The PCI DSS is a set of requirements explaining how to protect you and your customers when taking card payments. These are industry-spanning requirements, so all suppliers taking payments should take the PCI DSS seriously.
When you take card payments, you rely on customer trust in your ability to protect their financial data. With the Payment Card Industry Data Security Standard, established by major card brands, your business can demonstrate adherence to stringent security measures. The protocols of the standard are designed to safeguard transactional data, deter identity fraud and prevent costly security breaches, enhancing your reputation as a trustworthy business.
Our accredited PCI DSS certification service, provided by Panacea Infosec (acquired by SGS in January 2026), confirms your compliance with the 12 key PCI DSS requirements and positions you to manage ongoing security challenges effectively.

As the world leader in inspection, testing and certification, we offer in-depth data security expertise for your business operations. Our comprehensive PCI DSS certification process is tailored to the needs of your organization, regardless of its size or sector. We guide you through every step – from initial gap analysis to continuous compliance maintenance. Our global presence and experience ensure that your data security measures meet international standards, helping you navigate and adapt to the evolving landscape of cyber threats.
The PCI DSS is a set of requirements explaining how to protect you and your customers when taking card payments. These are industry-spanning requirements, so all suppliers taking payments should take the PCI DSS seriously.
Visa, MasterCard, Discover Financial Services, JCB International and American Express created the PCI DSS in 2004.
Your compliance level is based on the annual number of credit/debit card transactions your business processes. The level determines what you must do to maintain compliance.
Level 1: 6 million transactions per year
Level 2: 1-6 million transactions per year
Level 3: 20,000-1 million transactions per year
Level 4: <20,000 transactions per year
An organization that starts taking card payments has 90 days to meet the PCI DSS requirements. After this, you must maintain compliance and show it at least once a year.
Every organization is different, from its size and type to its information security and cybersecurity measures. Therefore, an organization is judged individually. What you must do to comply depends on your potential security risks.
If you cannot prove you are protecting customer cardholder data, the consequences could be severe for both sides, including: