What is PCI DSS and who must comply with it?
PCI DSS stands for Payment Card Industry Data Security Standard. It is a set of requirements designed to ensure that all companies that accept, process, store, or transmit credit card information maintain a secure environment. Compliance with PCI DSS is mandatory for QSAs [1], and entities that handle cardholder data, such as e-commerce merchants [2, 4], must adhere to its standards. The standard provides a framework for protecting cardholder data and includes requirements for security management, policies, procedures, network architecture, software design, and other critical protective measures.
5 verified sources
What changed in PCI DSS v4.0.1?
The context indicates that PCI DSS v4.0.1 was published on 11 June 2024 and is a limited revision with no new requirements added or removed compared to v4.0. Therefore, there were no changes in requirements between v4.0 and v4.0.1. [1]
5 verified sources
What are the NPCI and UPI security requirements?
The NPCI and UPI security requirements include:
1. Volume-cap compliance for Third-Party Application Providers (TPAPs), with a deadline of 31 December 2026, as per NPCI's volume-cap guidelines for UPI (referencing circular NPCI/UPI/OC-97/2020-21).
2. Audit and compliance obligations on TPAPs, including audits by CERT-In empanelled auditors and UPI data storage within India, as detailed in NPCI's Guidelines for Third-Party Application Providers in UPI (circular OC 97, 2020).
These requirements are effective as of their respective deadlines and are enforced through various circulars and guidelines issued by NPCI.
5 verified sources
What is the PCI DSS v4.0.1 effective date and what are the key deadlines?
The PCI DSS v4.0.1 effective date is 31 March 2025. Key deadlines include:
- Future-dated v4.x requirements becoming mandatory in assessments from 31 March 2025 [1].
The last-verified date for this information is 2026-08-01.
5 verified sources
When did the future-dated PCI DSS v4.0 requirements become mandatory?
The future-dated PCI DSS v4.0 requirements became mandatory in assessments from 31 March 2025. [1]
5 verified sources
What are the NPCI and UPI security and audit requirements?
NPCI and UPI security and audit requirements include:
1. **Audit Obligations**: TPAPs must undergo audits conducted by CERT-In empanelled auditors. These audits are part of the TPAP guidelines (OC 97, 2020) which impose audit and compliance obligations on TPAPs. ([1])
2. **Data Storage**: UPI data must be stored within India. PSP banks retain audit rights over TPAP UPI infrastructure. ([1])
3. **Volume-Cap Compliance**: Existing TPAPs exceeding the volume-cap must comply by 31 December 2026, following a two-year extension from the original deadline of 31 December 2024. ([2])
4. **API Usage Monitoring**: PSPs and acquiring banks must monitor and control API usage as per NPCI's Guidelines on usage of UPI APIs (OC 215 series, May 2025), with non-compliance potentially leading to API restrictions, penalties, or suspension of new customer onboarding. ([2])
5. **Security Audits**: Pre-go-live and periodic security audits are required for TPAPs, PSP banks, aggregators, and fintechs across various payment systems including UPI, IMPS, RuPay, NACH, AePS, and NETC. ([4])
These requirements ensure compliance and security standards are met in the UPI ecosystem. ([1][2][4])
5 verified sources
What are the PCI DSS merchant levels?
PCI DSS merchant levels are classified by Visa into four levels based on annual transaction volume:
- Level 1: More than 6 million Visa transactions per year across all channels (or any merchant designated Level 1 by Visa, e.g., after a compromise) - annual on-site assessment and Report on Compliance (ROC) plus quarterly network scan. [2]
- Level 2: 1 to 6 million transactions per year - annual Self-Assessment Questionnaire (SAQ) and quarterly scan. [2]
- Level 3: 20,000 to 1 million Visa e-commerce transactions per year - SAQ and quarterly scan. [2]
- Level 4: Fewer than 20,000 Visa e-commerce transactions, or up to 1 million total transactions per year - SAQ and scan as required by the acquirer. [2]
Other card brands set broadly similar but not identical thresholds; the acquirer confirms a merchant's level. [2]
5 verified sources
What are the PCI DSS SAQ types and when is a ROC required instead?
PCI DSS defines nine SAQ types, each scoped to how a merchant handles cardholder data:
- SAQ A (fully outsourced e-commerce or mail/telephone order, no data handling)
- SAQ A-EP (e-commerce that partially controls the payment page)
- SAQ B (imprint machines or standalone dial-out terminals, no electronic storage)
- SAQ B-IP (standalone PTS-approved IP-connected terminals)
- SAQ C-VT (web-based virtual terminal, one transaction at a time)
- SAQ C (payment application connected to the internet)
- SAQ P2PE (hardware terminals in a validated PCI P2PE solution)
- SAQ D for Merchants (all others that store, process or transmit cardholder data - the most comprehensive)
- SAQ D for Service Providers (applies to service providers)
A merchant who cannot meet an SAQ's eligibility criteria, or who is a Level 1 merchant, completes a full Report on Compliance (ROC) instead of an SAQ [1].
5 verified sources
What are the 12 requirements of PCI DSS?
The 12 requirements of PCI DSS are:
1. Build and maintain a secure network.
2. Build and maintain secure systems and applications.
3. Protect cardholder data.
4. Encrypt cardholder data during transmission over open, public networks.
5. Develop and maintain secure systems and applications.
6. Maintain a vulnerability management program.
7. Implement strong access control measures.
8. Regularly monitor and test networks.
9. Maintain a policy that addresses information security for employees and contractors.
10. Track and monitor all access to network resources and cardholder data.
11. Regularly test security systems and processes.
12. Maintain a written information security policy.
These requirements are structured under six goals as outlined in PCI DSS v4.0.1, which was published in June 2024. [1]
5 verified sources