PCI DSS for Merchants: What It Means for Your Organization

If your organization accepts payment cards, PCI DSS is the security standard your acquirer expects you to meet. The standard applies even when a processor handles the card number. ALCON DTS helps you see which systems can affect that environment and keep the related controls and evidence current. Your acquirer, and a Qualified Security Assessor when one is required, still decide how you validate.

Talk with ALCON DTSSee what you need in place

At a glance

  • PCI DSS is a standard from the PCI Security Standards Council, not a statute.
  • It applies to merchants that store, process, or transmit account data, and to firms whose services can affect the security of that data.
  • Using a compliant processor does not finish the merchant’s own validation.
  • The acquirer or payment brand decides whether you complete a Self-Assessment Questionnaire or a Report on Compliance.
  • A merchant questionnaire is not the form a service provider uses.
  • ALCON DTS does not issue an Attestation of Compliance.

What is PCI DSS?

PCI DSS is the Payment Card Industry Data Security Standard. Payment brands use it to set a common baseline for protecting account data. Version 4.0.1 is the current standard. Requirements that were future-dated became mandatory on March 31, 2025.

The merchant agreement with the acquirer is what makes the standard operative for most firms. The Council issues the standard. The acquirer says how you show that you meet it.

What it covers, and what it does not

It covers account data in the cardholder data environment, and systems connected to that environment that could affect its security. That can include the point of sale, the payment page, the network path, logging, and the vendors that touch the flow.

It does not replace a privacy law. It does not make a processor’s attestation yours. It does not tell a small firm to hire a QSA. Your acquirer decides the validation path.

Does it apply to you?

It likely applies if you accept branded payment cards for your own goods or services. Volume changes the validation path. It does not turn the standard off.

A quick check:

  1. You accept credit or debit cards.
  2. Card data is entered, stored, or transmitted on your systems, or a third party does that for you.
  3. Your website, terminal, network, or a vendor can affect that flow.

If those are true, ask the acquirer which form they want. Do not pick a short questionnaire because it looks smaller. Eligibility has to match the way you actually take cards.

What you need in place

Every merchant program needs a defined scope, a list of the systems and vendors in that scope, and evidence that the controls for that scope are operating.

The questionnaire follows the payment path:

  • Cards taken only through a compliant processor, with no electronic account data on your systems, often points to a shorter merchant questionnaire. Confirm that with the acquirer.
  • A payment page your site builds, or a terminal and network you operate, points to a broader questionnaire.
  • A firm that stores, processes, or transmits account data for someone else is a service provider. A service provider does not use a merchant questionnaire.

Controls that usually sit with the office systems are network segmentation, unique access, logging, tested restore, and vendor tracking for anyone who can affect the payment path.

How ALCON DTS helps

You keep the acquirer relationship and the attestation. We run the controls on the systems we support and keep the evidence with you.

PCI element What ALCON DTS provides
Scope picture A map of the networks, endpoints, and vendors that can affect the payment path
Access Unique accounts, multifactor authentication, and limited admin rights on systems that affect the payment path
Network Firewall, segmentation, and wireless settings documented when that work is part of the relationship
Logging and restore Logging on the managed environment, and backup and restore practice you can show
Vendors A list of providers that can affect the environment, and where their attestations are filed
Evidence file The diagrams, settings, and test notes an acquirer or assessor asks to see

The exact controls depend on the plan and any project work. The review shows what is in place and what would close a gap.

ALCON DTS is not a QSA and does not issue an Attestation of Compliance.

Need a clear picture of how you take cards? A review looks at which systems can affect that path and which form the acquirer expects.

Request a review

How it fits other rules

A security questionnaire often asks the same questions in the merchant’s language. See our Security Questionnaires guide.

Texas Cybersecurity Safe Harbor is a separate defense. It does not replace PCI validation. See Texas Cybersecurity Safe Harbor (SB 2610).

HIPAA applies when patient information is also in the environment. The payment path and the patient-information path should be named separately.

Frequently asked questions

No. It is a contractual standard enforced through the acquirer and the payment brands.

No. You still validate the part of the environment you control, and you keep the processor’s attestation on file.

Only if the acquirer or the brand requires a Report on Compliance. Many smaller merchants complete a questionnaire. Confirm the path before you start.

Only if you meet every eligibility rule for that form. The acquirer is the one that accepts it.

No. We prepare the controls and the evidence. The acquirer, or a QSA when one is required, is the validation path.

That can make you a service provider as well as a merchant. Those are two validations. A merchant form does not cover the service-provider duty.

Sources

  • PCI Security Standards Council, PCI DSS v4.0.1 and the glossary definitions of merchant and service provider
  • Your acquirer’s validation instructions

Talk with ALCON DTS

A review of your needs and growth plans looks at how you take cards, which systems can affect that path, and which form the acquirer expects. You keep the attestation. We run the controls and keep the evidence file with you.

Email: info@alcondts.com · Phone: 512-892-6900

Request a review