5 min read
PCI compliance is the set of security requirements every business must meet to handle payment card data safely. The Payment Card Industry Data Security Standard (PCI DSS) provides the framework you need to safeguard cardholder data and maintain secure transactions. Debit and credit cards account for 65% of U.S. consumer payments, making the protection of payment data essential to your business.1
The PCI Security Standards Council (SSC) developed PCI DSS to strengthen payment card data security and drive consistent protection worldwide.2 Compliance requirements are enforced by the major credit card brands, such as Visa®, Mastercard® and American Express®.
As a payment processor, merchant or service provider, you must implement and maintain these security measures if your business handles, stores, processes or transmits credit or debit card information in any way. These requirements establish a complete security framework for your business, from basic protections like firewalls and passwords to more comprehensive data encryption and access management systems.
As a merchant, your PCI compliance requirements scale with your transaction volume, divided into four levels:
Not all card networks use all four compliance levels, and transaction volumes for each level may vary depending on the card. For example, Discover and American Express have no PCI Level 4 designation, and JCB has only two merchant levels. Additionally, if a merchant suffers a data breach that compromises cardholder information, they may be moved to a higher PCI compliance level.
Your compliance level determines your validation requirements. Larger merchants, Levels 1 and 2, typically need on-site assessments by Qualified Security Assessors (QSAs) who are certified by SSC, while smaller merchants may only need to complete self-assessment questionnaires (SAQs).
While merchants have four levels of PCI requirements, service providers (such as payment gateways and other businesses involved in processing, storing or transmitting cardholder data) have only two.
PCI compliance protects your business and customers in several ways. Beyond protecting sensitive data—from credit card numbers to security codes—it provides a structure for preventing data breaches, fraud and identity theft.
If a cardholder data compromise does occur, you face forensic investigation, fraud assessment, fines and expenses, and must provide a Report of Compliance.3
Following PCI DSS standards strengthens your overall security posture and helps you stay ahead of evolving threats. Most importantly, it demonstrates to your customers that you take their data security seriously, helping you build the trust essential for long-term business relationships.
Our specialists can help you implement payment security measures that safeguard your business and customer trust.
The PCI DSS requirements consist of 12 security controls that protect cardholder data:
These 12 requirements are not a one-time compliance checklist; they work together in a continuous cycle of security management:
Our Trust & Safety Solutions can help you implement and maintain strong security measures that protect cardholder data while meeting all PCI DSS requirements—letting you focus on growing your business.
JPMorgan Chase Bank, N.A. Member FDIC. Visit jpmorgan.com/commercial-banking/legal-disclaimer for disclosures and disclaimers related to this content.
Federal Reserve Financial Services’ FedCash® Services, 2025 Diary of Consumer Payment Choice
PCI Security Standards Council, PCI DSS webpage
J.P. Morgan Merchant Services, Merchant Investigations Frequently Asked Questions PDF