Skip to main content
PCI DSS (Payment Card Industry Data Security Standard) is a global security standard for organizations that handle credit card data. It is managed by the PCI Security Standards Council and applies to any entity that stores, processes, or transmits cardholder data.
DSALTA supports both PCI DSS 3.2.1 and PCI DSS 4.0.1. Version 4.0.1 is the current standard, with version 3.2.1 being phased out.

Who needs PCI DSS?

Payment processors

Any organization that accepts, processes, stores, or transmits credit card information.

E-commerce & SaaS

Online businesses, subscription platforms, and any software that touches payment data directly or through third-party integrations.

12 PCI DSS requirements

#Requirement
1Install and maintain network security controls
2Apply secure configurations to all system components
3Protect stored account data
4Protect cardholder data with strong cryptography during transmission
5Protect all systems and networks from malicious software
6Develop and maintain secure systems and software
7Restrict access to system components by business need-to-know
8Identify users and authenticate access to system components
9Restrict physical access to cardholder data
10Log and monitor all access to system components and cardholder data
11Test security of systems and networks regularly
12Support information security with organizational policies and programs

PCI DSS 3.2.1 vs 4.0.1

v3.2.1v4.0.1
StatusLegacy — being retiredCurrent standard
ApproachPrescriptive requirementsCustomized approach option added
Key changesEnhanced authentication (MFA everywhere), targeted risk analysis, stronger encryption requirements

How DSALTA helps

  • Controls mapped to all 12 PCI DSS requirements
  • Automated evidence collection for network and access controls
  • Policy templates for PCI-required documentation
  • Vendor risk management for payment service providers
  • Dual version support — manage both 3.2.1 and 4.0.1 simultaneously during transition

Frequently asked questions

Use PCI DSS 4.0.1 for new implementations. If you are currently on 3.2.1, plan your transition as the older version is being phased out.
Using a third-party payment processor reduces your scope but does not eliminate PCI DSS requirements entirely. You still need to complete a Self-Assessment Questionnaire (SAQ).
Levels 1–4 are based on annual transaction volume. Level 1 (over 6 million transactions) requires an on-site audit. Levels 2–4 can use self-assessment questionnaires.