frequently asked questions

Use PCI DSS 4.0.1 for new implementations. If you are currently on 3.2.1, plan your transition as the older version is being phased out.
Using a third-party payment processor reduces your scope but does not eliminate PCI DSS requirements entirely. You still need to complete a Self-Assessment Questionnaire (SAQ).
Levels 1–4 are based on annual transaction volume. Level 1 (over 6 million transactions) requires an on-site audit. Levels 2–4 can use self-assessment questionnaires.

How DSALTA automates this

364 of DSALTA’s automated checks contribute evidence to this framework, drawn from 73 integrations. Browse them in the Compliance Tests catalog. They are linked through the controls each check satisfies, so a single check usually contributes to several frameworks at once — the count is not a list of checks unique to this one.