What is PCI DSS?
The Payment Card Industry Data Security Standard — the security baseline that any system handling card data must meet.
Also known as
PCI DSS — explained.
PCI DSS (Payment Card Industry Data Security Standard) is the security standard maintained by the PCI Security Standards Council, mandated by the card networks (Visa, Mastercard, Amex, Discover, JCB) for any organisation that stores, processes, or transmits cardholder data. The current version is PCI DSS 4.0 (with 4.0.1 as a maintenance release), in effect since 31 March 2024 with full enforcement of new requirements from 31 March 2025. The 12 high-level requirements cover network security, cardholder data protection, vulnerability management, access control, monitoring, and security policy. PCI DSS 4.0 introduced a customised approach that lets organisations meet the intent of a control via documented compensating controls — useful for atypical architectures. For software vendors processing card payments (kiosks, parking pay-stations, retail POS, etc.), the practical implications are: scoping the cardholder data environment (CDE) tightly; tokenising or P2PE-encrypting card data so it never enters the operator's general environment; passing Approved Scanning Vendor (ASV) quarterly scans; maintaining annual Report on Compliance (ROC) or Self-Assessment Questionnaire (SAQ) depending on transaction volume. Zeour smart-parking and retail-payment kiosks ship PCI DSS 4.0-aligned out of the box.
Zeour solutions that operate on this layer.
Verticals where pci dss is operationally critical.
Adjacent definitions to read next.
GDPR
Compliance & DataThe EU's data-protection regulation — establishes consent, purpose-limitation, residency, breach-notification, and the data-subject rights regime.
PDPL
Compliance & DataPersonal Data Protection Law — the data-protection regime in Saudi Arabia (and equivalents in the UAE and several Gulf states).
Sovereign Deployment
Sovereign DeploymentSoftware that runs entirely inside the operator's perimeter — their hardware, their network, their backups, their keys — with no third-party dependency for continued operation.
CCPA / CPRA
Compliance & DataCalifornia's data-protection law — and the CPRA amendment in force since 2023 — establishing data-subject rights for California residents.
Cyber Essentials
Compliance & DataThe UK NCSC's baseline cybersecurity certification — a five-control posture (firewalls, secure config, access control, malware, patches) increasingly required for UK government contracts.
Data Subject Access Request (DSAR)
Compliance & DataThe data-subject's right to request a copy of all personal data an operator holds about them, plus deletion, correction and processing-restriction rights — under GDPR, PDPL and equivalent laws.
Explicit Consent
Compliance & DataConsent that is specific, informed, unambiguous and given by a clear affirmative action — separate tickboxes per purpose, not bundled — required under GDPR, PDPL and equivalent laws.
HIPAA
Compliance & DataThe US healthcare-data-protection law governing Protected Health Information (PHI) — covers privacy, security, breach notification, and business-associate agreements.
Talk to a Zeour engineer.
A 30-minute scoping call to walk your operational profile against where pci dss actually sits in your stack, then a fixed-fee Discovery price by the end of the call.