Compliance framework

What is PCI DSS?

PCI DSS is a set of security standards for organizations that accept, process, store, or transmit payment card data. Compliance is validated annually by a Qualified Security Assessor (QSA) or through a Self-Assessment Questionnaire (SAQ) depending on transaction volume.

PCI DSS v4.0 introduced significant changes in 2022, including enhanced authentication requirements, customized implementation paths, and expanded applicability to e-commerce environments. Vendors processing cardholder data at Level 1 (over six million transactions per year) must publish a Report on Compliance (ROC). TrustVendor tracks PCI DSS level and last validation date.

Which vendors hold PCI DSS?

Search the TrustVendor vendor graph to see current certification status, evidence age, and expiry runway across all your vendors.

Common questions about PCI DSS

Which vendors hold PCI DSS certification?
Search the TrustVendor vendor graph to see which vendors in your portfolio hold current PCI DSS certification, when it was last verified, and how long until it expires. Certifications are tracked continuously and alerts fire when evidence ages past its half-life.
How often does PCI DSS certification need to be renewed?
Renewal frequency depends on the framework. SOC 2 Type II reports typically cover a 12-month audit period and should be requested annually. ISO 27001 certificates are valid for three years with annual surveillance audits. FedRAMP authorizations require annual assessment. TrustVendor tracks expiry dates and alerts you 90, 60, and 30 days before lapse.
Can I verify a vendor's PCI DSS report myself?
For certifications that produce a published artifact (ISO 27001 certificate, FedRAMP Marketplace listing), you can verify directly with the certifying body. For SOC 2, the report is issued by the auditing CPA firm and should be shared directly by the vendor under NDA. TrustVendor stores a sha256-hashed snapshot of every artifact it processes — you can verify the hash client-side using standard tooling.

Related frameworks

SOC 2 TYPE 2ISO 27001