The security standard that defines requirements for protecting payment-card data is the Payment Card Industry Data Security Standard, abbreviated PCI DSS.
PCI DSS was created by the major payment-card brands through the Payment Card Industry Security Standards Council. It applies to organizations that store, process, or transmit cardholder data, including merchants, processors, and service providers. Its requirements cover areas such as network protection, secure configurations, access control, vulnerability management, monitoring, and security testing.
PCI DSS is an industry standard rather than a general-purpose national law. Validation requirements depend on factors such as transaction volume, business type, and the payment brands involved. Compliance does not guarantee that a breach cannot happen; it establishes a baseline of controls intended to reduce risk and improve accountability.
PCI DSS should not be confused with ISO/IEC 27001, which addresses information-security management systems more broadly, or SOC 2, which is an assurance framework for service organizations. PCI DSS is specifically centered on payment-card data environments.