Have some questions about PCI DSS compliance? You’re in good company.
I got my start in compliance when the boss came by, dropped a four-inch stack of paper on my desk, the top page had the letters PCI on it and he said we needed to get compliant. I was staring down Alice’s rabbit hole, wondering what to do and where to start. I’ll never forget how overwhelming it was.
PCI compliance can be enormously overwhelming when you’re just starting to venture into the compliance realm. But TCT has specialized in PCI DSS since our inception—and our Consultants’ PCI history goes even farther back. Let’s address some frequently asked questions about PCI compliance.
Check out TCT’s complete guide to PCI DSS Certification
Does PCI apply to merchants who outsource all payment processing operations and never store, process, or transmit cardholder data?
Absolutely. This is one of the biggest misunderstandings that organizations struggle with. The easiest way to evaluate applicability is simple: if your organization receives money through credit cards, you must complete your PCI paperwork.
Many organizations assume that because they use modern, integrated payment providers like Stripe, Square, or Intuit to make processing feel seamless, they have zero remaining responsibilities. While those merchant platforms absorb a significant portion of the technical requirements, you must still maintain explicit internal controls. This includes vulnerability scanning of your in scope systems, configuring them securely, maintaining an incident response plan and more.
What is the difference between complying with PCI as a merchant versus as a service provider?
The distinction is based on your relationship to the transaction:
- Merchants: Organizations that directly accept and receive payments via credit cards.
- Service Providers: Organizations that provision services to other companies that receive money through credit cards.
The service provider bucket is broad. It encompasses hosting companies, gateways, and specialized solutions providers that help entities meet specific compliance items (such as centralized logging, file integrity monitoring, or direct transaction routing).
There are unique, specific security requirements that apply strictly to the service provider tier. Otherwise, the baseline controls of the PCI DSS apply identically to both merchants and service providers.
Can an organization be both a merchant and a service provider?
Yes. For example, a card-processing gateway provisions transactional services to external merchants (making them a service provider). It may also accept direct credit card payments from clients to pay for their own corporate services—making them a merchant also.
Organizations falling into this dual category generally handle compliance in one of two ways:
- Maintain two separate sets of PCI documentation to ensure the scope, context, and boundaries remain clean on both sides.
- Combine them into a single assessment, which requires meticulous specificity regarding which controls apply strictly to the merchant instance versus the service provider instance.
What happens if an organization fails to maintain PCI DSS after becoming compliant?
Completing your compliance documentation culminates in signing an Attestation of Compliance (AOC), which legally certifies that your program meets the required controls. An AOC is valid for exactly one year from the date of signature.
If you sign your paperwork but immediately stop maintaining your PCI security controls, you place your organization, data, and customers in severe jeopardy. If a data breach occurs while your company is out of compliance, you will be in direct violation of the PCI DSS and your signed attestation.
This exposes the business to substantial negative impacts, including aggressive fines levied by payment processors, direct financial penalties from the card brands, and severe legal liabilities.
From an operational standpoint, letting controls lapse introduces massive blindness. For example, if your company disabled centralized logging because the storage is deemed too expensive, you would lose all visibility into the environment and would not be able to detect an active compromise. Let alone failing to maintain compliance with the PCI DSS as you asserted through your AOC.
9 Must-have Resources to Make PCI Compliance Easier
Why do some organizations comply with PCI DSS even if they don’t process card payments?
The PCI DSS is widely recognized as one of the most prescriptive, granular sets of data protection guidelines in the security industry. Many alternative compliance frameworks are purely directional in nature. For example, a framework like HIPAA might feature a brief, one-line statement instructing an organization to use secure authentication. In contrast, PCI DSS breaks that exact same concept down into dozens of explicit, highly specific line-item requirements.
Organizations that value robust data security frequently leverage the structured baseline of the PCI DSS to run their entire GRC program. Instead of limiting the framework to a narrow cardholder data environment (CDE), they treat all sensitive data as if it were credit card data, applying the same rigorous controls across the enterprise.
Why are there multiple PCI Self-Assessment Questionnaires (SAQs)?
The PCI Security Standards Council maintains a diverse series of specialized Self-Assessment Questionnaires (SAQs) tailored to specific transactional environments. The specific mechanics of how an organization processes transactions dictates which questionnaire they must complete:
- SAQ A: Designed for organizations that have completely outsourced all of their card processing activities to a validated third party.
- Intermediate SAQs (B and C): Tailored to specific hybrid processing methods, separating out distinct variations of card data exposure.
- SAQ D: The most exhaustive tier, required for any organization or service provider that actively receives, processes, or stores cardholder data within their internal systems.
Is the PCI Attestation of Compliance (AOC) intended to be shared?
Yes, that is its primary purpose. When completing a PCI assessment, the raw Self-Assessment Questionnaire (SAQ) contains highly detailed, sensitive technical descriptions of your internal security infrastructure. Because of these exposure risks, a raw SAQ should never be distributed to third parties. The Attestation of Compliance (AOC), however, serves as the clean, publicly facing validation report meant to be shared externally to prove your compliance stance to clients and partners.
If we do business in multiple countries, does that affect which QSA we need to use for assessments?
The short answer is yes. A US-based business with a scope footprint in Europe or South America must use a QSA that has registered and paid to operate in those geographic region(s) or country(s) .
The PCI Security Standards Council organizes Assessors by official operating regions (such as US/Canada, Europe, APAC, etc.). Your organization must ensure that whichever QSA firm you select is formally qualified and approved by the Council to operate within the specific region(s) where your scope is located. Most organizations naturally gravitate toward an Assessor located in close geographic proximity to their primary operations, but this will be a consideration for those with more complicated circumstances.
Does PCI DSS address artificial intelligence (AI)?
The PCI Security Standards Council has released targeted directional guidance regarding the integration of artificial intelligence. This framework establishes rules for Assessors leveraging automated tools, including mandatory client notification and explicit consent protocols before using AI for artifact and evidence reviews. The guidance emphasizes keeping a human in the loop, warning that fully autonomous AI management remains an unfulfilled promise.
Crucially, all baseline requirements of the PCI DSS apply to any internal AI integration. The core principles of least privilege, strict access control, and need-to-know data boundaries must govern your machine learning models. If an organization opens an AI tool to unencrypted data across underlying systems without a verified business necessity, they are in direct violation of PCI data security requirements.
When does a self-assessment make sense?
If your annual credit card transaction volume sits below the formal thresholds mandated by the card brands, you are permitted to execute a Self-Assessment Questionnaire (SAQ) rather than undergoing a full Report on Compliance (ROC) managed by an external QSA. For smaller, newer, or early-stage businesses minimizing transaction overhead, the SAQ process is a cost-effective entry point into the compliance landscape.
However, self-assessment can be a double-edged sword. Internal teams frequently misinterpret complex control language, checking boxes under the assumption that their environment is compliant when it is not. This creates a dangerous, false sense of security.
Because an SAQ is a legally binding document, misunderstanding a requirement does not absolve your organization of risk. It is strongly recommended that self-assessing businesses retain a qualified PCI DSS Consultant to independently review their configurations and sanity-check their answers before formal submission and signing on the dotted line.
Where can I find official documentation and the current version of the PCI DSS?
All official compliance documentation is centrally maintained by the Payment Card Industry Security Standards Council (PCI SSC). You can access their public repository at www.pcisecuritystandards.org. The site features a dedicated Document Library where you can filter by standard types, if you go to Resources / Document Library. From there, in order to filter on the SAQs, scroll down and change the “Filter By” from PCI DSS to SAQ.
Can TCT help us with our PCI DSS compliance engagement?
Absolutely! TCT’s Consultants have decades of experience working with clients on PCI DSS engagements, among a myriad of other standards. But we’ve been working on PCI engagements since it first came out a couple of decades ago.
Our compliance management platform is also designed to make the heavy load of a PCI DSS engagement much lighter. TCT Portal is a holistic platform that takes out the most tedious and inefficient tasks to streamline the entire engagement. Real-time insights, common-sense organization, and automated functions make TCT Portal an absolute no-brainer for either seasoned or new PCI professionals.
