Security Frameworks

PCI DSS: What It Is & Why It Matters

The Payment Card Industry Data Security Standard is a set of requirements for any organisation that stores, processes or transmits cardholder data, intended to keep payment card information secure.

In this explainer

  • Understand what PCI DSS is and who it applies to
  • Learn the general goals behind its requirements
  • Understand how reducing scope reduces risk
  • See why card-data security matters when collecting payments
  • Know what to ask a vendor and how Merion approaches it

8 min

What it is

The Payment Card Industry Data Security Standard (PCI DSS) is a security standard maintained by the PCI Security Standards Council, an industry body formed by the major card brands. It applies to any organisation that stores, processes or transmits cardholder data, and its purpose is to protect payment card information from theft and misuse.

PCI DSS is detailed and prescriptive compared with broader frameworks. It sets out specific requirements across a number of areas, and the way an organisation demonstrates compliance depends on how it handles card data and the volume of transactions involved.

Key principles

The standard's requirements group into a set of high-level goals. In general terms, an organisation handling card data is expected to:

  • Build and maintain a secure network — including firewalls and avoiding insecure default settings.
  • Protect cardholder data — protecting stored data and encrypting it when transmitted across open networks.
  • Maintain a vulnerability management programme — using anti-malware measures and keeping systems patched.
  • Implement strong access control — restricting access to card data on a need-to-know basis and authenticating users.
  • Monitor and test networks — logging access and regularly testing security.
  • Maintain an information security policy — governing how people handle card data.

A central idea in practice is scope reduction: the less card data an organisation stores and the fewer systems that touch it, the smaller the area that must be protected. Many organisations deliberately avoid handling raw card numbers by using compliant payment providers.

Why it matters for debt recovery

Debt-recovery providers often take payments, which can mean handling card data. PCI DSS matters because card information is a high-value target, and mishandling it can cause direct harm to debtors and exposure for everyone in the chain. A provider that takes PCI DSS seriously reduces the chance of a payment-related breach.

For a risk team, an important and reassuring answer is often that a provider minimises its handling of card data altogether, for instance by routing payments through a compliant payment service so that raw card numbers never touch the provider's own systems. Understanding how card data flows, and where it is stored, is more revealing than a simple compliance assertion.

What to ask a provider

Payment-focused questions are worth asking precisely:

  • Do you store, process or transmit cardholder data, and if so, how is it protected?
  • How have you reduced the scope of systems that touch card data?
  • Do you use a compliant payment provider so that raw card numbers are not held in your environment?
  • How do you control access to payment data and monitor for misuse?

A provider that has minimised its card-data footprint can usually explain exactly how payments flow and where data does and does not go. Our data handling page describes how we think about sensitive information.

How Merion approaches it

Merion follows good practice for protecting payment information consistent with PCI DSS goals, including limiting the handling of card data and applying access control and monitoring to payment processes.

This page is general information and not a claim of a particular PCI DSS validation level for Merion. Because payment arrangements and attestations change, please verify a provider's current compliance and payment data flows directly during due diligence.

Key takeaways

  • PCI DSS applies to any organisation that stores, processes or transmits cardholder data
  • Its goals span secure networks, data protection, access control and monitoring
  • Reducing the systems that touch card data shrinks the area that must be protected
  • Ask how a provider handles card data and reduces scope, then verify current compliance

Frequently asked questions

Does every organisation that takes payments need to handle card data directly?

No. Many organisations route payments through a compliant payment provider so that raw card numbers never enter their own systems, which reduces their PCI DSS scope considerably.

Is PCI DSS a law?

It is an industry standard rather than legislation, enforced through agreements with card brands and acquirers. Even so, handling card data carelessly can breach other legal obligations and cause real harm.

What does scope reduction mean?

It means limiting the number of systems and processes that store or touch card data. The smaller that footprint, the less there is to secure and the lower the risk of a payment-related breach.

Built on trust

Security and compliance you can verify

Merion handles every account on the facts, within the rules, and with data protected by design. Ask us anything.