QUICK ANSWER

TL;DR

PCI DSS is the Payment Card Industry Data Security Standard: a baseline set of technical and operational requirements for protecting payment account data. PCI SSC states that it applies to entities that store, process, or transmit cardholder data or sensitive authentication data, or that can impact the security of that data. As of 2026, PCI DSS v4.0.1 is the active standard supported by PCI SSC.

AT A GLANCE

What does this guide answer?

  • What should merchants know about start with data flow?
  • What should merchants know about know the merchant’s validation path?
  • What should merchants know about third parties do not erase responsibility?
  • What should merchants know about keep security separate from underwriting?
01

QUESTION

What should merchants know about start with data flow?

ANSWER

Document where account data is entered, transmitted, stored, logged, and accessible, including websites, terminals, call centers, plugins, support tools, vendors, and backups.

  • The correct PCI DSS validation method depends on this real data flow and the eligibility criteria set by the accepting entity.
What to do
  • For start with data flow, keep the evidence simple and reviewable: identify the responsible owner, preserve the supporting documents, write down the provider’s requirement, and confirm the result in the account’s reports or agreement.
  • PCI DSS scope follows the flow of payment data.
  • Outsourcing can reduce exposure, but merchants still need to understand their environment, validate correctly, manage vendors, and maintain basic security controls.
  • These steps make the application easier to understand and give ORCA more to work with when matching the business to an appropriate processing relationship.
02

QUESTION

What should merchants know about know the merchant’s validation path?

ANSWER

Document where account data is entered, transmitted, stored, logged, and accessible, including websites, terminals, call centers, plugins, support tools, vendors, and backups.

  • The correct PCI DSS validation method depends on this real data flow and the eligibility criteria set by the accepting entity.
What to do
  • For know the merchant’s validation path, keep the evidence simple and reviewable: identify the responsible owner, preserve the supporting documents, write down the provider’s requirement, and confirm the result in the account’s reports or agreement.
  • PCI DSS scope follows the flow of payment data.
  • Outsourcing can reduce exposure, but merchants still need to understand their environment, validate correctly, manage vendors, and maintain basic security controls.
  • These steps make the application easier to understand and give ORCA more to work with when matching the business to an appropriate processing relationship.
03

QUESTION

What should merchants know about third parties do not erase responsibility?

ANSWER

Document where account data is entered, transmitted, stored, logged, and accessible, including websites, terminals, call centers, plugins, support tools, vendors, and backups.

  • The correct PCI DSS validation method depends on this real data flow and the eligibility criteria set by the accepting entity.
What to do
  • For third parties do not erase responsibility, keep the evidence simple and reviewable: identify the responsible owner, preserve the supporting documents, write down the provider’s requirement, and confirm the result in the account’s reports or agreement.
  • PCI DSS scope follows the flow of payment data.
  • Outsourcing can reduce exposure, but merchants still need to understand their environment, validate correctly, manage vendors, and maintain basic security controls.
  • These steps make the application easier to understand and give ORCA more to work with when matching the business to an appropriate processing relationship.
04

QUESTION

What should merchants know about keep security separate from underwriting?

ANSWER

This part of PCI DSS for Merchants: What High-Risk Businesses Need to Know should be evaluated against the merchant’s actual agreement and operating model.

  • PCI DSS scope follows the flow of payment data.
  • Outsourcing can reduce exposure, but merchants still need to understand their environment, validate correctly, manage vendors, and maintain basic security controls.
What to do
  • For keep security separate from underwriting, keep the evidence simple and reviewable: identify the responsible owner, preserve the supporting documents, write down the provider’s requirement, and confirm the result in the account’s reports or agreement.
  • PCI DSS scope follows the flow of payment data.
  • Outsourcing can reduce exposure, but merchants still need to understand their environment, validate correctly, manage vendors, and maintain basic security controls.
  • These steps make the application easier to understand and give ORCA more to work with when matching the business to an appropriate processing relationship.
05

QUESTION

What should merchants know about use current pci ssc materials?

ANSWER

Document where account data is entered, transmitted, stored, logged, and accessible, including websites, terminals, call centers, plugins, support tools, vendors, and backups.

  • The correct PCI DSS validation method depends on this real data flow and the eligibility criteria set by the accepting entity.
What to do
  • For use current pci ssc materials, keep the evidence simple and reviewable: identify the responsible owner, preserve the supporting documents, write down the provider’s requirement, and confirm the result in the account’s reports or agreement.
  • PCI DSS scope follows the flow of payment data.
  • Outsourcing can reduce exposure, but merchants still need to understand their environment, validate correctly, manage vendors, and maintain basic security controls.
  • These steps make the application easier to understand and give ORCA more to work with when matching the business to an appropriate processing relationship.

FREQUENTLY ASKED

Questions, answered

What version of PCI DSS is current?

PCI DSS v4.0.1 is the active PCI SSC version in the supplied 2026 context. Merchants should verify current documents and their required validation method with the entity receiving the validation.

Does outsourcing card storage remove PCI DSS?

No. Outsourcing can reduce scope, but merchants still retain responsibilities for vendor selection, integrations, access, website security, contracts, and the parts of the environment that can affect payment data.

Is PCI DSS a federal law?

Not by itself. “High risk” and PCI DSS are industry or contractual concepts, while federal, state, and local law may impose separate obligations. Merchants should confirm legal questions with qualified counsel.

PRIMARY SOURCES

Reference material

  1. PCI SSC , PCI DSS document library
  2. PCI SSC , Maintaining payment security

YOUR NEXT STEP

Need a path specific to your business?

Learn how ORCA approaches payment processing for complex merchant profiles.

Explore your options