PCI DSS Compliance Process and Requirements
An introduction to the PCI DSS compliance standards process, an explanation of PCI DSS levels of compliance and their required costs.

PCI DSS Standards
The Payment Card Industry Data Standards (referred to as PCI DSS), is a global industry standard set up by the major international credit card organisations pertaining to the security of cardholder information that flows through their networks. All organisations, whether Merchants or Service Providers, that accept payments or Store, Process and Transmit card data from the major international card organisations must adopt the PCI DSS and protect cardholder information in accordance with the Security Standards.
The PCI DSS is created and managed by the PCI SSC (Payment Industry Security Standards Council) and her members consist of VISA Inc., MasterCard, JCB, American Express and Discover.
PCI DSS Compliance Levels
The way to obtain the PCI DSS compliance status is usually via a PCI DSS Assessment. Both Merchants and Service Providers have different levels (using the regulations provided by VISA).
When a Merchant or Service Provider is deemed as Level 1, they are required to obtain the services of a QSA (Qualified Security Assessor), which is an approved PCI DSS auditor. The QSA has to perform an on-site audit for the organization and provide a report after the review.
Merchants Level 2-4 or Service Providers Level 2 must fill up a PCI DSS SAQ (Self-Assessment Questionnaire), which can also be assisted by a QSA. In order to determine the level and the type of SAQ you are required to use, please contact your acquirer.
PCI DSS Audit Process

In general, the PCI DSS audit can be divided into phases. The initial preparation and consultation phase may take up to 3-5 months, depending on the readiness of the organization that is undergoing the review and the complexity of their systems and their processes.
- Preparation & Consultation — Scope · Gap analysis · QSA engaged
- Remediation & Evidence — Policies · Controls · Documents
- QSA On-site Audit — 3–5 days on-site
- Report — ROC · AOC submission
PCI DSS related costs during and after the review

1. Systems Related Costs
As PCI DSS will require strong security protection to be implemented such as "One Primary Function Per Server" (Req. 2.2.1), the Web Server, Application Server and DB Server will have to be isolated from each other, if they were put in the same location previously. Similarly, there may be greater hosting equipment requirements (Virtual Servers can be used). Additionally, PCI DSS requires the establishment of security service components such as DNS Server, NTP Server, FIM Server (File Integrity Management), Log Server etc., therefore the organization may have to obtain more equipment than in the past in order to meet compliance requirements.
2. Security Equipment Costs
Additional security equipment may need to be purchased (i.e. Firewalls, IPS, IDS, WAF).
3. Data Encryption Costs
PCI DSS requires card data encryption. Organisations will typically use HSM (Hardware Secure Module) hardware encryption to ensure the security of the cardholder data stored.
4. Training Costs
PCI DSS requires employees to undergo Awareness Training, Secure Coding Training, and IRP (Incident Response Plan) drills. In addition, to perform Vulnerability Scans and Penetration Tests, your staff may also have to undergo sufficient technical training to operate these tools.
5. Technical Audit Costs
PCI DSS mandates a number of technical audits, including:
- Card Number Scanning
- Code Review
- Internal Vulnerability Scan
- ASV, External Vulnerability Scan
- Internal Penetration Test
- External Penetration Test
- Wireless Scan
6. Other Costs
If your organization is designated as a Service Provider, you will be required to register yourself, such as at VISA's Registry or MasterCard's Service Provider Registration.
PCI DSS Compliance Fees
In addition to the possible costs above, the PCI DSS Compliance fees and the time required by a QSA to complete the audit depend on the following factors as well:
- System Complexity: the number of hosts, the type of OS used by the system, the number of components installed on the system, whether there are multiple OSs used at the same time, whether there are multiple security configurations.
- Security Devices and Network Segments: how many security devices there are, such as Firewalls, IPS, IDS, WAF, Switches, Routers, SIEM, DRP etc. These must be set up and updated with proper access controls and logs; the higher the number, the more complicated the network segment, which increases audit time.
- The number of connected acquirers and service providers: the more acquirers there are, the more complicated the data-flows of the system.
- Retention and encryption of database and card data: the more diverse the card data flows and storage types, the more requirements for encryption and security protections, leading to more items for auditing.
- Number of operation units: the number of stores, server rooms, and offices will increase the number of review days. Backup server rooms that store card data are also included in the scope of review.
The costs of a PCI DSS audit also differ by geography, as the PCI SSC has different annual costs for each region and QSA costs vary by region. For example, a small-to-medium sized Service Provider in Southeast Asia will require around 3-5 days of on-site assessment and about a week for report preparation. Excluding transportation costs, a first-time PCI DSS certification may cost between 15,000 USD to 25,000 USD. The actual price must be estimated based on the variables above.

