# PCI DSS

URL: https://tnb-tech.com/en/glossary/pci-dss/

## What is PCI DSS?

PCI DSS is the card industry’s data security standard, required of every business that accepts card payments. It is not a law but a contractual condition attached to card acceptance, and it is proved either with a self-assessment questionnaire or with an audit, depending on how payments are taken. A shop that sends the customer to the bank’s or the payment provider’s page falls under the lightest version, yet stays responsible for the page the customer starts from.

**Example**

A shop takes cards through a bank’s payment page: the customer presses the payment button, the bank’s page opens, the card number is typed there, and the shop gets back only “approved” or “declined”. No card data reaches its server and none is stored in its database. That is the lightest form of compliance, and it still leaves work to do:

- The page the customer starts from is yours. If a foreign script gets into it, that script can swap the button and send the customer elsewhere, which is why, since 31 March 2025, even the lightest questionnaire asks you to confirm that the page is not open to such scripts, while the standard itself sets out how payment page scripts are managed and how a change to a page is detected.

- Admin access runs on named accounts with a second factor, not on one shared password.

- Software and plugins are kept updated, and versions past end of life are replaced.

The scope widens the moment somebody takes a card number over the phone and types it in by hand, or saves it in a note on the order. If the card form sits on your own site, the requirements are a different order of work.

**Why it matters for a business**

Compliance comes with the card acceptance contract, so the terms are set by your bank or payment provider. After an incident involving card data, the investigation and the liability travel towards the merchant, and the bank can ask for evidence of compliance or restrict card acceptance. The everyday consequence is simpler: the standard rules out habits that feel convenient, such as a card number sitting in an email, a chat thread, a spreadsheet or an order note.

**What to ask**

- Which self-assessment questionnaire applies to the way you take payments? Confirm it with the bank or the provider.

- Does a card number ever reach your server, your inbox, your chat tool or an order note?

- Who controls the scripts on the page carrying the payment button, and how would you know it had been changed?

- Who has admin access, with which rights, and is a second factor required?

- What does the payment provider cover and what stays with you? Ask for it in writing.

When we build an online store, payment runs through the bank or the payment provider and no card data is stored on our side, which keeps the shop in the lightest version and the scope small.

- Services: [Online store development](https://tnb-tech.com/en/services/online-store-development/)
- Glossary: https://tnb-tech.com/en/glossary/
