PCI DSS for Merchants: What It Means for Your Organization
If your organization accepts payment cards, PCI DSS is the security standard your acquirer expects you to meet. The standard applies even when a processor handles the card number. ALCON DTS helps you see which systems can affect that environment and keep the related controls and evidence current. Your acquirer, and a Qualified Security Assessor when one is required, still decide how you validate.
Jump to an answer
At a glance
- PCI DSS is a standard from the PCI Security Standards Council, not a statute.
- It applies to merchants that store, process, or transmit account data, and to firms whose services can affect the security of that data.
- Using a compliant processor does not finish the merchant’s own validation.
- The acquirer or payment brand decides whether you complete a Self-Assessment Questionnaire or a Report on Compliance.
- A merchant questionnaire is not the form a service provider uses.
- ALCON DTS does not issue an Attestation of Compliance.
What is PCI DSS?
PCI DSS is the Payment Card Industry Data Security Standard. Payment brands use it to set a common baseline for protecting account data. Version 4.0.1 is the current standard. Requirements that were future-dated became mandatory on March 31, 2025.
The merchant agreement with the acquirer is what makes the standard operative for most firms. The Council issues the standard. The acquirer says how you show that you meet it.
What it covers, and what it does not
It covers account data in the cardholder data environment, and systems connected to that environment that could affect its security. That can include the point of sale, the payment page, the network path, logging, and the vendors that touch the flow.
It does not replace a privacy law. It does not make a processor’s attestation yours. It does not tell a small firm to hire a QSA. Your acquirer decides the validation path.
Does it apply to you?
It likely applies if you accept branded payment cards for your own goods or services. Volume changes the validation path. It does not turn the standard off.
A quick check:
- You accept credit or debit cards.
- Card data is entered, stored, or transmitted on your systems, or a third party does that for you.
- Your website, terminal, network, or a vendor can affect that flow.
If those are true, ask the acquirer which form they want. Do not pick a short questionnaire because it looks smaller. Eligibility has to match the way you actually take cards.
What you need in place
Every merchant program needs a defined scope, a list of the systems and vendors in that scope, and evidence that the controls for that scope are operating.
The questionnaire follows the payment path:
- Cards taken only through a compliant processor, with no electronic account data on your systems, often points to a shorter merchant questionnaire. Confirm that with the acquirer.
- A payment page your site builds, or a terminal and network you operate, points to a broader questionnaire.
- A firm that stores, processes, or transmits account data for someone else is a service provider. A service provider does not use a merchant questionnaire.
Controls that usually sit with the office systems are network segmentation, unique access, logging, tested restore, and vendor tracking for anyone who can affect the payment path.
How ALCON DTS helps
You keep the acquirer relationship and the attestation. We run the controls on the systems we support and keep the evidence with you.
| PCI element | What ALCON DTS provides |
|---|---|
| Scope picture | A map of the networks, endpoints, and vendors that can affect the payment path |
| Access | Unique accounts, multifactor authentication, and limited admin rights on systems that affect the payment path |
| Network | Firewall, segmentation, and wireless settings documented when that work is part of the relationship |
| Logging and restore | Logging on the managed environment, and backup and restore practice you can show |
| Vendors | A list of providers that can affect the environment, and where their attestations are filed |
| Evidence file | The diagrams, settings, and test notes an acquirer or assessor asks to see |
The exact controls depend on the plan and any project work. The review shows what is in place and what would close a gap.
ALCON DTS is not a QSA and does not issue an Attestation of Compliance.
Need a clear picture of how you take cards? A review looks at which systems can affect that path and which form the acquirer expects.
How it fits other rules
A security questionnaire often asks the same questions in the merchant’s language. See our Security Questionnaires guide.
Texas Cybersecurity Safe Harbor is a separate defense. It does not replace PCI validation. See Texas Cybersecurity Safe Harbor (SB 2610).
HIPAA applies when patient information is also in the environment. The payment path and the patient-information path should be named separately.
Frequently asked questions
Is PCI DSS a law?
Does a compliant processor make us compliant?
Do we have to hire a QSA?
Can we use the shortest questionnaire?
Does ALCON DTS issue the attestation?
What if we also process cards for another firm?
Sources
- PCI Security Standards Council, PCI DSS v4.0.1 and the glossary definitions of merchant and service provider
- Your acquirer’s validation instructions
Talk with ALCON DTS
A review of your needs and growth plans looks at how you take cards, which systems can affect that path, and which form the acquirer expects. You keep the attestation. We run the controls and keep the evidence file with you.
Email: info@alcondts.com · Phone: 512-892-6900

