Version 1 - Primary Nav Search
Man at computer with credit card

5 min read

Key takeaways

  • PCI compliance, achieved through PCI DSS, provides a well-tested framework to protect your customers' payment data and prevent fraud
  • Meeting PCI DSS requirements strengthens your overall security posture and helps build lasting customer relationships built on trust
  • Systematic assessment, remediation and reporting help keep your PCI compliance measures—and your business—secure

PCI compliance is the set of security requirements every business must meet to handle payment card data safely. The Payment Card Industry Data Security Standard (PCI DSS) provides the framework you need to safeguard cardholder data and maintain secure transactions. Debit and credit cards account for 65% of U.S. consumer payments, making the protection of payment data essential to your business.1

What is PCI compliance?

The PCI Security Standards Council (SSC) developed PCI DSS to strengthen payment card data security and drive consistent protection worldwide.2 Compliance requirements are enforced by the major credit card brands, such as Visa®, Mastercard® and American Express®.

As a payment processor, merchant or service provider, you must implement and maintain these security measures if your business handles, stores, processes or transmits credit or debit card information in any way. These requirements establish a complete security framework for your business, from basic protections like firewalls and passwords to more comprehensive data encryption and access management systems.

How are PCI compliance levels ranked?

As a merchant, your PCI compliance requirements scale with your transaction volume, divided into four levels:

  • Level 1: Over 6 million transactions annually
  • Level 2: 1 million to 6 million transactions annually
  • Level 3: 20,000 to 1 million transactions annually
  • Level 4: Fewer than 20,000 transactions annually

Not all card networks use all four compliance levels, and transaction volumes for each level may vary depending on the card. For example, Discover and American Express have no PCI Level 4 designation, and JCB has only two merchant levels. Additionally, if a merchant suffers a data breach that compromises cardholder information, they may be moved to a higher PCI compliance level.

Your compliance level determines your validation requirements. Larger merchants, Levels 1 and 2, typically need on-site assessments by Qualified Security Assessors (QSAs) who are certified by SSC, while smaller merchants may only need to complete self-assessment questionnaires (SAQs).

While merchants have four levels of PCI requirements, service providers (such as payment gateways and other businesses involved in processing, storing or transmitting cardholder data) have only two.

Why is PCI compliance important?

PCI compliance protects your business and customers in several ways. Beyond protecting sensitive data—from credit card numbers to security codes—it provides a structure for preventing data breaches, fraud and identity theft.

If a cardholder data compromise does occur, you face forensic investigation, fraud assessment, fines and expenses, and must provide a Report of Compliance.3

Following PCI DSS standards strengthens your overall security posture and helps you stay ahead of evolving threats. Most importantly, it demonstrates to your customers that you take their data security seriously, helping you build the trust essential for long-term business relationships.

           

Our specialists can help you implement payment security measures that safeguard your business and customer trust.

Request a call

           

What are the key requirements for PCI compliance?

The PCI DSS requirements consist of 12 security controls that protect cardholder data:

  1. Install and maintain network security controls: Utilize firewalls and network rules to control traffic entering and leaving the cardholder data environment
  2. Apply secure configurations to all system components: Replace vendor default settings and passwords, and harden systems before they go live
  3. Protect stored account data: Limit what cardholder data is retained and secure any data that must be stored
  4. Protect cardholder data with strong cryptography during transmission over open public networks: Encrypt cardholder data whenever it travels across public or untrusted networks
  5. Protect all systems and networks from malicious software: Deploy and maintain anti-malware measures across systems at risk of infection
  6. Develop and maintain secure systems and software: Apply security patches and build applications using secure development practices
  7. Restrict access to system components and cardholder data: Grant data access only to the roles whose duties require it
  8. Identify users and authenticate access to system components: Assign a unique ID to each user and verify identity before granting access
  9. Restrict physical access to cardholder data: Control and monitor physical entry to areas where cardholder data is stored or handled
  10. Log and monitor all access to system components and cardholder data: Record access activity and review logs to detect and investigate anomalies
  11. Test security of systems and networks regularly: Run regular vulnerability scans and tests to find and fix weaknesses
  12. Support information security with organizational policies and programs: Maintain security policies and training that keep people accountable for protecting data

The PCI DSS security cycle

These 12 requirements are not a one-time compliance checklist; they work together in a continuous cycle of security management:

  • Assess: Evaluate where cardholder data exists in your systems and map out both the IT assets and business processes that interact with it.
  • Remediate: Address vulnerabilities, optimize data storage and strengthen protective measures based on your assessment findings.
  • Report: Document your compliance efforts and submit required validation to maintain your PCI DSS certification.

J.P. Morgan is here to help

Our Trust & Safety Solutions can help you implement and maintain strong security measures that protect cardholder data while meeting all PCI DSS requirements—letting you focus on growing your business.

JPMorgan Chase Bank, N.A. Member FDIC. Visit jpmorgan.com/commercial-banking/legal-disclaimer for disclosures and disclaimers related to this content.

References

1.

Federal Reserve Financial Services’ FedCash® Services, 2025 Diary of Consumer Payment Choice

2.

PCI Security Standards Council, PCI DSS webpage

Contact us

This field is required.

This field is required.

This field is required.

This field is required.

This field is required.

Please enter a valid business email. This field is required.

Please enter a valid business email. This field is required.

Please enter a valid business email. This field is required.

By checking the box below I consent to JPMorganChase using the information I have provided to send me:

Learn more about our data practices in our privacy policy.